
Custom checkout fields for EDD Security & Risk Analysis
wordpress.org/plugins/edd-custom-checkout-fieldsAdd custom fields to the edd checkout form
Is Custom checkout fields for EDD Safe to Use in 2026?
Generally Safe
Score 100/100Custom checkout fields for EDD has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.
The "edd-custom-checkout-fields" plugin, version 1.4.4, presents a mixed security picture. On one hand, the plugin demonstrates good practices by having no known CVEs and no bundled libraries, indicating a generally well-maintained codebase. The absence of direct SQL queries without prepared statements and the lack of file operations or external HTTP requests are also positive signs. However, the static analysis reveals significant concerns regarding output escaping and taint analysis. With only 8% of outputs properly escaped, there's a substantial risk of Cross-Site Scripting (XSS) vulnerabilities, especially given the two identified taint flows with unsanitized paths. While these taint flows are not currently classified as critical or high severity, they represent potential vectors for exploitation if user-supplied data is not rigorously validated and escaped before output. The plugin's attack surface is notably zero in terms of direct entry points like AJAX handlers, REST API routes, and shortcodes, which is a strong defensive measure. Despite the low perceived immediate risk due to a clean vulnerability history, the poor output escaping and unhandled taint flows represent a considerable latent risk that should be addressed.
Key Concerns
- Low percentage of properly escaped output
- Taint flows with unsanitized paths
Custom checkout fields for EDD Security Vulnerabilities
Custom checkout fields for EDD Code Analysis
Output Escaping
Data Flow Analysis
Custom checkout fields for EDD Attack Surface
WordPress Hooks 15
Maintenance & Trust
Custom checkout fields for EDD Maintenance & Trust
Maintenance Signals
Community Trust
Custom checkout fields for EDD Alternatives
Easy Digital Downloads – Empty Cart
easy-digital-downloads-empty-cart
Easily add content to the empty cart display in Easy Digital Downloads.
Easy Digital Downloads – Continue Shopping
easy-digital-downloads-continue-shopping
Adds a Continue Shopping link to the Easy Digital Downloads checkout cart.
Easy Digital Downloads – Clear Cart
easy-digital-downloads-clear-cart
Adds a Clear Cart link to the Easy Digital Downloads checkout cart.
Checkout Styler for Easy Digital Downloads
checkout-styler-for-easy-digital-downloads
An addon for Easy Digital Downloads plugin to help you customize the checkout page with Live Preview.
Checkout Field Editor for WooCommerce – Checkout Manager
checkout-field-editor-and-manager-for-woocommerce
WooCommerce checkout field editor and manager helps to manage checkout fields in WooCommerce
Custom checkout fields for EDD Developer Profile
7 plugins · 8K total installs
How We Detect Custom checkout fields for EDD
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/edd-custom-checkout-fields/edd-custom-fields.css/wp-content/plugins/edd-custom-checkout-fields/edd-custom-fields.js/wp-content/plugins/edd-custom-checkout-fields/edd-custom-fields.jsedd-custom-checkout-fields/edd-custom-fields.css?ver=edd-custom-checkout-fields/edd-custom-fields.js?ver=HTML / DOM Fingerprints
edd-custom-checkout-fieldsedd-custom-checkout-fields-textedd-custom-checkout-fields-multi_line_textedd-custom-checkout-fields-checkboxedd-custom-checkout-fields-paragraphedd-custom-checkout-fields-selectedd-custom-checkout-fields-dateedd-custom-checkout-fields-radio+7 moredata-iddata-requireddata-titledata-typedata-placeholderdata-desc+3 more