
EDD Versions Security & Risk Analysis
wordpress.org/plugins/edd-versionsThis plugin adds version numbers to your downloadable software products in Easy Digital Downloads.
Is EDD Versions Safe to Use in 2026?
Generally Safe
Score 85/100EDD Versions has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.
The "edd-versions" v1.0.1 plugin demonstrates a generally positive security posture based on the provided static analysis. The absence of any identified AJAX handlers, REST API routes, shortcodes, or cron events significantly limits the potential attack surface. Furthermore, the code shows a commitment to secure database interactions by exclusively using prepared statements for SQL queries, eliminating the risk of SQL injection vulnerabilities originating from this aspect.
However, a notable concern arises from the complete lack of output escaping. With 3 identified output points and 0% properly escaped, any user-provided data displayed on the frontend or backend is vulnerable to cross-site scripting (XSS) attacks. The absence of any capability checks or nonce checks on entry points, while currently not exploitable due to the lack of entry points, indicates a potential weakness if new functionalities are added without proper security considerations. The plugin's vulnerability history, being clean, is a positive indicator, suggesting a history of secure development or timely patching, but this must be weighed against the present code-level risks.
In conclusion, while the plugin has a minimal attack surface and handles database operations securely, the unescaped output represents a significant and exploitable security risk. Addressing the output escaping should be the immediate priority to improve its security posture. The lack of explicit security checks on potential entry points also suggests a need for more robust security implementations when expanding functionality.
Key Concerns
- Unescaped output points
- Missing capability checks
- Missing nonce checks
EDD Versions Security Vulnerabilities
EDD Versions Release Timeline
EDD Versions Code Analysis
Output Escaping
EDD Versions Attack Surface
WordPress Hooks 6
Maintenance & Trust
EDD Versions Maintenance & Trust
Maintenance Signals
Community Trust
EDD Versions Alternatives
EDD Auto Register
edd-auto-register
Automatically creates a WP user account at checkout, based on customer's email address.
Easy Digital Downloads Featured Downloads
edd-featured-downloads
Easily feature your downloads
EDD Downloads As Services
edd-downloads-as-services
Mark Downloads As Services in Easy Digital Downloads
Easy Digital Downloads – Blocks
edd-blocks
EDD Blocks adds a "Downloads" block to the new WordPress editor, also known as Gutenberg.
Easy Digital Downloads – Coming Soon
edd-coming-soon
Allows Coming Soon or Custom Status text instead of normal pricing for downloads in Easy Digital Downloads.
EDD Versions Developer Profile
23 plugins · 8K total installs
How We Detect EDD Versions
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
HTML / DOM Fingerprints
edd_download_download_version<strong>Version</strong><p class="howto">Enter the current version number of the item.</p>