
MyStem EDD Security & Risk Analysis
wordpress.org/plugins/mystem-eddThis plugin helps you to create a store with Easy Digital Downloads and WordPress theme MyStem.
Is MyStem EDD Safe to Use in 2026?
Generally Safe
Score 85/100MyStem EDD has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.
The mystem-edd v1.1 plugin exhibits a generally strong security posture based on the provided static analysis. The absence of dangerous functions, the exclusive use of prepared statements for SQL queries, and the presence of nonce and capability checks are positive indicators. The code's adherence to output escaping for a significant majority of its outputs (69%) suggests a good effort towards preventing cross-site scripting vulnerabilities.
However, the analysis also reveals potential areas for improvement. While the attack surface is currently small and appears to have no unprotected entry points, the presence of three shortcodes means there are potential interaction points that could be exploited if not properly secured internally. The 31% of outputs that are not properly escaped represent a moderate risk of cross-site scripting (XSS) vulnerabilities, which could be leveraged to compromise user sessions or inject malicious content.
The plugin's vulnerability history, showing zero known CVEs and no past vulnerabilities, is a positive sign. This indicates a history of stability and potentially good security practices in previous development cycles. Overall, mystem-edd v1.1 demonstrates a good foundation with its use of security best practices, but the unescaped output percentages warrant attention to fully mitigate potential XSS risks.
Key Concerns
- Unescaped output detected
MyStem EDD Security Vulnerabilities
MyStem EDD Release Timeline
MyStem EDD Code Analysis
Output Escaping
MyStem EDD Attack Surface
Shortcodes 3
WordPress Hooks 31
Maintenance & Trust
MyStem EDD Maintenance & Trust
Maintenance Signals
Community Trust
MyStem EDD Alternatives
Easy Digital Downloads Free Link
easy-digital-downloads-free-link
replace EDD add-to-cart button with download link when product is free
EDD Auto Register
edd-auto-register
Automatically creates a WP user account at checkout, based on customer's email address.
Easy Digital Downloads Featured Downloads
edd-featured-downloads
Easily feature your downloads
Counten- Sale Counter Advanced
counten-sale-counter-advanced
A Sale Counter Plugin work with the Easy Digital Download Products
Sale Price for EDD
edd-sale-price
Promote your downloads with a sale price!
MyStem EDD Developer Profile
26 plugins · 98K total installs
How We Detect MyStem EDD
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/mystem-edd/assets/css/style.css/wp-content/plugins/mystem-edd/assets/js/image-slides.js/wp-content/plugins/mystem-edd/assets/js/taxonomy.js/wp-content/plugins/mystem-edd/assets/js/image-slides.js/wp-content/plugins/mystem-edd/assets/js/taxonomy.jsHTML / DOM Fingerprints
color-picker-fieldname="mystem_cat_meta[icon_field]"name="mystem_cat_meta[icon_color]"name="mystem_cat_meta[cat_template]"name="mystem_cat_meta[hide_header]"