
EDD Download Images Security & Risk Analysis
wordpress.org/plugins/edd-download-imagesEasily add extra download images and display them.
Is EDD Download Images Safe to Use in 2026?
Generally Safe
Score 85/100EDD Download Images has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.
The "edd-download-images" plugin version 1.2 exhibits a mixed security posture. On the positive side, the static analysis reveals no dangerous functions, all SQL queries use prepared statements, and there are no file operations or external HTTP requests, which are excellent security practices. The absence of any recorded vulnerabilities in its history is also a strong indicator of good security development. However, significant concerns arise from the output escaping. With only 20% of total outputs properly escaped, there's a high probability of Cross-Site Scripting (XSS) vulnerabilities, especially given the presence of a shortcode which is a known entry point. Furthermore, the lack of nonce and capability checks on any entry points, including the shortcode, means that even authenticated users could potentially trigger unintended actions or expose data.
The taint analysis showing zero flows is reassuring, but it might be limited by the scope of the analysis or the plugin's complexity. The primary weakness lies in the insufficient output escaping and the complete absence of authorization checks on the identified shortcode. While the vulnerability history is clean, the code analysis reveals specific areas that are prone to exploitation if malicious input is provided through the shortcode. Therefore, while the plugin has strong foundations in certain areas, the unescaped output and lack of authorization on the shortcode present a considerable risk of XSS and potential privilege escalation or unauthorized actions.
Key Concerns
- Insufficient output escaping
- Missing nonce checks on shortcode
- Missing capability checks on shortcode
EDD Download Images Security Vulnerabilities
EDD Download Images Code Analysis
Output Escaping
EDD Download Images Attack Surface
Shortcodes 1
WordPress Hooks 7
Maintenance & Trust
EDD Download Images Maintenance & Trust
Maintenance Signals
Community Trust
EDD Download Images Alternatives
EDD Auto Register
edd-auto-register
Automatically creates a WP user account at checkout, based on customer's email address.
Easy Digital Downloads Featured Downloads
edd-featured-downloads
Easily feature your downloads
EDD Downloads As Services
edd-downloads-as-services
Mark Downloads As Services in Easy Digital Downloads
Easy Digital Downloads – Blocks
edd-blocks
EDD Blocks adds a "Downloads" block to the new WordPress editor, also known as Gutenberg.
Easy Digital Downloads – Coming Soon
edd-coming-soon
Allows Coming Soon or Custom Status text instead of normal pricing for downloads in Easy Digital Downloads.
EDD Download Images Developer Profile
17 plugins · 3K total installs
How We Detect EDD Download Images
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/edd-download-images/css/edd-download-images.css/wp-content/plugins/edd-download-images/js/edd-download-images.js/wp-content/plugins/edd-download-images/js/edd-download-images.jsedd-download-images/css/edd-download-images.css?ver=edd-download-images/js/edd-download-images.js?ver=HTML / DOM Fingerprints
edd-di-imagedata-key[edd_download_images]