SagePay Direct Gateway for Easy Digital Downloads Security & Risk Analysis

wordpress.org/plugins/sagepay-direct-gateway-for-easy-digital-downloads

SagePay Direct Gateway for accepting payments on your Easy Digital Downloads Store.

10 active installs v1.0.0 PHP + WP 3.5+ Updated Sep 1, 2016
easy-digital-downloadsecommercepayment-gatewaysagepay
85
A · Safe
CVEs total0
Unpatched0
Last CVENever
Safety Verdict

Is SagePay Direct Gateway for Easy Digital Downloads Safe to Use in 2026?

Generally Safe

Score 85/100

SagePay Direct Gateway for Easy Digital Downloads has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.

No known CVEs Updated 9yr ago
Risk Assessment

The "sagepay-direct-gateway-for-easy-digital-downloads" plugin version 1.0.0 exhibits a strong security posture in several key areas, particularly regarding its limited attack surface and SQL query handling. The absence of AJAX handlers, REST API routes, shortcodes, and cron events suggests a minimal exposure to common attack vectors. Furthermore, all SQL queries are correctly prepared, which is an excellent practice for preventing SQL injection vulnerabilities. The plugin also avoids file operations and does not bundle external libraries, further reducing its potential for introducing vulnerabilities.

However, there are notable areas for improvement. The plugin has a concerning 56% of its output functions that are not properly escaped. This could lead to Cross-Site Scripting (XSS) vulnerabilities if user-supplied data is not sanitized before being displayed. Additionally, the lack of nonce checks and capability checks on any potential entry points (though the static analysis reports zero entry points, this is a significant omission if any were to be added in the future or if the analysis missed something) is a concern, as these are fundamental WordPress security mechanisms for preventing CSRF and unauthorized actions. The plugin also makes external HTTP requests, which, while not inherently a vulnerability, can be a vector for attacks if not handled securely.

The plugin's vulnerability history is remarkably clean, with no recorded CVEs. This indicates a potentially well-maintained codebase or simply a lack of past exploitation, but it does not negate the existing concerns identified in the static analysis. In conclusion, while the plugin demonstrates strengths in its limited attack surface and secure SQL practices, the significant percentage of unescaped output and the absence of essential security checks represent tangible risks that should be addressed to improve its overall security.

Key Concerns

  • Unescaped output detected
  • Missing nonce checks
  • Missing capability checks
Vulnerabilities
None known

SagePay Direct Gateway for Easy Digital Downloads Security Vulnerabilities

No known vulnerabilities — this is a good sign.
Version History

SagePay Direct Gateway for Easy Digital Downloads Release Timeline

v1.0.0Current
Code Analysis
Analyzed Apr 16, 2026

SagePay Direct Gateway for Easy Digital Downloads Code Analysis

Dangerous Functions
0
Raw SQL Queries
0
0 prepared
Unescaped Output
5
4 escaped
Nonce Checks
0
Capability Checks
0
File Operations
0
External Requests
2
Bundled Libraries
0

Output Escaping

44% escaped9 total outputs
Attack Surface

SagePay Direct Gateway for Easy Digital Downloads Attack Surface

Entry Points0
Unprotected0
WordPress Hooks 5
filteredd_payment_gatewaysedd-sagepay-direct.php:25
actionedd_before_cc_expirationedd-sagepay-direct.php:61
actionedd_gateway_sagepay_directedd-sagepay-direct.php:266
actioninitedd-sagepay-direct.php:363
filteredd_settings_gatewaysedd-sagepay-direct.php:483
Maintenance & Trust

SagePay Direct Gateway for Easy Digital Downloads Maintenance & Trust

Maintenance Signals

WordPress version tested4.6.30
Last updatedSep 1, 2016
PHP min version
Downloads1K

Community Trust

Rating80/100
Number of ratings1
Active installs10
Developer Profile

SagePay Direct Gateway for Easy Digital Downloads Developer Profile

PatSaTECH

10 plugins · 390 total installs

74
trust score
Avg Security Score
93/100
Avg Patch Time
2228 days
View full developer profile
Detection Fingerprints

How We Detect SagePay Direct Gateway for Easy Digital Downloads

Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.

Asset Fingerprints

HTML / DOM Fingerprints

CSS Classes
edd-labeledd-descriptionedd-selectedd-required-indicator
Data Attributes
name="card_type"class="edd-select required"
Shortcode Output
<p id="edd-card-type-wrap">
FAQ

Frequently Asked Questions about SagePay Direct Gateway for Easy Digital Downloads