Flutterwave Easy Digital Downloads Payment Gateway Security & Risk Analysis

wordpress.org/plugins/edd-rave

Flutterwave Easy Digital Downloads payment gateway allows you to accept payment through multiple payment channels via Flutterwave

100 active installs v2.1.0 PHP 7.4+ WP 6.0+ Updated Apr 17, 2025
eddflutterwavepayment-gateway
100
A · Safe
CVEs total0
Unpatched0
Last CVENever
Download
Safety Verdict

Is Flutterwave Easy Digital Downloads Payment Gateway Safe to Use in 2026?

Generally Safe

Score 100/100

Flutterwave Easy Digital Downloads Payment Gateway has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.

No known CVEs Updated 11mo ago
Risk Assessment

The "edd-rave" v2.1.0 plugin exhibits a generally strong security posture based on the provided static analysis. The absence of any detected dangerous functions, raw SQL queries, or unescaped output is highly commendable. The plugin also appears to have no known vulnerabilities in its history, suggesting a commitment to secure coding practices and prompt patching.

However, the static analysis does reveal areas for concern. The complete lack of nonce checks and capability checks across all identified entry points (though the attack surface is currently zero) is a significant weakness. This means that if any new entry points are introduced or become accessible, they would be vulnerable to various attacks without proper authorization checks. While there are no detected taint flows or file operation vulnerabilities in this specific version, the potential for exploitation of these missing checks remains.

In conclusion, while "edd-rave" v2.1.0 demonstrates good practices in its current code regarding sensitive functions and data handling, the absence of essential security mechanisms like nonce and capability checks represents a critical oversight. The plugin's clean vulnerability history is a positive indicator, but it doesn't negate the inherent risks posed by these missing security controls. Developers should prioritize implementing these checks to bolster the plugin's security against future threats.

Key Concerns

  • Missing nonce checks
  • Missing capability checks
Vulnerabilities
None known

Flutterwave Easy Digital Downloads Payment Gateway Security Vulnerabilities

No known vulnerabilities — this is a good sign.
Code Analysis
Analyzed Mar 16, 2026

Flutterwave Easy Digital Downloads Payment Gateway Code Analysis

Dangerous Functions
0
Raw SQL Queries
0
0 prepared
Unescaped Output
0
6 escaped
Nonce Checks
0
Capability Checks
0
File Operations
1
External Requests
2
Bundled Libraries
0

Output Escaping

100% escaped6 total outputs
Attack Surface

Flutterwave Easy Digital Downloads Payment Gateway Attack Surface

Entry Points0
Unprotected0
WordPress Hooks 21
actionplugins_loadededd-rave.php:54
filteredd_settings_sections_gatewaysincludes\class-admin.php:17
filteredd_settings_gatewaysincludes\class-admin.php:18
actionadmin_noticesincludes\class-admin.php:19
filteredd_gateway_settings_url_raveincludes\class-admin.php:20
filteredd_payment_gatewaysincludes\class-frontend.php:17
actionedd_rave_cc_formincludes\class-frontend.php:18
actionedd_gateway_raveincludes\class-frontend.php:19
actionedd_pre_process_purchaseincludes\class-frontend.php:20
actioninitincludes\class-frontend.php:21
actiontbz_edd_rave_redirect_verifyincludes\class-frontend.php:22
actiontbz_edd_rave_ipn_verifyincludes\class-frontend.php:23
filteredd_currenciesincludes\class-frontend.php:24
filteredd_accepted_payment_iconsincludes\class-frontend.php:25
filteredd_currency_symbolincludes\class-frontend.php:26
filteredd_ngn_currency_filter_beforeincludes\class-frontend.php:27
filteredd_ngn_currency_filter_afterincludes\class-frontend.php:28
filteredd_ghs_currency_filter_beforeincludes\class-frontend.php:29
filteredd_ghs_currency_filter_afterincludes\class-frontend.php:30
filteredd_zar_currency_filter_beforeincludes\class-frontend.php:31
filteredd_zar_currency_filter_afterincludes\class-frontend.php:32
Maintenance & Trust

Flutterwave Easy Digital Downloads Payment Gateway Maintenance & Trust

Maintenance Signals

WordPress version tested6.8.5
Last updatedApr 17, 2025
PHP min version7.4
Downloads8K

Community Trust

Rating100/100
Number of ratings1
Active installs100
Developer Profile

Flutterwave Easy Digital Downloads Payment Gateway Developer Profile

Tunbosun Ayinla

9 plugins · 33K total installs

88
trust score
Avg Security Score
92/100
Avg Patch Time
30 days
View full developer profile
Detection Fingerprints

How We Detect Flutterwave Easy Digital Downloads Payment Gateway

Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.

Asset Fingerprints

Asset Paths
/wp-content/plugins/edd-rave/

HTML / DOM Fingerprints

FAQ

Frequently Asked Questions about Flutterwave Easy Digital Downloads Payment Gateway