
EDD TaxJar Security & Risk Analysis
wordpress.org/plugins/edd-taxjarAutomatically calculate sales tax in Easy Digital Downloads with TaxJar.
Is EDD TaxJar Safe to Use in 2026?
Generally Safe
Score 85/100EDD TaxJar has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.
The static analysis of edd-taxjar v1.0.2 indicates a strong security posture from a code perspective. The absence of dangerous functions, properly escaped output, and the use of prepared statements for SQL queries are all positive indicators. Furthermore, the lack of file operations and external HTTP requests reduces the plugin's attack surface. The vulnerability history also shows no recorded CVEs, which suggests a history of secure development or a lack of significant vulnerabilities being publicly disclosed. However, the complete absence of AJAX handlers, REST API routes, shortcodes, cron events, nonce checks, and capability checks, while seemingly indicating a small attack surface, also means there are no mechanisms in place for authentication or authorization checks within the analyzed entry points, which could be a concern if the plugin were to introduce such features in the future without proper security considerations.
While the current version appears secure based on the provided data, the lack of any identified entry points (AJAX, REST, shortcodes, cron) is unusual. If the plugin *does* have functionality that should be secured, this absence in the static analysis could mean those functions are not being properly identified or that the plugin has a very limited scope of interaction. The bundled Guzzle library is noted, and while not inherently a vulnerability, it's important to ensure bundled libraries are kept up-to-date to mitigate potential zero-day exploits. The overall assessment is positive regarding the current code, but a lack of identified protected entry points warrants a slight caution, particularly concerning future extensibility.
Key Concerns
- Bundled library (Guzzle)
- No capability checks found
- No nonce checks found
EDD TaxJar Security Vulnerabilities
EDD TaxJar Code Analysis
Bundled Libraries
Output Escaping
EDD TaxJar Attack Surface
WordPress Hooks 6
Maintenance & Trust
EDD TaxJar Maintenance & Trust
Maintenance Signals
Community Trust
EDD TaxJar Alternatives
EDD List File Names
edd-list-file-names
Shows a simple list of the download's files with a shortcode
Gateway for Interkassa and Easy Digital Downloads
edd-gateway-interkassa
This plugin adds the Interkassa payment gateway for the Easy Digital Downloads digital product plugin. Interkassa is an aggregator of payment methods.
EDD Invoice Data
edd-invoice-data
This plugin allows you to gather invoice data for any EDD payment gateway.
Easy Digital Downloads Free Link
easy-digital-downloads-free-link
replace EDD add-to-cart button with download link when product is free
EDD Auto Register
edd-auto-register
Automatically creates a WP user account at checkout, based on customer's email address.
EDD TaxJar Developer Profile
94 plugins · 23.5M total installs
How We Detect EDD TaxJar
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
HTML / DOM Fingerprints
edd_taxjar