Gateway for Robokassa and Easy Digital Downloads Lite Security & Risk Analysis

wordpress.org/plugins/edd-robokassa-lite

This plugin adds the Robokassa payment gateway for the Easy Digital Downloads digital product plugin. Robokassa is a leading service for receiving pay …

10 active installs v1.0 PHP 5.4+ WP 4.4+ Updated Aug 12, 2020
e-commerceeasy-digital-downloadsecommerceeddsell
85
A · Safe
CVEs total0
Unpatched0
Last CVENever
Download
Safety Verdict

Is Gateway for Robokassa and Easy Digital Downloads Lite Safe to Use in 2026?

Generally Safe

Score 85/100

Gateway for Robokassa and Easy Digital Downloads Lite has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.

No known CVEs Updated 5yr ago
Risk Assessment

The "edd-robokassa-lite" v1.0 plugin exhibits a very strong security posture based on the static analysis. The complete absence of dangerous functions, SQL queries without prepared statements, file operations, external HTTP requests, and the full utilization of output escaping are excellent indicators of secure coding practices. Furthermore, the plugin has no recorded vulnerability history, suggesting a history of stable and secure releases.

However, the analysis does highlight a significant area of concern: two flows with unsanitized paths. While no critical or high severity issues were identified from these taint flows, the presence of unsanitized paths in any part of the code, especially without accompanying input validation or sanitization, presents a latent risk. The complete lack of nonce and capability checks on its entry points (AJAX handlers, REST API routes, shortcodes, cron events) is also a notable weakness. This means that any potential future functionality added to these entry points would be entirely unprotected, leaving them vulnerable to unauthorized access or manipulation.

In conclusion, while the current version of "edd-robokassa-lite" v1.0 is exceptionally well-coded in terms of direct vulnerabilities and has a clean historical record, the identified unsanitized paths and the complete absence of authentication/authorization checks on its entry points represent potential security weaknesses that should be addressed. The plugin's strengths lie in its clean code and vulnerability-free history, but its weaknesses are in the potential for future exploitation through unprotected entry points and the presence of unsanitized paths.

Key Concerns

  • Unsanitized path found in taint flow
  • Unsanitized path found in taint flow
  • No capability checks on entry points
  • No nonce checks on entry points
Vulnerabilities
None known

Gateway for Robokassa and Easy Digital Downloads Lite Security Vulnerabilities

No known vulnerabilities — this is a good sign.
Version History

Gateway for Robokassa and Easy Digital Downloads Lite Release Timeline

v1.0Current
Code Analysis
Analyzed Apr 16, 2026

Gateway for Robokassa and Easy Digital Downloads Lite Code Analysis

Dangerous Functions
0
Raw SQL Queries
0
0 prepared
Unescaped Output
0
12 escaped
Nonce Checks
0
Capability Checks
0
File Operations
0
External Requests
0
Bundled Libraries
0

Output Escaping

100% escaped12 total outputs
Data Flows · Security
2 unsanitized

Data Flow Analysis

2 flows2 with unsanitized paths
process_rb_notifications (edd-robokassa-lite.php:365)
Source (user input) Sink (dangerous op) Sanitizer Transform Unsanitized Sanitized
Attack Surface

Gateway for Robokassa and Easy Digital Downloads Lite Attack Surface

Entry Points0
Unprotected0
WordPress Hooks 11
actionedd_robokassa_cc_formedd-robokassa-lite.php:53
actionedd_gateway_robokassaedd-robokassa-lite.php:54
actioninitedd-robokassa-lite.php:57
actioninitedd-robokassa-lite.php:59
actioninitedd-robokassa-lite.php:60
filteredd_payment_gatewaysedd-robokassa-lite.php:62
filteredd_accepted_payment_iconsedd-robokassa-lite.php:63
filteredd_payment_confirm_robokassaedd-robokassa-lite.php:64
filteredd_settings_sections_gatewaysedd-robokassa-lite.php:65
filteredd_settings_gatewaysedd-robokassa-lite.php:66
actionplugins_loadededd-robokassa-lite.php:575
Maintenance & Trust

Gateway for Robokassa and Easy Digital Downloads Lite Maintenance & Trust

Maintenance Signals

WordPress version tested5.5.18
Last updatedAug 12, 2020
PHP min version5.4
Downloads1K

Community Trust

Rating0/100
Number of ratings0
Active installs10
Developer Profile

Gateway for Robokassa and Easy Digital Downloads Lite Developer Profile

Aleksandr

6 plugins · 20 total installs

84
trust score
Avg Security Score
85/100
Avg Patch Time
30 days
View full developer profile
Detection Fingerprints

How We Detect Gateway for Robokassa and Easy Digital Downloads Lite

Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.

Asset Fingerprints

Asset Paths
/wp-content/plugins/edd-robokassa-lite/rb_icon.png

HTML / DOM Fingerprints

FAQ

Frequently Asked Questions about Gateway for Robokassa and Easy Digital Downloads Lite