WPML Multilingual for Easy Digital Downloads Security & Risk Analysis

wordpress.org/plugins/edd-multilingual

WPML Multilingual for Easy Digital Downloads is the glue plugin that provides seamless integration between Easy Digital Downloads and WPML.

100 active installs v1.4.3 PHP + WP 4.7+ Updated Dec 4, 2025
downloade-commerceeddmultilingualwpml
100
A · Safe
CVEs total0
Unpatched0
Last CVENever
Safety Verdict

Is WPML Multilingual for Easy Digital Downloads Safe to Use in 2026?

Generally Safe

Score 100/100

WPML Multilingual for Easy Digital Downloads has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.

No known CVEs Updated 5mo ago
Risk Assessment

The "edd-multilingual" v1.4.3 plugin exhibits a seemingly strong security posture based on the static analysis provided. There are no identified dangerous functions, SQL queries are all prepared, and there are no file operations or external HTTP requests. Furthermore, the vulnerability history is clear, with no recorded CVEs, suggesting a history of secure development or prompt patching. The absence of any taint analysis findings further reinforces this positive outlook.

However, there are significant areas of concern despite the lack of direct vulnerabilities. The plugin has a complete absence of any entry points (AJAX, REST API, shortcodes, cron events), which is unusual for a plugin that likely needs to interact with WordPress in some way. More critically, there are no observed nonce checks or capability checks, and only a quarter of its output is properly escaped. This lack of fundamental security mechanisms, especially for output, creates a considerable risk of Cross-Site Scripting (XSS) vulnerabilities if any input were to be mishandled in the future, or if an attack vector exists outside the analyzed entry points.

In conclusion, while the plugin lacks a historical track record of vulnerabilities and utilizes secure database practices, the complete absence of basic security checks like nonces and capability checks, coupled with a low rate of output escaping, presents a substantial inherent risk. The very low number of analyzed flows in the taint analysis could also indicate a limited scope of analysis or a plugin that, by design, minimizes complex data handling, which might mask potential issues.

Key Concerns

  • Low percentage of properly escaped output
  • No nonce checks detected
  • No capability checks detected
  • No entry points analyzed, indicating limited scope or risk
Vulnerabilities
None known

WPML Multilingual for Easy Digital Downloads Security Vulnerabilities

No known vulnerabilities — this is a good sign.
Version History

WPML Multilingual for Easy Digital Downloads Release Timeline

v1.4.3Current
v1.4.2
v1.4.1
v1.4.0
v1.3.4
v1.3.3
v1.2.2
v1.2.1
v1.2
v1.0.0
Code Analysis
Analyzed Mar 16, 2026

WPML Multilingual for Easy Digital Downloads Code Analysis

Dangerous Functions
0
Raw SQL Queries
0
0 prepared
Unescaped Output
3
1 escaped
Nonce Checks
0
Capability Checks
0
File Operations
0
External Requests
0
Bundled Libraries
0

Output Escaping

25% escaped4 total outputs
Attack Surface

WPML Multilingual for Easy Digital Downloads Attack Surface

Entry Points0
Unprotected0
WordPress Hooks 11
actionplugins_loadedclass-edd-multilingual.php:11
actionadmin_noticesclass-edd-multilingual.php:20
actionadmin_noticesclass-edd-multilingual.php:24
actionadmin_noticesclass-edd-multilingual.php:31
actionedd_insert_paymentclass-edd-multilingual.php:76
filteredd_payments_table_columnsclass-edd-multilingual.php:79
filteredd_payments_table_columnclass-edd-multilingual.php:80
filteredd_download_columnsclass-edd-multilingual.php:83
actionadmin_enqueue_scriptsclass-edd-multilingual.php:95
filteroption_cfm-checkout-formclass-edd-multilingual.php:99
filteredd_api_v2_products_query_argsclass-edd-multilingual.php:102
Maintenance & Trust

WPML Multilingual for Easy Digital Downloads Maintenance & Trust

Maintenance Signals

WordPress version tested6.9.4
Last updatedDec 4, 2025
PHP min version
Downloads7K

Community Trust

Rating100/100
Number of ratings1
Active installs100
Developer Profile

WPML Multilingual for Easy Digital Downloads Developer Profile

Amir Helzer

9 plugins · 108K total installs

82
trust score
Avg Security Score
91/100
Avg Patch Time
53 days
View full developer profile
Detection Fingerprints

How We Detect WPML Multilingual for Easy Digital Downloads

Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.

Asset Fingerprints

HTML / DOM Fingerprints

CSS Classes
edd-ml-language-columnedd_ml_language_column
Data Attributes
data-edd-ml-language
FAQ

Frequently Asked Questions about WPML Multilingual for Easy Digital Downloads