Paytm Digital Downloads Security & Risk Analysis

wordpress.org/plugins/edd-paytm-gateway

A paytm gateway for Easy Digital Downloads. This plugin allow you to accept payments using Paytm. This plugin will add a Paytm Payment option on check …

10 active installs v2.0 PHP 5.6+ WP 4.0.1+ Updated Nov 26, 2024
paytmpaytm-digital-downloadspaytm-easy-digital-downloadspaytm-payment-gatewaypaytm-payments
92
A · Safe
CVEs total0
Unpatched0
Last CVENever
Safety Verdict

Is Paytm Digital Downloads Safe to Use in 2026?

Generally Safe

Score 92/100

Paytm Digital Downloads has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.

No known CVEs Updated 1yr ago
Risk Assessment

The "edd-paytm-gateway" v2.0 plugin exhibits a strong static security posture with a seemingly small attack surface and no identified dangerous functions or SQL injection risks due to prepared statements. The absence of known vulnerabilities in its history is also a positive indicator. However, significant concerns arise from the complete lack of output escaping for the single identified output. This means that any data being displayed to users, if improperly formatted or containing malicious code, could be rendered directly, potentially leading to cross-site scripting (XSS) vulnerabilities. Additionally, the plugin makes two external HTTP requests without any apparent checks for capability or nonces, which, while not inherently a vulnerability, represent potential points of attack if the remote endpoints are compromised or if these requests can be triggered in an unauthorized manner. The zero nonce and capability checks across all potential entry points further contribute to a lack of robust access control, although the current lack of identified entry points mitigates this risk for now.

Key Concerns

  • Output not properly escaped
  • No nonce checks
  • No capability checks
Vulnerabilities
None known

Paytm Digital Downloads Security Vulnerabilities

No known vulnerabilities — this is a good sign.
Code Analysis
Analyzed Mar 17, 2026

Paytm Digital Downloads Code Analysis

Dangerous Functions
0
Raw SQL Queries
0
0 prepared
Unescaped Output
1
0 escaped
Nonce Checks
0
Capability Checks
0
File Operations
0
External Requests
2
Bundled Libraries
0

Output Escaping

0% escaped1 total outputs
Attack Surface

Paytm Digital Downloads Attack Surface

Entry Points0
Unprotected0
WordPress Hooks 7
filteredd_payment_gatewaysedd-paytm-gateway.php:24
actionedd_paytm_gateway_cc_formedd-paytm-gateway.php:32
actionedd_gateway_paytm_gatewayedd-paytm-gateway.php:195
actioninitedd-paytm-gateway.php:204
actionedd_verify_paytm_gateway_ipnedd-paytm-gateway.php:321
filteredd_settings_sections_gatewaysedd-paytm-gateway.php:328
filteredd_settings_gatewaysedd-paytm-gateway.php:404
Maintenance & Trust

Paytm Digital Downloads Maintenance & Trust

Maintenance Signals

WordPress version tested6.7.5
Last updatedNov 26, 2024
PHP min version5.6
Downloads4K

Community Trust

Rating100/100
Number of ratings1
Active installs10
Developer Profile

Paytm Digital Downloads Developer Profile

integrationdevpaytm

5 plugins · 3K total installs

69
trust score
Avg Security Score
85/100
Avg Patch Time
271 days
View full developer profile
Detection Fingerprints

How We Detect Paytm Digital Downloads

Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.

Asset Fingerprints

Asset Paths
/wp-content/plugins/edd-paytm-gateway/assets/css/paytm-payments.css
Script Paths
https://securegw.paytm.in/ext_resources/js/paytm.jshttps://securegw-stage.paytm.in/ext_resources/js/paytm.js
Version Parameters
edd-paytm-gateway/assets/css/paytm-payments.css?ver=

HTML / DOM Fingerprints

CSS Classes
paytm-woopg-loaderbounce1bounce2bounce3bounce4bounce5loading-paytmpaytm-overlay+1 more
HTML Comments
<!-- registers the gateway --><!-- Remove this if you want a credit card form --><!-- register the action to remove default CC form --><!-- Get the transaction token -->+3 more
Data Attributes
data-orderiddata-tokendata-tokenTypedata-amount
JS Globals
PaytmPaytm.CheckoutJSinvokeBlinkCheckoutPopup
FAQ

Frequently Asked Questions about Paytm Digital Downloads