Easy Digital Downloads – Drip Security & Risk Analysis

wordpress.org/plugins/edd-drip

Easy Digital Downloads - Drip integrates the Easy Digital Downloads (EDD) shopping cart with the Drip email marketing automation tool.

10 active installs v1.4.1 PHP + WP 3.9.1+ Updated Nov 21, 2017
dripeddemailemail-marketingmarketing-automation
85
A · Safe
CVEs total0
Unpatched0
Last CVENever
Safety Verdict

Is Easy Digital Downloads – Drip Safe to Use in 2026?

Generally Safe

Score 85/100

Easy Digital Downloads – Drip has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.

No known CVEs Updated 8yr ago
Risk Assessment

The "edd-drip" v1.4.1 plugin exhibits a generally good security posture based on the provided static analysis. The lack of critical findings in taint analysis, no known CVEs, and the absence of dangerous functions are positive indicators. The fact that all SQL queries utilize prepared statements further reinforces this. However, the plugin has a significant weakness in its output escaping, with 0% of outputs being properly escaped. This could lead to cross-site scripting (XSS) vulnerabilities if any of the outputted data originates from user-supplied input or is otherwise untrusted. Additionally, the presence of a single cron event, while not inherently insecure, warrants attention to ensure its functionality does not introduce vulnerabilities, especially in conjunction with the unescaped output. The vulnerability history being clean is a strong positive, suggesting consistent good security practices from the developer or diligent maintenance.

Key Concerns

  • Unescaped output detected
  • One cron event exists
Vulnerabilities
None known

Easy Digital Downloads – Drip Security Vulnerabilities

No known vulnerabilities — this is a good sign.
Code Analysis
Analyzed Mar 17, 2026

Easy Digital Downloads – Drip Code Analysis

Dangerous Functions
0
Raw SQL Queries
0
0 prepared
Unescaped Output
2
0 escaped
Nonce Checks
0
Capability Checks
0
File Operations
0
External Requests
1
Bundled Libraries
0

Output Escaping

0% escaped2 total outputs
Attack Surface

Easy Digital Downloads – Drip Attack Surface

Entry Points0
Unprotected0
WordPress Hooks 7
filtercron_schedulesedd-drip.php:109
filteredd_settings_extensionsedd-drip.php:112
actionedd_complete_purchaseedd-drip.php:114
actionedd_update_payment_statusedd-drip.php:116
actionedd_drip_cron_half_hourlyedd-drip.php:118
actionplugins_loadededd-drip.php:535
actionadmin_noticesincludes\class.extension-activation.php:75

Scheduled Events 1

edd_drip_cron_half_hourly
Maintenance & Trust

Easy Digital Downloads – Drip Maintenance & Trust

Maintenance Signals

WordPress version tested4.9.0
Last updatedNov 21, 2017
PHP min version
Downloads6K

Community Trust

Rating100/100
Number of ratings2
Active installs10
Developer Profile

Easy Digital Downloads – Drip Developer Profile

fatcatapps

13 plugins · 67K total installs

74
trust score
Avg Security Score
93/100
Avg Patch Time
242 days
View full developer profile
Detection Fingerprints

How We Detect Easy Digital Downloads – Drip

Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.

Asset Fingerprints

Asset Paths
/wp-content/plugins/edd-drip/assets/css/edd-drip.css/wp-content/plugins/edd-drip/assets/js/edd-drip.js
Script Paths
/wp-content/plugins/edd-drip/assets/js/edd-drip.js
Version Parameters
edd-drip/assets/css/edd-drip.css?ver=edd-drip/assets/js/edd-drip.js?ver=

HTML / DOM Fingerprints

CSS Classes
edd-drip-settings-headingedd-drip-api-key-fieldedd-drip-account-id-fieldedd-drip-list-field
HTML Comments
<!-- EDD Drip Settings --><!-- Drip API Key --><!-- Drip Account ID --><!-- Choose drip list -->
Data Attributes
data-edd-drip-apidata-edd-drip-account-iddata-edd-drip-list
JS Globals
edd_drip_settings
FAQ

Frequently Asked Questions about Easy Digital Downloads – Drip