Sepordeh Payment Gateway for Easy Digital Downloads (EDD) Security & Risk Analysis

wordpress.org/plugins/sepordeh-payment-gateway-for-easy-digital-downloads-edd

this plugin add Sepordeh payment method for Easy Digital Downloads (EDD)

0 active installs v3.0.1 PHP 5.0+ WP 4.7+ Updated Oct 20, 2023
easy-digital-downloadseddpaymentpayment-gatewaysepordeh
85
A · Safe
CVEs total0
Unpatched0
Last CVENever
Safety Verdict

Is Sepordeh Payment Gateway for Easy Digital Downloads (EDD) Safe to Use in 2026?

Generally Safe

Score 85/100

Sepordeh Payment Gateway for Easy Digital Downloads (EDD) has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.

No known CVEs Updated 2yr ago
Risk Assessment

Based on the provided static analysis and vulnerability history, the 'sepordeh-payment-gateway-for-easy-digital-downloads-edd' v3.0.1 plugin exhibits a strong security posture regarding core WordPress security practices. The absence of any recorded CVEs and a clean vulnerability history is a significant positive indicator. Furthermore, the code analysis reveals a complete lack of dangerous functions, file operations, and raw SQL queries, with all SQL queries utilizing prepared statements. All output is properly escaped, which is excellent for preventing cross-site scripting vulnerabilities. The plugin also has no apparent attack surface exposed through AJAX, REST API, shortcodes, or cron events, which limits potential entry points for attackers.

However, there are a few areas for potential concern. The presence of two external HTTP requests without further context raises a minor flag, as these could potentially be exploited if the remote endpoints are compromised or if the data sent is not properly sanitized. More significantly, the plugin has zero nonce checks and zero capability checks across its entire analyzed code. This is a substantial weakness. While the current analysis shows no unprotected entry points, the complete absence of these fundamental WordPress security mechanisms means that if any entry points were to be introduced in future updates or through other means, they would be inherently unprotected, leaving the site vulnerable to various attacks like Cross-Site Request Forgery (CSRF) or unauthorized actions by unauthenticated or low-privileged users.

In conclusion, the plugin demonstrates commendable secure coding practices in many areas, particularly in SQL handling and output escaping, and its historical lack of vulnerabilities is reassuring. However, the complete absence of nonce and capability checks is a critical oversight that significantly weakens its overall security, making it vulnerable if any new entry points are added or if existing, unanalyzed code paths exist.

Key Concerns

  • Missing nonce checks
  • Missing capability checks
  • External HTTP requests (2)
Vulnerabilities
None known

Sepordeh Payment Gateway for Easy Digital Downloads (EDD) Security Vulnerabilities

No known vulnerabilities — this is a good sign.
Code Analysis
Analyzed Mar 17, 2026

Sepordeh Payment Gateway for Easy Digital Downloads (EDD) Code Analysis

Dangerous Functions
0
Raw SQL Queries
0
0 prepared
Unescaped Output
0
13 escaped
Nonce Checks
0
Capability Checks
0
File Operations
0
External Requests
2
Bundled Libraries
0

Output Escaping

100% escaped13 total outputs
Attack Surface

Sepordeh Payment Gateway for Easy Digital Downloads (EDD) Attack Surface

Entry Points0
Unprotected0
WordPress Hooks 11
actioninitedd-sepordeh.php:15
filteredd_payment_gatewaysgateways\sepordeh.php:28
filteredd_settings_gatewaysgateways\sepordeh.php:32
actionedd_payment_receipt_aftergateways\sepordeh.php:34
actioninitgateways\sepordeh.php:36
filteredd_currenciesincludes\toman-currency.php:21
filteredd_sanitize_amount_decimalsincludes\toman-currency.php:26
filteredd_format_amount_decimalsincludes\toman-currency.php:39
filteredd_irt_currency_filter_afterincludes\toman-currency.php:53
filteredd_irt_currency_filter_afterincludes\toman-currency.php:56
filteredd_rial_currency_filter_afterincludes\toman-currency.php:61
Maintenance & Trust

Sepordeh Payment Gateway for Easy Digital Downloads (EDD) Maintenance & Trust

Maintenance Signals

WordPress version tested6.3.8
Last updatedOct 20, 2023
PHP min version5.0
Downloads766

Community Trust

Rating0/100
Number of ratings0
Active installs0
Developer Profile

Sepordeh Payment Gateway for Easy Digital Downloads (EDD) Developer Profile

SEPORDEH

1 plugin · 0 total installs

84
trust score
Avg Security Score
85/100
Avg Patch Time
30 days
View full developer profile
Detection Fingerprints

How We Detect Sepordeh Payment Gateway for Easy Digital Downloads (EDD)

Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.

Asset Fingerprints

Version Parameters
/wp-content/plugins/sepordeh-payment-gateway-for-easy-digital-downloads-edd/edd-sepordeh.php?ver=/wp-content/plugins/sepordeh-payment-gateway-for-easy-digital-downloads-edd/includes/toman-currency.php?ver=/wp-content/plugins/sepordeh-payment-gateway-for-easy-digital-downloads-edd/gateways/sepordeh.php?ver=

HTML / DOM Fingerprints

CSS Classes
sepordeh-ref-id-rowezp-fieldsepordeh
HTML Comments
<!-- Sepordeh Gateway for Easy Digital Downloads --><!-- Toman Currency --><!-- Include the main file --><!-- We don't need it anyway. -->+23 more
Data Attributes
sepordeh_merchantsepordeh_labelsepordeh_header
JS Globals
window.edd_sepordeh_params
FAQ

Frequently Asked Questions about Sepordeh Payment Gateway for Easy Digital Downloads (EDD)