Subscriber Discounts for Easy Digital Downloads Security & Risk Analysis

wordpress.org/plugins/subscriber-discounts-for-easy-digital-downloads

Easily send mailing list subscribers a discount code for joining your list.

10 active installs v1.1.3 PHP + WP 2.9+ Updated Apr 4, 2023
activecampaigndiscountseasy-digital-downloadsmailchimp
85
A · Safe
CVEs total0
Unpatched0
Last CVENever
Safety Verdict

Is Subscriber Discounts for Easy Digital Downloads Safe to Use in 2026?

Generally Safe

Score 85/100

Subscriber Discounts for Easy Digital Downloads has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.

No known CVEs Updated 3yr ago
Risk Assessment

The subscriber-discounts-for-easy-digital-downloads plugin v1.1.3 exhibits a generally good security posture based on the provided static analysis and vulnerability history. The absence of known CVEs, dangerous functions, raw SQL queries, file operations, and external HTTP requests is a strong positive indicator. Furthermore, the plugin appears to have a very small attack surface, with zero identified entry points like AJAX handlers, REST API routes, or shortcodes, and no cron events. This significantly reduces the immediate avenues for attackers to exploit.

However, there are areas of concern that prevent a perfect security score. The most significant weakness lies in the output escaping, with only 35% of identified outputs being properly escaped. This could leave the plugin vulnerable to cross-site scripting (XSS) attacks if user-supplied data is displayed without sufficient sanitization. While the taint analysis shows no unsanitized paths, this could be due to the limited attack surface and lack of complex data flows being analyzed. The complete lack of nonce checks and capability checks is also a concern, as these are fundamental security mechanisms in WordPress for preventing unauthorized actions and ensuring proper authorization on any potential, albeit currently unexposed, entry points.

Overall, the plugin is strong in its foundational security elements and has a clean vulnerability history. Its limited attack surface is a significant strength. However, the poor output escaping and the absence of essential WordPress security checks (nonces, capabilities) are notable weaknesses that warrant attention and could be exploited if any of the currently unexposed entry points were to be introduced or if user-supplied data is processed in unexpected ways. Addressing the output escaping and implementing capability checks would significantly improve its security.

Key Concerns

  • Poor output escaping
  • Missing nonce checks
  • Missing capability checks
Vulnerabilities
None known

Subscriber Discounts for Easy Digital Downloads Security Vulnerabilities

No known vulnerabilities — this is a good sign.
Code Analysis
Analyzed Mar 17, 2026

Subscriber Discounts for Easy Digital Downloads Code Analysis

Dangerous Functions
0
Raw SQL Queries
0
1 prepared
Unescaped Output
11
6 escaped
Nonce Checks
0
Capability Checks
0
File Operations
0
External Requests
0
Bundled Libraries
0

SQL Query Safety

100% prepared1 total queries

Output Escaping

35% escaped17 total outputs
Attack Surface

Subscriber Discounts for Easy Digital Downloads Attack Surface

Entry Points0
Unprotected0
WordPress Hooks 7
actionadmin_menuincludes\options-page.php:6
actionadmin_initincludes\options-page.php:7
actionadmin_initincludes\sdedd.php:10
actionadmin_noticesincludes\sdedd.php:11
actionplugins_loadedsubscriber-discounts-for-easy-digital-downloads.php:18
actionadmin_initsubscriber-discounts-for-easy-digital-downloads.php:36
actioninitsubscriber-discounts-for-easy-digital-downloads.php:74
Maintenance & Trust

Subscriber Discounts for Easy Digital Downloads Maintenance & Trust

Maintenance Signals

WordPress version tested6.1.10
Last updatedApr 4, 2023
PHP min version
Downloads2K

Community Trust

Rating100/100
Number of ratings1
Active installs10
Developer Profile

Subscriber Discounts for Easy Digital Downloads Developer Profile

AMP-MODE

15 plugins · 13K total installs

85
trust score
Avg Security Score
87/100
Avg Patch Time
30 days
View full developer profile
Detection Fingerprints

How We Detect Subscriber Discounts for Easy Digital Downloads

Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.

Asset Fingerprints

Asset Paths
/wp-content/plugins/subscriber-discounts-for-easy-digital-downloads/includes/admin/css/sdedd-admin.css/wp-content/plugins/subscriber-discounts-for-easy-digital-downloads/includes/admin/js/sdedd-admin.js
Version Parameters
subscriber-discounts-for-easy-digital-downloads/includes/admin/css/sdedd-admin.css?ver=subscriber-discounts-for-easy-digital-downloads/includes/admin/js/sdedd-admin.js?ver=

HTML / DOM Fingerprints

CSS Classes
sdedd_mailchimp_keysdedd_mailchimp_listsdedd_activecampaign_keysdedd_activecampaign_listsdedd_activecampaign_field
Data Attributes
data-mailchimp-keydata-mailchimp-listdata-activecampaign-keydata-activecampaign-listdata-activecampaign-field
JS Globals
sdedd_admin_ajax
FAQ

Frequently Asked Questions about Subscriber Discounts for Easy Digital Downloads