
EDD Metrics Security & Risk Analysis
wordpress.org/plugins/edd-metricsBetter reports for Easy Digital Downloads, similar to Baremetrics.
Is EDD Metrics Safe to Use in 2026?
Generally Safe
Score 85/100EDD Metrics has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.
The "edd-metrics" plugin version 1.0 presents a significant security risk due to its unprotected AJAX handlers. The analysis reveals two AJAX entry points, both lacking any authentication or capability checks. This creates a wide-open attack surface, allowing any unauthenticated user to potentially interact with these handlers, leading to an unknown but potentially severe impact on the WordPress site. The lack of nonce checks further exacerbates this issue, making it easier for attackers to craft malicious requests.
The static analysis also highlights a critical concern regarding SQL queries. The plugin executes one SQL query, and 100% of them are not using prepared statements. This is a major vulnerability that could lead to SQL injection attacks, allowing attackers to manipulate or extract sensitive data from the database. While there is no recorded vulnerability history for this plugin, this does not guarantee its safety. The current state of the code, particularly the unprotected AJAX and raw SQL queries, suggests a disregard for fundamental WordPress security practices.
In conclusion, while the plugin does not bundle libraries or make external HTTP requests, the presence of unprotected AJAX handlers and raw SQL queries significantly outweighs these positive observations. The plugin's security posture is poor, and immediate attention is required to address these critical vulnerabilities to prevent potential exploitation.
Key Concerns
- Unprotected AJAX handlers
- No nonce checks on AJAX
- Raw SQL without prepared statements
- Insufficient output escaping
EDD Metrics Security Vulnerabilities
EDD Metrics Release Timeline
EDD Metrics Code Analysis
SQL Query Safety
Output Escaping
EDD Metrics Attack Surface
AJAX Handlers 2
WordPress Hooks 7
Maintenance & Trust
EDD Metrics Maintenance & Trust
Maintenance Signals
Community Trust
EDD Metrics Alternatives
Romiltec Analytics Tracking
romiltec-analytics-tracking
Professional Matomo analytics integration with automatic Post ID tracking as custom dimensions.
Easy Digital Downloads – Geckoboard
edd-geckoboard
Allow site owners to display EDD statistics through Geckoboard
Enhanced Ecommerce Plus for Easy Digital Downloads
enhanced-ecommerce-plus-easy-digital-downloads
Enhanced Ecommerce Tracking in Google Analytics for Easy Digital Downloads
User Admin Purchases Column for Easy Digital Downloads
edd-user-admin-purchases-column
See basic statistics of customers for the Easy Digital Downloads e-commerce plugin.
FoxMetrics
foxmetrics
FoxMetrics is software that helps you overcome the challenges with siloed systems and products. It captures, stores, and unlocks data generated from t …
EDD Metrics Developer Profile
4 plugins · 1K total installs
How We Detect EDD Metrics
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/edd-metrics/assets/js/moment.js/wp-content/plugins/edd-metrics/assets/js/admin.js/wp-content/plugins/edd-metrics/assets/css/admin.css/wp-content/plugins/edd-metrics/assets/js/Calendar.js/wp-content/plugins/edd-metrics/assets/js/Chart.min.js/wp-content/plugins/edd-metrics/assets/css/calendar.css/wp-content/plugins/edd-metrics/assets/js/moment.js/wp-content/plugins/edd-metrics/assets/js/admin.js/wp-content/plugins/edd-metrics/assets/js/Calendar.js/wp-content/plugins/edd-metrics/assets/js/Chart.min.jsedd-metrics/assets/js/admin.js?ver=edd-metrics/assets/css/admin.css?ver=edd-metrics/assets/js/moment.js?ver=edd-metrics/assets/js/Calendar.js?ver=edd-metrics/assets/js/Chart.min.js?ver=HTML / DOM Fingerprints
edd-metrics-wrapeddMetrics