
VKShop for Easy Digital Downloads Security & Risk Analysis
wordpress.org/plugins/vkshop-for-eddАвтоматическая синхронизация магазина на Easy Digital Downloads c разделом Товары ВКонтакте.
Is VKShop for Easy Digital Downloads Safe to Use in 2026?
Generally Safe
Score 85/100VKShop for Easy Digital Downloads has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.
The vkshop-for-edd plugin v0.9 exhibits a concerning security posture due to a significant unprotected entry point. While the plugin demonstrates good practices in its SQL query handling, showing 100% prepared statement usage, and has no recorded vulnerability history, these strengths are overshadowed by its attack surface. The presence of an AJAX handler without any authentication or capability checks represents a direct pathway for potential unauthorized actions. Furthermore, the taint analysis indicates flows with unsanitized paths, suggesting that user-supplied data might not be properly validated before being processed, although no critical or high severity issues were identified in this analysis. The limited code signals also point to potential weaknesses, such as the use of the dangerous `create_function` and a low percentage of properly escaped output, which could lead to cross-site scripting vulnerabilities if user-controlled data is echoed without sufficient sanitization. The lack of any nonce checks on its AJAX endpoint further exacerbates the risk, as it leaves the entry point vulnerable to cross-site request forgery (CSRF) attacks. In conclusion, while the plugin's historical security record is clean and its SQL practices are commendable, the current version presents tangible risks due to its unprotected AJAX endpoint and potential for data sanitization and output escaping issues.
Key Concerns
- AJAX handler without auth check
- Unsanitized paths in taint analysis
- Low percentage of properly escaped output
- Use of dangerous create_function
- No nonce checks on AJAX
VKShop for Easy Digital Downloads Security Vulnerabilities
VKShop for Easy Digital Downloads Release Timeline
VKShop for Easy Digital Downloads Code Analysis
Dangerous Functions Found
SQL Query Safety
Output Escaping
Data Flow Analysis
VKShop for Easy Digital Downloads Attack Surface
AJAX Handlers 1
WordPress Hooks 44
Maintenance & Trust
VKShop for Easy Digital Downloads Maintenance & Trust
Maintenance Signals
Community Trust
VKShop for Easy Digital Downloads Alternatives
Events Tracker for Elementor
events-tracker-for-elementor
Track Click or Submit events and conversions for any Elementor widget with Google Analytics, Facebook, Yandex Metrika, Vkontakte.
Meks Easy Social Share
meks-easy-social-share
Easily display social share buttons for your posts, pages and custom post types. Supports Facebook, Twitter, Reddit, Pinterest, Email, Google+, Linked …
Social Comments by Heateor
heateor-social-comments
Integrate Facebook Comments, Vkontakte Comments and/or Disqus Comments along with default comment form at your website
Import VK
import-vk
Importing VKontakte (vk.com) posts into your WordPress site.
VKontakte
vkontakte
The plugin adds a wide range of VKontakte functionality to your site.
VKShop for Easy Digital Downloads Developer Profile
6 plugins · 20 total installs
How We Detect VKShop for Easy Digital Downloads
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/vkshop-for-edd/css/vkshop-for-edd.css/wp-content/plugins/vkshop-for-edd/js/vkshop-for-edd.js/wp-content/plugins/vkshop-for-edd/inc/wp-settings-api-class-edd.php/wp-content/plugins/vkshop-for-edd/inc/wp-help-pointer-class-edd.php/wp-content/plugins/vkshop-for-edd/inc/vkwp-api-edd.php/wp-content/plugins/vkshop-for-edd/vks-functions.php/wp-content/plugins/vkshop-for-edd/vks-export.php/wp-content/plugins/vkshop-for-edd/vks-admin.phpwp-content/plugins/vkshop-for-edd/js/vkshop-for-edd.jsvkshop-for-edd/css/vkshop-for-edd.css?ver=vkshop-for-edd/js/vkshop-for-edd.js?ver=HTML / DOM Fingerprints
vksvks-boxvks-boxxdata-targetdata-iddata-screendata-titledata-contentdata-positionWP_Help_Pointer_Edd