
Subscriber Discounts for Easy Digital Downloads Security & Risk Analysis
wordpress.org/plugins/subscriber-discounts-for-easy-digital-downloadsEasily send mailing list subscribers a discount code for joining your list.
Is Subscriber Discounts for Easy Digital Downloads Safe to Use in 2026?
Generally Safe
Score 85/100Subscriber Discounts for Easy Digital Downloads has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.
The subscriber-discounts-for-easy-digital-downloads plugin v1.1.3 exhibits a generally good security posture based on the provided static analysis and vulnerability history. The absence of known CVEs, dangerous functions, raw SQL queries, file operations, and external HTTP requests is a strong positive indicator. Furthermore, the plugin appears to have a very small attack surface, with zero identified entry points like AJAX handlers, REST API routes, or shortcodes, and no cron events. This significantly reduces the immediate avenues for attackers to exploit.
However, there are areas of concern that prevent a perfect security score. The most significant weakness lies in the output escaping, with only 35% of identified outputs being properly escaped. This could leave the plugin vulnerable to cross-site scripting (XSS) attacks if user-supplied data is displayed without sufficient sanitization. While the taint analysis shows no unsanitized paths, this could be due to the limited attack surface and lack of complex data flows being analyzed. The complete lack of nonce checks and capability checks is also a concern, as these are fundamental security mechanisms in WordPress for preventing unauthorized actions and ensuring proper authorization on any potential, albeit currently unexposed, entry points.
Overall, the plugin is strong in its foundational security elements and has a clean vulnerability history. Its limited attack surface is a significant strength. However, the poor output escaping and the absence of essential WordPress security checks (nonces, capabilities) are notable weaknesses that warrant attention and could be exploited if any of the currently unexposed entry points were to be introduced or if user-supplied data is processed in unexpected ways. Addressing the output escaping and implementing capability checks would significantly improve its security.
Key Concerns
- Poor output escaping
- Missing nonce checks
- Missing capability checks
Subscriber Discounts for Easy Digital Downloads Security Vulnerabilities
Subscriber Discounts for Easy Digital Downloads Code Analysis
SQL Query Safety
Output Escaping
Subscriber Discounts for Easy Digital Downloads Attack Surface
WordPress Hooks 7
Maintenance & Trust
Subscriber Discounts for Easy Digital Downloads Maintenance & Trust
Maintenance Signals
Community Trust
Subscriber Discounts for Easy Digital Downloads Alternatives
Subscriber Discounts for WooCommerce
subscriber-discounts-for-woocommerce
Easily send mailing list subscribers a discount code for joining your list.
Subscribe Mailchimp for EDD
edd-mailchimp-subscribe
Subscribe Mailchimp for EDD WordPress plugin displays a newsletter signup checkbox on checkout for Easy Digital Downloads integrated with MailChimp
Coupon Counter for EDD
edd-coupon-counter
Easily display the remaining or used coupon codes with Easy Digital Downloads (EDD).
EDD First Time Buyer's Gift
edd-first-time-buyers-gift
Increase customer satisfaction and repeat business by generating and assigning discounts for buyers after their first purchase.
UpsellMaster – Upsells and Cross Sell Everywhere for WooCommerce and Easy Digital Downloads (EDD)
psupsellmaster
UpsellMaster boosts conversions with tailored upsells, discounts, and recently viewed products for WooCommerce and EDD, increasing order values.
Subscriber Discounts for Easy Digital Downloads Developer Profile
15 plugins · 13K total installs
How We Detect Subscriber Discounts for Easy Digital Downloads
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/subscriber-discounts-for-easy-digital-downloads/includes/admin/css/sdedd-admin.css/wp-content/plugins/subscriber-discounts-for-easy-digital-downloads/includes/admin/js/sdedd-admin.jssubscriber-discounts-for-easy-digital-downloads/includes/admin/css/sdedd-admin.css?ver=subscriber-discounts-for-easy-digital-downloads/includes/admin/js/sdedd-admin.js?ver=HTML / DOM Fingerprints
sdedd_mailchimp_keysdedd_mailchimp_listsdedd_activecampaign_keysdedd_activecampaign_listsdedd_activecampaign_fielddata-mailchimp-keydata-mailchimp-listdata-activecampaign-keydata-activecampaign-listdata-activecampaign-fieldsdedd_admin_ajax