Easy Digital Downloads – Checkout Notes Security & Risk Analysis

wordpress.org/plugins/edd-checkout-notes

Add a textarea to the checkout form where customers can leave notes about their order.

10 active installs v1.0 PHP + WP 3.9+ Updated Apr 17, 2014
checkoutcheckout-noteseasy-digital-downloads
85
A · Safe
CVEs total0
Unpatched0
Last CVENever
Safety Verdict

Is Easy Digital Downloads – Checkout Notes Safe to Use in 2026?

Generally Safe

Score 85/100

Easy Digital Downloads – Checkout Notes has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.

No known CVEs Updated 11yr ago
Risk Assessment

The plugin 'edd-checkout-notes' v1.0 presents a strong initial security posture based on the provided static analysis. The absence of identified AJAX handlers, REST API routes, shortcodes, and cron events significantly limits its attack surface. Furthermore, the code signals indicate good practices in several key areas: no dangerous functions were detected, all SQL queries utilize prepared statements, no file operations or external HTTP requests were found, and there are no recorded vulnerabilities in its history. This suggests a diligent approach to secure coding and maintenance by the developers.

However, a notable concern arises from the output escaping analysis. With 15 total outputs and only 60% properly escaped, a significant portion (40%) of outputs may be vulnerable to Cross-Site Scripting (XSS) attacks. This is a critical area of weakness that could allow attackers to inject malicious scripts into the user interface. Additionally, the complete lack of nonce checks and capability checks, coupled with zero identified flows in taint analysis, could be interpreted in two ways: either the plugin is extremely simple and inherently secure, or these checks are missing due to the lack of complex functionalities that would typically require them. While the absence of vulnerabilities in its history is positive, the potential for XSS due to insufficient output escaping remains a significant risk that warrants immediate attention.

Key Concerns

  • Significant portion of outputs not properly escaped
  • No nonce checks implemented
  • No capability checks implemented
Vulnerabilities
None known

Easy Digital Downloads – Checkout Notes Security Vulnerabilities

No known vulnerabilities — this is a good sign.
Version History

Easy Digital Downloads – Checkout Notes Release Timeline

No version history available.
Code Analysis
Analyzed Mar 17, 2026

Easy Digital Downloads – Checkout Notes Code Analysis

Dangerous Functions
0
Raw SQL Queries
0
0 prepared
Unescaped Output
6
9 escaped
Nonce Checks
0
Capability Checks
0
File Operations
0
External Requests
0
Bundled Libraries
0

Output Escaping

60% escaped15 total outputs
Attack Surface

Easy Digital Downloads – Checkout Notes Attack Surface

Entry Points0
Unprotected0
WordPress Hooks 6
actionedd_purchase_form_after_cc_formedd-checkout-notes.php:71
filteredd_payment_metaedd-checkout-notes.php:72
actionedd_payment_view_detailsedd-checkout-notes.php:73
filteredd_settings_extensionsedd-checkout-notes.php:75
filteratcf_csv_colsedd-checkout-notes.php:76
filteratcf_csv_cols_valuesedd-checkout-notes.php:77
Maintenance & Trust

Easy Digital Downloads – Checkout Notes Maintenance & Trust

Maintenance Signals

WordPress version tested3.9.40
Last updatedApr 17, 2014
PHP min version
Downloads3K

Community Trust

Rating100/100
Number of ratings2
Active installs10
Developer Profile

Easy Digital Downloads – Checkout Notes Developer Profile

Adam Pickering

3 plugins · 30 total installs

84
trust score
Avg Security Score
85/100
Avg Patch Time
30 days
View full developer profile
Detection Fingerprints

How We Detect Easy Digital Downloads – Checkout Notes

Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.

Asset Fingerprints

HTML / DOM Fingerprints

CSS Classes
edd-acnatcf-edd-address-1-wrap
Data Attributes
name="edd_acn"class="edd-input"
Shortcode Output
<fieldset class="edd-acn"><p id="atcf-edd-address-1-wrap">
FAQ

Frequently Asked Questions about Easy Digital Downloads – Checkout Notes