
EDD Favorites Security & Risk Analysis
wordpress.org/plugins/edd-favoritesFavorite/Unfavorite downloads in Easy Digital Downloads with just 1 click.
Is EDD Favorites Safe to Use in 2026?
Generally Safe
Score 85/100EDD Favorites has a strong security track record. Known vulnerabilities have been patched promptly.
The EDD Favorites v1.0.8 plugin exhibits a mixed security posture. On the positive side, it demonstrates strong practices regarding SQL queries, utilizing prepared statements exclusively and having no known unpatched vulnerabilities. The absence of dangerous functions, file operations, and external HTTP requests is also commendable. However, significant concerns arise from the static analysis. The plugin exposes two AJAX endpoints that lack authentication checks, presenting a substantial risk. Furthermore, only 25% of its output is properly escaped, indicating a potential for Cross-Site Scripting (XSS) vulnerabilities, especially given its history of XSS CVEs. While the taint analysis shows no current issues, the lack of comprehensive checks on entry points and output sanitization, coupled with past XSS trends, suggests a heightened risk profile that requires attention. The plugin's vulnerability history, though lacking recent critical or high severity issues, shows a past pattern of XSS, implying that the development team may have struggled with proper input validation and output escaping. In conclusion, while the plugin has some strengths in secure database interaction, the unprotected entry points and insufficient output escaping are critical weaknesses that could be exploited.
Key Concerns
- AJAX handlers without auth checks
- Low percentage of properly escaped output
- Past XSS vulnerabilities indicate potential ongoing risk
- No nonce checks on AJAX handlers
- No capability checks on AJAX handlers
EDD Favorites Security Vulnerabilities
CVEs by Year
Severity Breakdown
1 total CVE
Easy Digital Downloads – Favorites <= 1.0.6 - Cross-Site Scripting
EDD Favorites Code Analysis
Output Escaping
EDD Favorites Attack Surface
AJAX Handlers 2
Shortcodes 2
WordPress Hooks 30
Maintenance & Trust
EDD Favorites Maintenance & Trust
Maintenance Signals
Community Trust
EDD Favorites Alternatives
EDD Purchase Rewards
edd-purchase-rewards
Increase sales and build customer loyalty by rewarding customers
EDD Free Download Text
edd-free-download-text
Change the button text of a free download
EDD Purchase Gravatars
edd-purchase-gravatars
Displays Gravatars of customers who have purchased your product
EDD Add To Cart Redirect
edd-add-to-cart-redirect
Redirect to any post/page/download when a download has been added the cart.
EDD Prevent Checkout
edd-prevent-checkout
Prevents customer from being able to checkout until a minimum cart total is reached
EDD Favorites Developer Profile
17 plugins · 3K total installs
How We Detect EDD Favorites
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/edd-favorites/assets/css/edd-favorites.css/wp-content/plugins/edd-favorites/assets/js/edd-favorites.js/wp-content/plugins/edd-favorites/assets/js/edd-favorites.jsedd-favorites/assets/css/edd-favorites.css?ver=edd-favorites/assets/js/edd-favorites.js?ver=HTML / DOM Fingerprints
edd-wl-favoritefavoritededd-loadingdata-edd-loadingedd_favorites_ajax