
EDD Service Extended Security & Risk Analysis
wordpress.org/plugins/edd-service-extendedEasy Digital Download Service Extended adds message section in the user dashboard for conversation.
Is EDD Service Extended Safe to Use in 2026?
Generally Safe
Score 85/100EDD Service Extended has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.
The 'edd-service-extended' v1.0.1 plugin presents a mixed security posture. On the positive side, it has a small attack surface with only one entry point (a shortcode) and no direct file operations or external HTTP requests. The plugin also demonstrates good practices by implementing nonce checks and performing a high percentage of output escaping.
However, significant concerns arise from the presence of a dangerous function, `unserialize`, which, if used with user-controlled input, could lead to deserialization vulnerabilities. Furthermore, the plugin executes a SQL query without using prepared statements, a common vector for SQL injection if the data is not properly sanitized before being used in the query. The absence of capability checks on any potential entry points is also a notable weakness. The lack of any recorded vulnerability history is a positive indicator, suggesting a history of secure development, but this does not mitigate the risks identified in the current code analysis.
In conclusion, while the plugin has some strengths like a limited attack surface and good output escaping, the identified risks related to `unserialize`, raw SQL queries, and missing capability checks warrant careful consideration and remediation to ensure a robust security posture.
Key Concerns
- Dangerous function `unserialize` found
- Raw SQL query without prepared statements
- No capability checks on entry points
EDD Service Extended Security Vulnerabilities
EDD Service Extended Code Analysis
Dangerous Functions Found
SQL Query Safety
Output Escaping
EDD Service Extended Attack Surface
Shortcodes 1
WordPress Hooks 13
Maintenance & Trust
EDD Service Extended Maintenance & Trust
Maintenance Signals
Community Trust
EDD Service Extended Alternatives
EDD Downloads As Services
edd-downloads-as-services
Mark Downloads As Services in Easy Digital Downloads
EDD Auto Register
edd-auto-register
Automatically creates a WP user account at checkout, based on customer's email address.
Easy Digital Downloads Featured Downloads
edd-featured-downloads
Easily feature your downloads
Easy Digital Downloads – Blocks
edd-blocks
EDD Blocks adds a "Downloads" block to the new WordPress editor, also known as Gutenberg.
Easy Digital Downloads – Coming Soon
edd-coming-soon
Allows Coming Soon or Custom Status text instead of normal pricing for downloads in Easy Digital Downloads.
EDD Service Extended Developer Profile
5 plugins · 420 total installs
How We Detect EDD Service Extended
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/edd-service-extended/css/style.css/wp-content/plugins/edd-service-extended/js/jRate.min.js/wp-content/plugins/edd-service-extended/js/script.js/wp-content/plugins/edd-service-extended/js/script.js/wp-content/plugins/edd-service-extended/js/jRate.min.jsedd-service-extended/css/style.css?ver=edd-service-extended/js/script.js?ver=edd-service-extended/js/jRate.min.js?ver=HTML / DOM Fingerprints
add_user_commentedd_message_attachmentsubmit-msgedd_files_namesid="add_user_comment"id="edd_message_attachment"name="attach[]"id="edd_message_attachment"name="add_comment"value="Add"+5 more[add_user_comment_edd]