Enhanced Ecommerce Plus for Easy Digital Downloads Security & Risk Analysis

wordpress.org/plugins/enhanced-ecommerce-plus-easy-digital-downloads

Enhanced Ecommerce Tracking in Google Analytics for Easy Digital Downloads

10 active installs v1.2 PHP 5.6+ WP 4.0+ Updated Apr 26, 2022
analyticseasy-digital-downloadseddmarketing
85
A · Safe
CVEs total0
Unpatched0
Last CVENever
Safety Verdict

Is Enhanced Ecommerce Plus for Easy Digital Downloads Safe to Use in 2026?

Generally Safe

Score 85/100

Enhanced Ecommerce Plus for Easy Digital Downloads has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.

No known CVEs Updated 3yr ago
Risk Assessment

The static analysis of the 'enhanced-ecommerce-plus-easy-digital-downloads' plugin v1.2 reveals a generally strong security posture, with excellent adherence to best practices in several key areas. The plugin demonstrates a commitment to secure coding by using prepared statements exclusively for all SQL queries and maintaining a high percentage of properly escaped output. The limited attack surface, consisting of only one AJAX handler and no exposed REST API routes or shortcodes, further contributes to its security. The presence of a nonce check on the single AJAX handler is a positive sign for preventing CSRF attacks.

However, there are a few areas that warrant attention. The taint analysis identified one flow with an unsanitized path, which, although not classified as critical or high severity in this instance, represents a potential risk. A lack of capability checks on the AJAX handler is a significant concern, as it means any authenticated user could potentially interact with this entry point without proper authorization, leaving it vulnerable to privilege escalation or unauthorized actions. The plugin's history of zero known vulnerabilities is encouraging and suggests a proactive approach to security, but it doesn't entirely negate the potential risks identified in the static analysis.

In conclusion, the plugin has a solid foundation with its secure handling of database queries and output, and a small attack surface. The primary weakness lies in the insufficient authorization checks for its sole AJAX endpoint and the identified unsanitized path flow, which represent the most immediate risks. While the lack of a vulnerability history is a positive indicator, it's crucial to address the identified code analysis concerns to maintain a robust security posture.

Key Concerns

  • No capability checks on AJAX handler
  • Flow with unsanitized path identified
  • Unescaped output (14% of outputs)
Vulnerabilities
None known

Enhanced Ecommerce Plus for Easy Digital Downloads Security Vulnerabilities

No known vulnerabilities — this is a good sign.
Code Analysis
Analyzed Mar 17, 2026

Enhanced Ecommerce Plus for Easy Digital Downloads Code Analysis

Dangerous Functions
0
Raw SQL Queries
0
0 prepared
Unescaped Output
1
6 escaped
Nonce Checks
1
Capability Checks
0
File Operations
2
External Requests
2
Bundled Libraries
0

Output Escaping

86% escaped7 total outputs
Data Flows
1 unsanitized

Data Flow Analysis

1 flows1 with unsanitized paths
<plugin> (plugin.php:0)
Source (user input) Sink (dangerous op) Sanitizer Transform Unsanitized Sanitized
Attack Surface

Enhanced Ecommerce Plus for Easy Digital Downloads Attack Surface

Entry Points1
Unprotected0

AJAX Handlers 1

authwp_ajax_eepeed_save_property_idplugin.php:67
WordPress Hooks 11
actionadmin_menuplugin.php:66
actionedd_purchase_link_endplugin.php:69
actionedd_pre_add_to_cartplugin.php:70
actionedd_pre_remove_from_cartplugin.php:71
actionedd_before_checkout_cartplugin.php:72
actionedd_complete_purchaseplugin.php:73
actionedd_complete_purchaseplugin.php:74
actionedd_post_refund_paymentplugin.php:75
actionedd_insert_paymentplugin.php:76
actionedd_purchase_link_endplugin.php:77
actionwp_footerplugin.php:78
Maintenance & Trust

Enhanced Ecommerce Plus for Easy Digital Downloads Maintenance & Trust

Maintenance Signals

WordPress version tested5.9.13
Last updatedApr 26, 2022
PHP min version5.6
Downloads3K

Community Trust

Rating0/100
Number of ratings0
Active installs10
Developer Profile

Enhanced Ecommerce Plus for Easy Digital Downloads Developer Profile

Shivanand Sharma

6 plugins · 1K total installs

89
trust score
Avg Security Score
93/100
Avg Patch Time
30 days
View full developer profile
Detection Fingerprints

How We Detect Enhanced Ecommerce Plus for Easy Digital Downloads

Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.

Asset Fingerprints

Asset Paths
/wp-content/plugins/enhanced-ecommerce-plus-easy-digital-downloads/assets/js/checkout-tracking.js/wp-content/plugins/enhanced-ecommerce-plus-easy-digital-downloads/assets/js/google-analytics.js
Script Paths
/wp-content/plugins/enhanced-ecommerce-plus-easy-digital-downloads/assets/js/checkout-tracking.js/wp-content/plugins/enhanced-ecommerce-plus-easy-digital-downloads/assets/js/google-analytics.js
Version Parameters
enhanced-ecommerce-plus-easy-digital-downloads/assets/js/checkout-tracking.js?ver=enhanced-ecommerce-plus-easy-digital-downloads/assets/js/google-analytics.js?ver=

HTML / DOM Fingerprints

JS Globals
EEPEDD_GA_SETTINGS
FAQ

Frequently Asked Questions about Enhanced Ecommerce Plus for Easy Digital Downloads