Easy Digital Downloads – Omnidesk Support Security & Risk Analysis

wordpress.org/plugins/edd-omnidesk-support

Bring the helpdesk into your blog

0 active installs v1.3.0 PHP 5.6+ WP 4.2+ Updated Jun 3, 2020
customer-supporthelp-deskhelpdeskomnidesksupport
85
A · Safe
CVEs total0
Unpatched0
Last CVENever
Safety Verdict

Is Easy Digital Downloads – Omnidesk Support Safe to Use in 2026?

Generally Safe

Score 85/100

Easy Digital Downloads – Omnidesk Support has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.

No known CVEs Updated 5yr ago
Risk Assessment

The EDD Omnidesk Support plugin version 1.3.0 exhibits a generally positive security posture due to the absence of known vulnerabilities and a low number of critical code signals. The plugin demonstrates good practice by not utilizing raw SQL queries, all of which are prepared statements. Furthermore, there are no external HTTP requests that are not properly handled or directly exploitable. The limited attack surface, with only one shortcode and no unprotected AJAX handlers or REST API routes, is also a strength. However, there are areas for improvement. The 50% rate of unescaped output is a concern, as it could potentially lead to cross-site scripting (XSS) vulnerabilities if user-supplied data is not handled carefully. The taint analysis revealing two flows with unsanitized paths, even without critical or high severity, warrants attention as it suggests potential areas where malicious input could be processed insecurely, although the lack of critical findings mitigates this immediate risk. The absence of nonce checks and capability checks on its entry points is a notable weakness, especially for the shortcode, as it could be invoked by unauthenticated users or users with insufficient privileges, potentially leading to unintended actions. In conclusion, while the plugin has a solid foundation by avoiding known vulnerabilities and using prepared statements, the unescaped output and lack of proper authorization checks on its entry points represent security risks that should be addressed.

Key Concerns

  • Unescaped output detected
  • Missing capability checks on entry points
  • Missing nonce checks on entry points
  • Taint flows with unsanitized paths
Vulnerabilities
None known

Easy Digital Downloads – Omnidesk Support Security Vulnerabilities

No known vulnerabilities — this is a good sign.
Version History

Easy Digital Downloads – Omnidesk Support Release Timeline

v1.3.0Current
Code Analysis
Analyzed Mar 17, 2026

Easy Digital Downloads – Omnidesk Support Code Analysis

Dangerous Functions
0
Raw SQL Queries
0
0 prepared
Unescaped Output
2
2 escaped
Nonce Checks
0
Capability Checks
0
File Operations
0
External Requests
1
Bundled Libraries
0

Output Escaping

50% escaped4 total outputs
Data Flows · Security
2 unsanitized

Data Flow Analysis

2 flows2 with unsanitized paths
login_redirect (edd-omnidesk.php:153)
Source (user input) Sink (dangerous op) Sanitizer Transform Unsanitized Sanitized
Attack Surface

Easy Digital Downloads – Omnidesk Support Attack Surface

Entry Points1
Unprotected0

Shortcodes 1

[edd_omnidesk] edd-omnidesk.php:39
WordPress Hooks 5
filteredd_settings_sections_extensionsedd-omnidesk.php:41
filteredd_settings_extensionsedd-omnidesk.php:43
filtereomni_settings_erroredd-omnidesk.php:45
actionplugins_loadededd-omnidesk.php:295
actionadmin_noticesincludes\class.extension-activation.php:70
Maintenance & Trust

Easy Digital Downloads – Omnidesk Support Maintenance & Trust

Maintenance Signals

WordPress version tested5.4.19
Last updatedJun 3, 2020
PHP min version5.6
Downloads1K

Community Trust

Rating0/100
Number of ratings0
Active installs0
Developer Profile

Easy Digital Downloads – Omnidesk Support Developer Profile

Aleksandr

6 plugins · 20 total installs

84
trust score
Avg Security Score
85/100
Avg Patch Time
30 days
View full developer profile
Detection Fingerprints

How We Detect Easy Digital Downloads – Omnidesk Support

Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.

Asset Fingerprints

Asset Paths
/wp-content/plugins/edd-omnidesk-support/core/JWT.php

HTML / DOM Fingerprints

JS Globals
JWT
Shortcode Output
You need to enter in your Omnidesk credentials under Downloads -> Settings -> Extensions -> Omnidesk before you can access the Omnidesk support system.
FAQ

Frequently Asked Questions about Easy Digital Downloads – Omnidesk Support