Easy Digital Downloads – External Products Security & Risk Analysis

wordpress.org/plugins/edd-external-products

Adds a robust third-party product system to Easy Digital Downloads

100 active installs v1.1.1 PHP + WP 3.0+ Updated Feb 3, 2026
easy-digital-downloadseddexternalremotethird-party
100
A · Safe
CVEs total0
Unpatched0
Last CVENever
Safety Verdict

Is Easy Digital Downloads – External Products Safe to Use in 2026?

Generally Safe

Score 100/100

Easy Digital Downloads – External Products has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.

No known CVEs Updated 1mo ago
Risk Assessment

The static analysis of "edd-external-products" v1.1.1 indicates a generally strong security posture. There are no identified dangerous functions, SQL queries are exclusively using prepared statements, and there are no file operations or external HTTP requests, all of which are positive indicators. However, the complete absence of nonce checks and capability checks, despite there being outputs, raises a concern. While the reported attack surface is zero, the lack of these security mechanisms means that any potential entry points, even if not immediately apparent in this analysis, could be exploited without proper authorization or integrity checks. The vulnerability history shows no recorded CVEs, which suggests a stable and well-maintained codebase over time. This lack of past vulnerabilities is encouraging, but it doesn't negate the potential risks identified in the code signals.

Key Concerns

  • No nonce checks on potential output flows
  • No capability checks on potential output flows
  • 71% of output escaping is proper, leaving some unescaped
Vulnerabilities
None known

Easy Digital Downloads – External Products Security Vulnerabilities

No known vulnerabilities — this is a good sign.
Code Analysis
Analyzed Mar 16, 2026

Easy Digital Downloads – External Products Code Analysis

Dangerous Functions
0
Raw SQL Queries
0
0 prepared
Unescaped Output
2
5 escaped
Nonce Checks
0
Capability Checks
0
File Operations
0
External Requests
0
Bundled Libraries
0

Output Escaping

71% escaped7 total outputs
Attack Surface

Easy Digital Downloads – External Products Attack Surface

Entry Points0
Unprotected0
WordPress Hooks 5
actionplugins_loadededd-external-products.php:152
actionedd_meta_box_fieldsincludes\admin\downloads\meta-box.php:38
filteredd_metabox_fields_saveincludes\admin\downloads\meta-box.php:56
actionedd_pre_add_to_cartincludes\template-overrides.php:30
actionedd_purchase_download_formincludes\template-overrides.php:61
Maintenance & Trust

Easy Digital Downloads – External Products Maintenance & Trust

Maintenance Signals

WordPress version tested6.9.4
Last updatedFeb 3, 2026
PHP min version
Downloads6K

Community Trust

Rating100/100
Number of ratings2
Active installs100
Developer Profile

Easy Digital Downloads – External Products Developer Profile

DigitalME

20 plugins · 140K total installs

79
trust score
Avg Security Score
100/100
Avg Patch Time
3200 days
View full developer profile
Detection Fingerprints

How We Detect Easy Digital Downloads – External Products

Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.

Asset Fingerprints

Asset Paths
/wp-content/plugins/edd-external-products/assets/css/style.css/wp-content/plugins/edd-external-products/assets/js/edd-external-products.js
Script Paths
/wp-content/plugins/edd-external-products/assets/js/edd-external-products.js
Version Parameters
edd-external-products/assets/css/style.css?ver=edd-external-products/assets/js/edd-external-products.js?ver=

HTML / DOM Fingerprints

CSS Classes
edd_download_purchase_formedd_purchase_submit_wrapper
Data Attributes
id="edd_external_product_url"name="_edd_external_product_url"id="edd_external_product_button"name="_edd_external_product_button"
FAQ

Frequently Asked Questions about Easy Digital Downloads – External Products