Postmark Open to EDD Customer Note Security & Risk Analysis

wordpress.org/plugins/postmark-open-to-edd-customer-note

Add a Customer Note when a Postmark-delivered email has been opened by an EDD Customer

0 active installs v1.0.0 PHP 5.6+ WP 4.8+ Updated Feb 10, 2022
eddnoteopenpostmarkwebhook
85
A · Safe
CVEs total0
Unpatched0
Last CVENever
Safety Verdict

Is Postmark Open to EDD Customer Note Safe to Use in 2026?

Generally Safe

Score 85/100

Postmark Open to EDD Customer Note has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.

No known CVEs Updated 4yr ago
Risk Assessment

Based on the static analysis, the "postmark-open-to-edd-customer-note" plugin version 1.0.0 exhibits a strong security posture in several key areas. The absence of AJAX handlers, REST API routes, shortcodes, and cron events significantly limits the plugin's attack surface. Furthermore, the code demonstrates good practices by employing prepared statements for all SQL queries and properly escaping all output. The lack of file operations and external HTTP requests, while not explicitly stated as absent, are not flagged as risks, indicating a potentially clean implementation in these regards.

However, the analysis also highlights some areas for concern. The complete absence of nonce checks and capability checks across all entry points is a significant weakness. While the current attack surface is reported as zero, this implies that if any new entry points were introduced or if the existing ones were inadvertently exposed, they would be entirely unprotected against unauthorized access or manipulation. The presence of one external HTTP request, without further context on its purpose and implementation, also warrants careful consideration regarding potential vulnerabilities related to external service interactions.

The vulnerability history is entirely clean, with no recorded CVEs, which is a positive indicator of the plugin's historical security. This, combined with the good coding practices observed in SQL and output handling, suggests that the developers are likely aware of security principles. Nevertheless, the lack of robust access control mechanisms (nonces and capabilities) represents a critical oversight that could be exploited should any new functionalities be added or if the existing structure becomes vulnerable. The overall risk is low due to the current limited attack surface, but the potential for vulnerabilities exists due to the missing access control.

Key Concerns

  • No nonce checks on entry points
  • No capability checks on entry points
Vulnerabilities
None known

Postmark Open to EDD Customer Note Security Vulnerabilities

No known vulnerabilities — this is a good sign.
Code Analysis
Analyzed Mar 17, 2026

Postmark Open to EDD Customer Note Code Analysis

Dangerous Functions
0
Raw SQL Queries
0
0 prepared
Unescaped Output
0
6 escaped
Nonce Checks
0
Capability Checks
0
File Operations
0
External Requests
1
Bundled Libraries
0

Output Escaping

100% escaped6 total outputs
Attack Surface

Postmark Open to EDD Customer Note Attack Surface

Entry Points0
Unprotected0
WordPress Hooks 4
actioninitpostmark-open-to-edd-customer-note.php:24
actionadmin_noticespostmark-open-to-edd-customer-note.php:32
actionadmin_noticespostmark-open-to-edd-customer-note.php:38
actionrest_api_initpostmark-open-to-edd-customer-note.php:47
Maintenance & Trust

Postmark Open to EDD Customer Note Maintenance & Trust

Maintenance Signals

WordPress version tested5.9.0
Last updatedFeb 10, 2022
PHP min version5.6
Downloads1K

Community Trust

Rating100/100
Number of ratings1
Active installs0
Developer Profile

Postmark Open to EDD Customer Note Developer Profile

Jon Christopher

11 plugins · 110K total installs

86
trust score
Avg Security Score
89/100
Avg Patch Time
30 days
View full developer profile
Detection Fingerprints

How We Detect Postmark Open to EDD Customer Note

Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.

Asset Fingerprints

HTML / DOM Fingerprints

REST Endpoints
/wp-json/pmeddcn/v1/open
FAQ

Frequently Asked Questions about Postmark Open to EDD Customer Note