EDD First Time Buyer's Gift Security & Risk Analysis

wordpress.org/plugins/edd-first-time-buyers-gift

Increase customer satisfaction and repeat business by generating and assigning discounts for buyers after their first purchase.

10 active installs v1.1 PHP + WP + Updated Dec 9, 2018
couponsdiscountseasy-digital-downloads
85
A · Safe
CVEs total0
Unpatched0
Last CVENever
Safety Verdict

Is EDD First Time Buyer's Gift Safe to Use in 2026?

Generally Safe

Score 85/100

EDD First Time Buyer's Gift has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.

No known CVEs Updated 7yr ago
Risk Assessment

The "edd-first-time-buyers-gift" plugin v1.1 exhibits a generally strong security posture based on the provided static analysis. The absence of dangerous functions, SQL injection vulnerabilities (all queries use prepared statements), and file operations is a significant positive. Furthermore, all identified output is properly escaped, mitigating potential cross-site scripting (XSS) risks. The plugin also shows no external HTTP requests, which reduces its exposure to man-in-the-middle attacks or compromised external resources.

However, there are areas of concern. The complete lack of nonce checks and capability checks across all entry points (including the single shortcode) is a critical weakness. This means that any user, regardless of their role or authentication status, could potentially trigger the functionality of the shortcode, leading to unintended actions or information disclosure if the shortcode's logic is not inherently safe. The absence of taint analysis data means we cannot rule out potential vulnerabilities that might be missed by direct function analysis.

The plugin's vulnerability history is clean, with no recorded CVEs. This is a good indicator of past development practices. However, the lack of historical data can also mean the plugin hasn't been extensively scrutinized or tested against known vulnerability patterns. In conclusion, while the code demonstrates good practices in several key areas, the absence of essential security checks like nonces and capability checks on its shortcode creates a significant and direct risk that needs immediate attention.

Key Concerns

  • Missing nonce checks
  • Missing capability checks
Vulnerabilities
None known

EDD First Time Buyer's Gift Security Vulnerabilities

No known vulnerabilities — this is a good sign.
Code Analysis
Analyzed Mar 17, 2026

EDD First Time Buyer's Gift Code Analysis

Dangerous Functions
0
Raw SQL Queries
0
0 prepared
Unescaped Output
0
1 escaped
Nonce Checks
0
Capability Checks
0
File Operations
0
External Requests
0
Bundled Libraries
0

Output Escaping

100% escaped1 total outputs
Attack Surface

EDD First Time Buyer's Gift Attack Surface

Entry Points1
Unprotected0

Shortcodes 1

[edd_ftbg_gift_notice] includes\admin\shortcodes.php:12
WordPress Hooks 5
actionedd_complete_purchaseedd-first-time-buyers-gift.php:64
actionedd_add_email_tagsedd-first-time-buyers-gift.php:67
actionplugins_loadededd-first-time-buyers-gift.php:162
filteredd_settings_miscincludes\admin\register-settings.php:14
filteredd_ftbg_gift_notice_textincludes\admin\shortcodes.php:59
Maintenance & Trust

EDD First Time Buyer's Gift Maintenance & Trust

Maintenance Signals

WordPress version tested5.0.25
Last updatedDec 9, 2018
PHP min version
Downloads2K

Community Trust

Rating0/100
Number of ratings0
Active installs10
Developer Profile

EDD First Time Buyer's Gift Developer Profile

Ren Ventura

6 plugins · 2K total installs

87
trust score
Avg Security Score
82/100
Avg Patch Time
6 days
View full developer profile
Detection Fingerprints

How We Detect EDD First Time Buyer's Gift

Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.

Asset Fingerprints

HTML / DOM Fingerprints

CSS Classes
ftbg-notice
Shortcode Output
<div class="ftbg-notice"><p>Congratulations on your first purchase! As a way to say thanks, we would like to gift you a discount to use toward your next purchase. Your discount code is</strong>.</p></div>
FAQ

Frequently Asked Questions about EDD First Time Buyer's Gift