
EDD List File Names Security & Risk Analysis
wordpress.org/plugins/edd-list-file-namesShows a simple list of the download's files with a shortcode
Is EDD List File Names Safe to Use in 2026?
Generally Safe
Score 85/100EDD List File Names has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.
The EDD List File Names v1.0.1 plugin presents a mixed security profile. On the positive side, the plugin exhibits excellent practices regarding database interactions, utilizing prepared statements for all its SQL queries and having no recorded vulnerabilities or CVEs. It also has a minimal attack surface with no AJAX handlers, REST API routes, cron events, or file operations, which significantly reduces potential avenues for attack. However, a critical concern arises from the lack of output escaping for all identified output points. This means that any data displayed to users could potentially be manipulated by an attacker to inject malicious scripts, leading to cross-site scripting (XSS) vulnerabilities. The absence of nonce and capability checks on the identified shortcode entry point, while seemingly minor given the limited attack surface, is also a weakness that could be exploited in conjunction with other vulnerabilities.
Key Concerns
- Output is not properly escaped
- No nonce checks on shortcode
- No capability checks on shortcode
EDD List File Names Security Vulnerabilities
EDD List File Names Code Analysis
Output Escaping
EDD List File Names Attack Surface
Shortcodes 1
WordPress Hooks 1
Maintenance & Trust
EDD List File Names Maintenance & Trust
Maintenance Signals
Community Trust
EDD List File Names Alternatives
EDD Invoice Data
edd-invoice-data
This plugin allows you to gather invoice data for any EDD payment gateway.
EDD Auto Register
edd-auto-register
Automatically creates a WP user account at checkout, based on customer's email address.
Easy Digital Downloads Featured Downloads
edd-featured-downloads
Easily feature your downloads
EDD Downloads As Services
edd-downloads-as-services
Mark Downloads As Services in Easy Digital Downloads
Easy Digital Downloads – Blocks
edd-blocks
EDD Blocks adds a "Downloads" block to the new WordPress editor, also known as Gutenberg.
EDD List File Names Developer Profile
17 plugins · 3K total installs
How We Detect EDD List File Names
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
HTML / DOM Fingerprints
edd-file-names<ol class="edd-file-names"><li></li></ol>