
EDD Recent downloads Security & Risk Analysis
wordpress.org/plugins/edd-recent-downloadsAdds a widget that can display recent downloads for Easy Digital Downloads.
Is EDD Recent downloads Safe to Use in 2026?
Generally Safe
Score 85/100EDD Recent downloads has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.
The "edd-recent-downloads" v1.0 plugin presents a mixed security posture. On the positive side, it exhibits excellent practices regarding SQL injection prevention, with 100% of queries using prepared statements. Furthermore, the plugin has no known vulnerabilities, no recorded CVEs, and a clean vulnerability history, suggesting a generally stable and well-maintained codebase.
However, significant concerns arise from the static analysis. The presence of the `create_function` is a notable risk, as it can lead to code injection vulnerabilities if user-supplied data is ever used within its definition, though the absence of taint analysis flows in this release makes it hard to quantify the immediate risk. More importantly, only 24% of outputs are properly escaped, indicating a high potential for Cross-Site Scripting (XSS) vulnerabilities. The complete lack of nonce checks and capability checks on any entry points, combined with zero protected entry points, leaves the plugin highly susceptible to unauthorized actions and privilege escalation if any interaction points were to be introduced or discovered.
While the current attack surface appears minimal (0 entry points), this plugin has several fundamental security weaknesses that would become critical if the attack surface expands or if the `create_function` were ever to process untrusted input. The low output escaping coverage is the most immediate and probable risk.
Key Concerns
- Dangerous function create_function used
- Low output escaping coverage (24%)
- No nonce checks found
- No capability checks found
EDD Recent downloads Security Vulnerabilities
EDD Recent downloads Code Analysis
Dangerous Functions Found
Output Escaping
EDD Recent downloads Attack Surface
WordPress Hooks 1
Maintenance & Trust
EDD Recent downloads Maintenance & Trust
Maintenance Signals
Community Trust
EDD Recent downloads Alternatives
Easy Digital Downloads – Frontend Submissions Product Details
easy-digital-downloads-frontend-submissions-product-details-widget
Specify and display frontend submission data as "product details" in a widget.
Classic Widgets
classic-widgets
Enables the previous "classic" widgets settings screens in Appearance - Widgets and the Customizer. Disables the block editor from managing widgets.
ElementsKit Elementor Addons – Advanced Widgets & Templates Addons for Elementor
elementskit-lite
Join millions who empower their websites with ElementsKit Elementor Addons. Get templates, & 100+ widgets like header-footer, mega menu, custom widget
Essential Addons for Elementor – Popular Elementor Templates & Widgets
essential-addons-for-elementor-lite
Elementor addon offering 110+ widgets and templates — Elementor Gallery, Slider, Form, Post Grid, Menu, Accordion, WooCommerce & more.
Ultimate Addons for Elementor
header-footer-elementor
Powerful Elementor addon with advanced Elementor widgets, templates, WooCommerce widgets & Header-Footer builder to build professional websites fa …
EDD Recent downloads Developer Profile
1 plugin · 10 total installs
How We Detect EDD Recent downloads
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
HTML / DOM Fingerprints
edd-recent-downloads_widgetedd-recent-post-itemdata-widget_typedata-widget-id