SendPress for Easy Digital Downloads Security & Risk Analysis

wordpress.org/plugins/edd-sendpress

Integrate the Easy Digital Downloads plugin easily with the SendPress to collect emails on checkout.

10 active installs v1.0 PHP + WP 3.7.1+ Updated Feb 16, 2014
easy-digital-downloadseddemailnewslettersendpress
85
A · Safe
CVEs total0
Unpatched0
Last CVENever
Download
Safety Verdict

Is SendPress for Easy Digital Downloads Safe to Use in 2026?

Generally Safe

Score 85/100

SendPress for Easy Digital Downloads has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.

No known CVEs Updated 12yr ago
Risk Assessment

The static analysis of edd-sendpress v1.0 presents a generally positive security posture with no immediate critical or high-severity issues detected. The absence of dangerous functions, file operations, and external HTTP requests is commendable. Furthermore, the presence of 100% prepared statements for SQL queries significantly mitigates the risk of SQL injection vulnerabilities. The lack of any recorded CVEs in its history suggests a relatively stable and secure past for this plugin.

However, several areas raise concerns. The most significant is the complete lack of output escaping, meaning that any data processed or displayed by the plugin could potentially be vulnerable to cross-site scripting (XSS) attacks if that data originates from an untrusted source. Additionally, the absence of any nonce checks or capability checks on the identified entry points (though there are zero entry points in total based on the analysis) leaves a hypothetical gap. If new entry points were to be added in future versions without proper authorization and security checks, this could become a significant risk. The limited scope of taint analysis (0 flows analyzed) also means that potential vulnerabilities in data processing might have been missed.

In conclusion, while the plugin exhibits good practices in preventing common vulnerabilities like SQL injection and code execution, the unescaped output is a serious oversight that requires immediate attention. The lack of security checks on entry points, although currently moot due to zero entry points, is a weakness in defensive design. The overall security is decent, but the unescaped output is a critical flaw that needs remediation.

Key Concerns

  • Unescaped output (100% of outputs)
  • No nonce checks on entry points
  • No capability checks on entry points
  • Limited taint analysis scope
Vulnerabilities
None known

SendPress for Easy Digital Downloads Security Vulnerabilities

No known vulnerabilities — this is a good sign.
Code Analysis
Analyzed Mar 17, 2026

SendPress for Easy Digital Downloads Code Analysis

Dangerous Functions
0
Raw SQL Queries
0
0 prepared
Unescaped Output
1
0 escaped
Nonce Checks
0
Capability Checks
0
File Operations
0
External Requests
0
Bundled Libraries
0

Output Escaping

0% escaped1 total outputs
Attack Surface

SendPress for Easy Digital Downloads Attack Surface

Entry Points0
Unprotected0
WordPress Hooks 7
actionplugins_loadedclasses\edd-sendpress-signup.php:7
actioninitclasses\edd-sendpress-signup.php:12
filteredd_settings_miscclasses\edd-sendpress-signup.php:18
actionedd_purchase_form_before_submitclasses\edd-sendpress-signup.php:20
actionadmin_noticesclasses\edd-sendpress-signup.php:129
actionadmin_noticesclasses\edd-sendpress-signup.php:133
actionedd_checkout_before_gatewayclasses\edd-sendpress-signup.php:174
Maintenance & Trust

SendPress for Easy Digital Downloads Maintenance & Trust

Maintenance Signals

WordPress version tested3.7.41
Last updatedFeb 16, 2014
PHP min version
Downloads2K

Community Trust

Rating0/100
Number of ratings0
Active installs10
Developer Profile

SendPress for Easy Digital Downloads Developer Profile

brewlabs

4 plugins · 2K total installs

58
trust score
Avg Security Score
70/100
Avg Patch Time
1682 days
View full developer profile
Detection Fingerprints

How We Detect SendPress for Easy Digital Downloads

Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.

Asset Fingerprints

Asset Paths
/wp-content/plugins/edd-sendpress/assets/css/edd-sendpress.css/wp-content/plugins/edd-sendpress/assets/js/edd-sendpress.js
Script Paths
/wp-content/plugins/edd-sendpress/assets/js/edd-sendpress.js
Version Parameters
edd-sendpress/assets/css/edd-sendpress.css?ver=edd-sendpress/assets/js/edd-sendpress.js?ver=

HTML / DOM Fingerprints

CSS Classes
edd-sendpress-signup-formedd-sendpress-field
Data Attributes
data-edd-sendpress-signup-form
JS Globals
edd_sendpress_vars
Shortcode Output
[edd_sendpress_signup]
FAQ

Frequently Asked Questions about SendPress for Easy Digital Downloads