GoUrl Easy Digital Downloads (EDD) – Bitcoin Altcoin Payment Gateway Security & Risk Analysis

wordpress.org/plugins/gourl-bitcoin-easy-digital-downloads-edd

Provides Bitcoin/Altcoin Payment Gateway for Easy Digital Downloads (EDD) 2.4 or higher. Accept Bitcoin, Bitcoin Cash, Litecoin, Dogecoin, Dash, etc o …

50 active installs v1.0.2 PHP + WP 3.5+ Updated Jul 13, 2021
bitcoinbitcoin-cashbitcoincasheasy-digital-downloadsedd
85
A · Safe
CVEs total0
Unpatched0
Last CVENever
Safety Verdict

Is GoUrl Easy Digital Downloads (EDD) – Bitcoin Altcoin Payment Gateway Safe to Use in 2026?

Generally Safe

Score 85/100

GoUrl Easy Digital Downloads (EDD) – Bitcoin Altcoin Payment Gateway has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.

No known CVEs Updated 4yr ago
Risk Assessment

The "gourl-bitcoin-easy-digital-downloads-edd" plugin v1.0.2 exhibits a mixed security posture. On the positive side, it boasts an absence of known vulnerabilities, no dangerous functions, and all SQL queries are properly prepared. The presence of a nonce check is also a good security practice. However, a significant concern arises from the static analysis, which indicates that 100% of the 18 output operations are not properly escaped. This means that any dynamic data displayed by the plugin could be vulnerable to Cross-Site Scripting (XSS) attacks if that data originates from user input or external sources. Additionally, the taint analysis revealed one flow with an unsanitized path, which, while not classified as critical or high severity in this report, warrants attention as it suggests a potential avenue for data leakage or manipulation.

The plugin's clean vulnerability history is a strong indicator that it has either been developed with good security practices or has not yet been targeted by attackers. However, relying solely on the absence of past vulnerabilities is not a robust security strategy. The current code analysis highlights specific weaknesses that could be exploited regardless of past history. The lack of capability checks on any entry points, coupled with no apparent entry points being present in the static analysis, makes it difficult to assess the access control mechanisms fully. Overall, while the plugin has some strengths in areas like SQL handling, the unescaped output and the identified taint flow represent notable risks that require remediation.

Key Concerns

  • 100% of output operations are unescaped
  • Taint analysis shows 1 flow with unsanitized paths
  • No capability checks on identified entry points
Vulnerabilities
None known

GoUrl Easy Digital Downloads (EDD) – Bitcoin Altcoin Payment Gateway Security Vulnerabilities

No known vulnerabilities — this is a good sign.
Code Analysis
Analyzed Mar 16, 2026

GoUrl Easy Digital Downloads (EDD) – Bitcoin Altcoin Payment Gateway Code Analysis

Dangerous Functions
0
Raw SQL Queries
0
0 prepared
Unescaped Output
18
0 escaped
Nonce Checks
1
Capability Checks
0
File Operations
0
External Requests
0
Bundled Libraries
0

Output Escaping

0% escaped18 total outputs
Data Flows
1 unsanitized

Data Flow Analysis

3 flows1 with unsanitized paths
cryptocoin_payment (gourl-edd.php:460)
Source (user input) Sink (dangerous op) Sanitizer Transform Unsanitized Sanitized
Attack Surface

GoUrl Easy Digital Downloads (EDD) – Bitcoin Altcoin Payment Gateway Attack Surface

Entry Points0
Unprotected0
WordPress Hooks 14
actionplugins_loadedgourl-edd.php:22
filterplugin_action_linksgourl-edd.php:23
actionplugins_loadedgourl-edd.php:24
filteredd_settings_gatewaysgourl-edd.php:163
filteredd_payment_gatewaysgourl-edd.php:164
filteredd_accepted_payment_iconsgourl-edd.php:165
actionedd_gourl_cc_formgourl-edd.php:166
actionedd_gateway_gourlgourl-edd.php:167
actionedd_payment_receipt_beforegourl-edd.php:168
filteredd_currenciesgourl-edd.php:171
filteredd_btc_currency_filter_beforegourl-edd.php:172
filteredd_btc_currency_filter_aftergourl-edd.php:173
filteredd_currency_decimal_countgourl-edd.php:174
actionadmin_footer_textgourl-edd.php:177
Maintenance & Trust

GoUrl Easy Digital Downloads (EDD) – Bitcoin Altcoin Payment Gateway Maintenance & Trust

Maintenance Signals

WordPress version tested5.8.13
Last updatedJul 13, 2021
PHP min version
Downloads107K

Community Trust

Rating60/100
Number of ratings4
Active installs50
Developer Profile

GoUrl Easy Digital Downloads (EDD) – Bitcoin Altcoin Payment Gateway Developer Profile

gourl

11 plugins · 2K total installs

67
trust score
Avg Security Score
83/100
Avg Patch Time
1910 days
View full developer profile
Detection Fingerprints

How We Detect GoUrl Easy Digital Downloads (EDD) – Bitcoin Altcoin Payment Gateway

Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.

Asset Fingerprints

Asset Paths
/wp-content/plugins/gourl-bitcoin-easy-digital-downloads-edd/css/gourl-edd.css/wp-content/plugins/gourl-bitcoin-easy-digital-downloads-edd/js/gourl-edd.js
Script Paths
/wp-content/plugins/gourl-bitcoin-easy-digital-downloads-edd/js/gourl-edd.js
Version Parameters
gourl-bitcoin-easy-digital-downloads-edd/css/gourl-edd.css?ver=gourl-bitcoin-easy-digital-downloads-edd/js/gourl-edd.js?ver=

HTML / DOM Fingerprints

CSS Classes
gourl-edd-settings
HTML Comments
<!-- gourl-edd-settings -->
JS Globals
GOURL
FAQ

Frequently Asked Questions about GoUrl Easy Digital Downloads (EDD) – Bitcoin Altcoin Payment Gateway