IDPay for Easy Digital Downloads (EDD) Security & Risk Analysis

wordpress.org/plugins/idpay-for-edd

After installing and enabling this plugin, your customers can pay through IDPay gateway.

40 active installs v2.2.1 PHP + WP + Updated Nov 13, 2022
digital-downloadsdownloadeasy-digital-downloadseddidpay
85
A · Safe
CVEs total0
Unpatched0
Last CVENever
Download
Safety Verdict

Is IDPay for Easy Digital Downloads (EDD) Safe to Use in 2026?

Generally Safe

Score 85/100

IDPay for Easy Digital Downloads (EDD) has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.

No known CVEs Updated 3yr ago
Risk Assessment

The idpay-for-edd plugin v2.2.1 demonstrates a generally strong security posture with no known vulnerabilities or CVEs. The static analysis reveals a minimal attack surface, with zero AJAX handlers, REST API routes, shortcodes, or cron events. This lack of direct entry points significantly reduces the potential for external exploitation. Furthermore, the plugin exclusively uses prepared statements for SQL queries, and the vast majority of output is properly escaped, indicating good practices in preventing common web vulnerabilities like SQL injection and cross-site scripting. The single external HTTP request is a point to note, but without further context on its purpose and destination, it's difficult to assess its risk. The presence of one taint flow with an unsanitized path, even if not critical or high severity in this instance, warrants attention as it represents a potential avenue for vulnerabilities if the input is not strictly controlled. The absence of nonce and capability checks on the (zero) entry points is a minor concern, as these are standard security mechanisms, though their absence is less impactful given the extremely limited attack surface. Overall, the plugin is well-secured, with the primary area for review being the single unsanitized path identified in the taint analysis.

Key Concerns

  • Taint flow with unsanitized path
  • External HTTP requests (1)
  • No nonce checks
  • No capability checks
Vulnerabilities
None known

IDPay for Easy Digital Downloads (EDD) Security Vulnerabilities

No known vulnerabilities — this is a good sign.
Code Analysis
Analyzed Mar 16, 2026

IDPay for Easy Digital Downloads (EDD) Code Analysis

Dangerous Functions
0
Raw SQL Queries
0
0 prepared
Unescaped Output
1
9 escaped
Nonce Checks
0
Capability Checks
0
File Operations
0
External Requests
1
Bundled Libraries
0

Output Escaping

90% escaped10 total outputs
Data Flows
1 unsanitized

Data Flow Analysis

1 flows1 with unsanitized paths
<edd-idpay-gateway> (includes\edd-idpay-gateway.php:0)
Source (user input) Sink (dangerous op) Sanitizer Transform Unsanitized Sanitized
Attack Surface

IDPay for Easy Digital Downloads (EDD) Attack Surface

Entry Points0
Unprotected0
WordPress Hooks 5
actioninitidpay-for-edd.php:24
filteredd_payment_gatewaysincludes\edd-idpay-gateway.php:14
filteredd_settings_gatewaysincludes\edd-idpay-gateway.php:18
actionedd_payment_receipt_afterincludes\edd-idpay-gateway.php:19
actioninitincludes\edd-idpay-gateway.php:20
Maintenance & Trust

IDPay for Easy Digital Downloads (EDD) Maintenance & Trust

Maintenance Signals

WordPress version tested6.1.10
Last updatedNov 13, 2022
PHP min version
Downloads6K

Community Trust

Rating20/100
Number of ratings1
Active installs40
Developer Profile

IDPay for Easy Digital Downloads (EDD) Developer Profile

IDPay

7 plugins · 1K total installs

84
trust score
Avg Security Score
85/100
Avg Patch Time
30 days
View full developer profile
Detection Fingerprints

How We Detect IDPay for Easy Digital Downloads (EDD)

Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.

Asset Fingerprints

Asset Paths
/wp-content/plugins/idpay-for-edd/assets/css/edd-idpay.css/wp-content/plugins/idpay-for-edd/assets/js/edd-idpay.js
Version Parameters
idpay-for-edd/assets/css/edd-idpay.css?ver=idpay-for-edd/assets/js/edd-idpay.js?ver=

HTML / DOM Fingerprints

CSS Classes
idpay-payment-form
HTML Comments
<!-- IDPay Gateway Options --><!-- IDPay Settings --><!-- IDPay Sandbox --><!-- IDPay API Key -->+1 more
Data Attributes
data-idpay-gateway-noncedata-idpay-gateway-key
FAQ

Frequently Asked Questions about IDPay for Easy Digital Downloads (EDD)