EDD Invoice Data Security & Risk Analysis

wordpress.org/plugins/edd-invoice-data

This plugin allows you to gather invoice data for any EDD payment gateway.

10 active installs v1.2.1 PHP + WP 3.5+ Updated Jun 19, 2018
digital-downloadse-commercee-downloadseasy-digital-downloadsedd
85
A · Safe
CVEs total0
Unpatched0
Last CVENever
Download
Safety Verdict

Is EDD Invoice Data Safe to Use in 2026?

Generally Safe

Score 85/100

EDD Invoice Data has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.

No known CVEs Updated 7yr ago
Risk Assessment

The plugin "edd-invoice-data" v1.2.1 exhibits a generally good security posture based on the provided static analysis and vulnerability history. The absence of any recorded CVEs and the lack of critical or high-severity issues in taint analysis are positive indicators. Furthermore, the code's adherence to prepared statements for SQL queries is a strong practice. However, there are areas for improvement.

The static analysis reveals a complete absence of entry points like AJAX handlers, REST API routes, shortcodes, and cron events, which significantly reduces the potential attack surface. This is a substantial strength. Despite this, a notable concern is the 73% proper output escaping, implying that 27% of outputs are not properly escaped. While no critical or high severity taint flows were identified, unescaped output can still lead to cross-site scripting (XSS) vulnerabilities, especially if user-supplied data is involved in those unescaped outputs.

In conclusion, the plugin has a strong foundation with minimal known vulnerabilities and a well-protected attack surface. The primary area of concern is the unescaped output, which, while not manifesting as critical taint flows in this analysis, still presents a latent risk. Addressing this would further harden the plugin's security.

Key Concerns

  • 27% of outputs are not properly escaped
Vulnerabilities
None known

EDD Invoice Data Security Vulnerabilities

No known vulnerabilities — this is a good sign.
Code Analysis
Analyzed Mar 17, 2026

EDD Invoice Data Code Analysis

Dangerous Functions
0
Raw SQL Queries
0
0 prepared
Unescaped Output
17
46 escaped
Nonce Checks
0
Capability Checks
0
File Operations
0
External Requests
0
Bundled Libraries
0

Output Escaping

73% escaped63 total outputs
Attack Surface

EDD Invoice Data Attack Surface

Entry Points0
Unprotected0
WordPress Hooks 11
actionplugins_loadededd-invoice-data.php:40
actionplugins_loadedincludes\actions.php:16
filteredd_payment_metaincludes\actions.php:256
actionedd_checkout_error_checksincludes\actions.php:309
actionedd_payment_personal_details_listincludes\actions.php:455
actionedd_after_purchase_formincludes\actions.php:488
filteredd_purchase_form_required_fieldsincludes\actions.php:500
actionsave_postincludes\actions.php:547
filteredd_settings_gatewaysincludes\admin\settings.php:62
actionwp_enqueue_scriptsincludes\scripts.php:20
actionwp_enqueue_scriptsincludes\scripts.php:45
Maintenance & Trust

EDD Invoice Data Maintenance & Trust

Maintenance Signals

WordPress version tested4.9.29
Last updatedJun 19, 2018
PHP min version
Downloads3K

Community Trust

Rating0/100
Number of ratings0
Active installs10
Developer Profile

EDD Invoice Data Developer Profile

Michal Jaworski

5 plugins · 740 total installs

86
trust score
Avg Security Score
89/100
Avg Patch Time
15 days
View full developer profile
Detection Fingerprints

How We Detect EDD Invoice Data

Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.

Asset Fingerprints

Asset Paths
/wp-content/plugins/edd-invoice-data/assets/js/scripts.js/wp-content/plugins/edd-invoice-data/assets/css/style.css/wp-content/plugins/edd-invoice-data/assets/css/hide_fname.css/wp-content/plugins/edd-invoice-data/assets/css/hide_lname.css
Script Paths
/wp-content/plugins/edd-invoice-data/assets/js/scripts.js
Version Parameters
edd-invoice-data/assets/js/scripts.js?ver=edd-invoice-data/assets/css/style.css?ver=edd-invoice-data/assets/css/hide_fname.css?ver=edd-invoice-data/assets/css/hide_lname.css?ver=

HTML / DOM Fingerprints

CSS Classes
bpmj_edd_invoice_data_invoice_checkbpmj_edd_invoice_data_invoicebpmj_edd_invoice_data_invoice_forcebpmj_edd_invoice_data_person_name_pbpmj_edd_invoice_data_company_name_pbpmj_edd_invoice_data_company_name_p_showbpmj_edd_invoice_data_nip_pbpmj_edd_invoice_data_nip_p_show
Data Attributes
name="bpmj_edd_invoice_data_invoice_check"id="bpmj_edd_invoice_data_invoice_check"name="bpmj_edd_invoice_data_invoice_type"name="bpmj_edd_invoice_data_invoice_person_name"name="bpmj_edd_invoice_data_invoice_company_name"name="bpmj_edd_invoice_data_invoice_nip"+3 more
FAQ

Frequently Asked Questions about EDD Invoice Data