Storage for EDD via Box Security & Risk Analysis

wordpress.org/plugins/storage-for-edd-via-box

Enable secure cloud storage and delivery of your digital products through Box for Easy Digital Downloads.

0 active installs v1.1.0 PHP 7.4+ WP 5.0+ Updated Mar 15, 2026
boxcloudeasy-digital-downloadseddstorage
100
A · Safe
CVEs total0
Unpatched0
Last CVENever
Download
Safety Verdict

Is Storage for EDD via Box Safe to Use in 2026?

Generally Safe

Score 100/100

Storage for EDD via Box has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.

No known CVEs Updated 19d ago
Risk Assessment

The "storage-for-edd-via-box" plugin version 1.1.0 exhibits a generally strong security posture based on the provided static analysis and vulnerability history. The plugin implements robust security measures such as comprehensive nonce and capability checks on its entry points, and all identified SQL queries utilize prepared statements. Furthermore, a high percentage of output is properly escaped, and there are no recorded historical vulnerabilities, suggesting a diligent development team and stable codebase.

However, a notable concern arises from the taint analysis, which indicates four flows with unsanitized paths. While the analysis did not flag these as critical or high severity, unsanitized paths are a potential vector for injection attacks if user-supplied data is not handled with extreme care. The presence of file operations, even if only one is identified, also warrants attention, particularly in conjunction with unsanitized paths.

In conclusion, the plugin demonstrates good security practices with a clean vulnerability history and strong authentication/authorization mechanisms. The primary area for improvement lies in thoroughly sanitizing all user-supplied input that flows into potentially sensitive operations, especially those involving file operations. Addressing these unsanitized paths would significantly enhance the plugin's overall security.

Key Concerns

  • Flows with unsanitized paths found
  • File operation identified
Vulnerabilities
None known

Storage for EDD via Box Security Vulnerabilities

No known vulnerabilities — this is a good sign.
Code Analysis
Analyzed Mar 17, 2026

Storage for EDD via Box Code Analysis

Dangerous Functions
0
Raw SQL Queries
0
0 prepared
Unescaped Output
1
61 escaped
Nonce Checks
4
Capability Checks
5
File Operations
1
External Requests
0
Bundled Libraries
1

Bundled Libraries

Guzzle

Output Escaping

98% escaped62 total outputs
Data Flows
4 unsanitized

Data Flow Analysis

4 flows4 with unsanitized paths
ajaxUpload (includes\class-box-uploader.php:27)
Source (user input) Sink (dangerous op) Sanitizer Transform Unsanitized Sanitized
Attack Surface

Storage for EDD via Box Attack Surface

Entry Points2
Unprotected0

AJAX Handlers 2

authwp_ajax_edbx_ajax_uploadincludes\class-box-uploader.php:21
authwp_ajax_edbx_get_libraryincludes\class-media-library.php:32
WordPress Hooks 18
filteredd_settings_extensionsincludes\class-admin-settings.php:23
filteredd_settings_sections_extensionsincludes\class-admin-settings.php:24
actionadmin_enqueue_scriptsincludes\class-admin-settings.php:27
actionadmin_post_edbx_oauth_startincludes\class-admin-settings.php:30
actionadmin_post_edbx_disconnectincludes\class-admin-settings.php:31
actioninitincludes\class-admin-settings.php:34
actiontemplate_redirectincludes\class-admin-settings.php:35
filterquery_varsincludes\class-admin-settings.php:38
actioninitincludes\class-admin-settings.php:41
actionadmin_noticesincludes\class-admin-settings.php:44
filterpre_update_option_edd_settingsincludes\class-admin-settings.php:47
filterallowed_redirect_hostsincludes\class-admin-settings.php:388
actionadmin_noticesincludes\class-main-plugin.php:27
filteredd_requested_fileincludes\class-main-plugin.php:36
actionadmin_enqueue_scriptsincludes\class-media-library.php:23
actionedd_download_file_table_rowincludes\class-media-library.php:26
actionadmin_footerincludes\class-media-library.php:29
actionplugins_loadedstorage-for-edd-via-box.php:44
Maintenance & Trust

Storage for EDD via Box Maintenance & Trust

Maintenance Signals

WordPress version tested6.9.4
Last updatedMar 15, 2026
PHP min version7.4
Downloads34

Community Trust

Rating0/100
Number of ratings0
Active installs0
Developer Profile

Storage for EDD via Box Developer Profile

mohammadr3z

9 plugins · 51K total installs

94
trust score
Avg Security Score
100/100
Avg Patch Time
30 days
View full developer profile
Detection Fingerprints

How We Detect Storage for EDD via Box

Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.

Asset Fingerprints

Asset Paths
/wp-content/plugins/storage-for-edd-via-box/assets/css/box-integration.css/wp-content/plugins/storage-for-edd-via-box/assets/js/box-integration.js
Script Paths
/wp-content/plugins/storage-for-edd-via-box/assets/js/box-integration.js
Version Parameters
storage-for-edd-via-box/assets/css/box-integration.css?ver=storage-for-edd-via-box/assets/js/box-integration.js?ver=

HTML / DOM Fingerprints

CSS Classes
edbx-settings-section-titleedbx-oauth-status-connectededbx-oauth-status-disconnectededbx-folder-selector-wrapperedbx-folder-selectoredbx-input-groupedbx-button-groupedbx-button-primary+2 more
HTML Comments
<!-- Main Box Storage Plugin Settings --><!-- Box OAuth Status --><!-- Box Folder Selector --><!-- EDD Settings: Box Integration -->
Data Attributes
data-edbx-oauth-statusdata-edbx-folder-iddata-edbx-folder-name
JS Globals
edbx_admin_params
REST Endpoints
/wp-json/edbx/v1/folders
FAQ

Frequently Asked Questions about Storage for EDD via Box