Storage for EDD via Dropbox Security & Risk Analysis

wordpress.org/plugins/storage-for-edd-via-dropbox

Enable secure cloud storage and delivery of your digital products through Dropbox for Easy Digital Downloads.

0 active installs v1.1.0 PHP 7.4+ WP 5.0+ Updated Feb 24, 2026
clouddropboxeasy-digital-downloadseddstorage
100
A · Safe
CVEs total0
Unpatched0
Last CVENever
Download
Safety Verdict

Is Storage for EDD via Dropbox Safe to Use in 2026?

Generally Safe

Score 100/100

Storage for EDD via Dropbox has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.

No known CVEs Updated 1mo ago
Risk Assessment

The plugin "storage-for-edd-via-dropbox" v1.1.0 exhibits a generally good security posture based on the provided static analysis. The absence of known vulnerabilities and a strong emphasis on secure coding practices like prepared statements for SQL queries and robust output escaping (98%) are positive indicators. The plugin also demonstrates good use of nonces and capability checks, with all identified entry points appearing to be protected by authentication or authorization mechanisms.

However, the static analysis did reveal a potential area of concern: all 7 analyzed taint flows contained unsanitized paths. While no critical or high severity issues were identified in the taint analysis, this pattern suggests that user-supplied input that influences file paths is not being adequately sanitized. This could potentially lead to path traversal vulnerabilities if not handled with extreme care at runtime, especially given that file operations are present. The vulnerability history being completely clear is a significant strength, suggesting a consistent record of security awareness from the developers.

In conclusion, the plugin has a strong foundation of secure coding practices. The primary weakness lies in the unsanitized paths within taint flows, which warrants careful review to ensure no exploitable path traversal issues exist. The lack of past vulnerabilities is a positive sign, but the current findings in taint analysis should not be overlooked.

Key Concerns

  • Taint flows with unsanitized paths
Vulnerabilities
None known

Storage for EDD via Dropbox Security Vulnerabilities

No known vulnerabilities — this is a good sign.
Code Analysis
Analyzed Mar 17, 2026

Storage for EDD via Dropbox Code Analysis

Dangerous Functions
0
Raw SQL Queries
0
0 prepared
Unescaped Output
1
65 escaped
Nonce Checks
6
Capability Checks
7
File Operations
1
External Requests
0
Bundled Libraries
1

Bundled Libraries

Guzzle

Output Escaping

98% escaped66 total outputs
Data Flows
7 unsanitized

Data Flow Analysis

7 flows7 with unsanitized paths
performFileUpload (includes\class-dropbox-uploader.php:31)
Source (user input) Sink (dangerous op) Sanitizer Transform Unsanitized Sanitized
Attack Surface

Storage for EDD via Dropbox Attack Surface

Entry Points2
Unprotected0

AJAX Handlers 2

authwp_ajax_dbxe_ajax_uploadincludes\class-dropbox-uploader.php:25
authwp_ajax_dbxe_get_libraryincludes\class-media-library.php:32
WordPress Hooks 19
filteredd_settings_extensionsincludes\class-admin-settings.php:23
filteredd_settings_sections_extensionsincludes\class-admin-settings.php:24
actionadmin_enqueue_scriptsincludes\class-admin-settings.php:27
actionadmin_post_dbxe_oauth_startincludes\class-admin-settings.php:30
actionadmin_post_dbxe_disconnectincludes\class-admin-settings.php:31
actioninitincludes\class-admin-settings.php:34
actiontemplate_redirectincludes\class-admin-settings.php:35
filterquery_varsincludes\class-admin-settings.php:38
actioninitincludes\class-admin-settings.php:41
actionadmin_noticesincludes\class-admin-settings.php:44
filterpre_update_option_edd_settingsincludes\class-admin-settings.php:47
filterallowed_redirect_hostsincludes\class-admin-settings.php:383
actionadmin_post_dbxe_uploadincludes\class-dropbox-uploader.php:22
actionadmin_noticesincludes\class-main-plugin.php:28
filteredd_requested_fileincludes\class-main-plugin.php:37
actionadmin_enqueue_scriptsincludes\class-media-library.php:23
actionedd_download_file_table_rowincludes\class-media-library.php:26
actionadmin_footerincludes\class-media-library.php:29
actionplugins_loadedstorage-for-edd-via-dropbox.php:44
Maintenance & Trust

Storage for EDD via Dropbox Maintenance & Trust

Maintenance Signals

WordPress version tested6.9.4
Last updatedFeb 24, 2026
PHP min version7.4
Downloads282

Community Trust

Rating100/100
Number of ratings1
Active installs0
Developer Profile

Storage for EDD via Dropbox Developer Profile

mohammadr3z

9 plugins · 51K total installs

94
trust score
Avg Security Score
100/100
Avg Patch Time
30 days
View full developer profile
Detection Fingerprints

How We Detect Storage for EDD via Dropbox

Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.

Asset Fingerprints

Asset Paths
/wp-content/plugins/storage-for-edd-via-dropbox/assets/js/dbxe-admin-script.js
Script Paths
/wp-content/plugins/storage-for-edd-via-dropbox/assets/js/dbxe-admin-script.js
Version Parameters
storage-for-edd-via-dropbox/assets/js/dbxe-admin-script.js?ver=

HTML / DOM Fingerprints

CSS Classes
dbxe-dropbox-connecteddbxe-dropbox-disconnected
HTML Comments
<!-- Dropbox Storage for EDD Settings --><!-- Dropbox Storage for EDD Settings Section -->
Data Attributes
data-connected-status
JS Globals
dbxe_admin_script_params
FAQ

Frequently Asked Questions about Storage for EDD via Dropbox