
Premium Packages – Sell Digital Products Securely Security & Risk Analysis
wordpress.org/plugins/wpdm-premium-packagesPremium Packages is a free, full-featured WordPress eCommerce plugin to sell digital products easily and securely.
Is Premium Packages – Sell Digital Products Securely Safe to Use in 2026?
Generally Safe
Score 94/100Premium Packages – Sell Digital Products Securely has a strong security track record. Known vulnerabilities have been patched promptly.
The "wpdm-premium-packages" v6.2.0 plugin exhibits a mixed security posture. While it demonstrates some good practices, such as utilizing prepared statements for a significant portion of its SQL queries and implementing nonce and capability checks on some entry points, there are considerable concerns. The large attack surface, with 16 AJAX handlers and a concerning 10 of these lacking authentication checks, presents a significant risk of unauthorized access and potential exploitation. Furthermore, the presence of the `unserialize` function, a known source of vulnerabilities, coupled with a notable percentage of improperly escaped output, increases the susceptibility to various attacks.
Key Concerns
- Unprotected AJAX handlers
- Presence of unserialize function
- Low percentage of properly escaped output
- High severity taint flows
- SQL queries without prepared statements
- Historical medium severity vulnerabilities
Premium Packages – Sell Digital Products Securely Security Vulnerabilities
CVEs by Year
Severity Breakdown
9 total CVEs
WPDM – Premium Packages <= 6.0.2 - Cross-Site Request Forgery
Premium Packages <= 6.0.5 - Authenticated (Contributor+) Stored Cross-Site Scripting
Premium Packages <= 5.9.6 - Authenticated (Administrator+) SQL Injection
Premium Packages – Sell Digital Products Securely <= 5.9.3 - Reflected Cross-Site Scripting via add_query_arg
Premium Packages - Sell Digital Products Securely <= 5.9.3 - Authenticated (Contributor+) Stored Cross-Site Scripting via wpdmpp_pay_link Shortcode
Premium Packages <= 6.0.5 - Authenticated (Administrator+) SQL Injection
Premium Packages – Sell Digital Products Securely <= 5.9.1 - Cross-Site Request Forgery
Premium Packages <= 5.8.2 - Reflected Cross-Site Scripting
Premium Packages - Sell Digital Products Securely <= 5.7.4 - Arbitrary User Meta Update to Authenticated (Subscriber+) Privilege Escalation
Premium Packages – Sell Digital Products Securely Code Analysis
Dangerous Functions Found
SQL Query Safety
Output Escaping
Data Flow Analysis
Premium Packages – Sell Digital Products Securely Attack Surface
AJAX Handlers 16
WordPress Hooks 31
Maintenance & Trust
Premium Packages – Sell Digital Products Securely Maintenance & Trust
Maintenance Signals
Community Trust
Premium Packages – Sell Digital Products Securely Alternatives
Easy Digital Downloads – Empty Cart
easy-digital-downloads-empty-cart
Easily add content to the empty cart display in Easy Digital Downloads.
Easy Digital Downloads – Continue Shopping
easy-digital-downloads-continue-shopping
Adds a Continue Shopping link to the Easy Digital Downloads checkout cart.
Easy Digital Downloads – Clear Cart
easy-digital-downloads-clear-cart
Adds a Clear Cart link to the Easy Digital Downloads checkout cart.
WooCommerce
woocommerce
Everything you need to launch an online store in days and keep it growing for years. From your first sale to millions in revenue, Woo is with you.
Ecwid by Lightspeed Ecommerce Shopping Cart
ecwid-shopping-cart
Powerful, easy to use ecommerce shopping cart for WordPress. Sell on Facebook and Instagram. iPhone & Android apps. Superb support.
Premium Packages – Sell Digital Products Securely Developer Profile
6 plugins · 116K total installs
How We Detect Premium Packages – Sell Digital Products Securely
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/wpdm-premium-packages/assets/css/backend.css/wp-content/plugins/wpdm-premium-packages/assets/css/frontend.css/wp-content/plugins/wpdm-premium-packages/assets/css/animate.min.css/wp-content/plugins/wpdm-premium-packages/assets/css/bootstrap-theme.css/wp-content/plugins/wpdm-premium-packages/assets/css/bootstrap.min.css/wp-content/plugins/wpdm-premium-packages/assets/css/datepicker.css/wp-content/plugins/wpdm-premium-packages/assets/css/font-awesome.min.css/wp-content/plugins/wpdm-premium-packages/assets/css/jquery.dataTables.min.css+17 morePremium Packages - Sell Digital Products Securely/wp-content/plugins/wpdm-premium-packages/assets/js/backend.js/wp-content/plugins/wpdm-premium-packages/assets/js/bootstrap.min.js/wp-content/plugins/wpdm-premium-packages/assets/js/chart.min.js/wp-content/plugins/wpdm-premium-packages/assets/js/custom.js/wp-content/plugins/wpdm-premium-packages/assets/js/datepicker.js/wp-content/plugins/wpdm-premium-packages/assets/js/download-manager.js+6 morewpdm-premium-packages/assets/css/backend.css?ver=wpdm-premium-packages/assets/css/frontend.css?ver=wpdm-premium-packages/assets/css/animate.min.css?ver=wpdm-premium-packages/assets/css/bootstrap-theme.css?ver=wpdm-premium-packages/assets/css/bootstrap.min.css?ver=wpdm-premium-packages/assets/css/datepicker.css?ver=wpdm-premium-packages/assets/css/font-awesome.min.css?ver=wpdm-premium-packages/assets/css/jquery.dataTables.min.css?ver=wpdm-premium-packages/assets/css/jquery.mCustomScrollbar.min.css?ver=wpdm-premium-packages/assets/css/select2.css?ver=wpdm-premium-packages/assets/css/style.css?ver=wpdm-premium-packages/assets/css/sweet-alert.css?ver=wpdm-premium-packages/assets/js/backend.js?ver=wpdm-premium-packages/assets/js/bootstrap.min.js?ver=wpdm-premium-packages/assets/js/chart.min.js?ver=wpdm-premium-packages/assets/js/custom.js?ver=wpdm-premium-packages/assets/js/datepicker.js?ver=wpdm-premium-packages/assets/js/download-manager.js?ver=wpdm-premium-packages/assets/js/front-script.js?ver=wpdm-premium-packages/assets/js/jquery.dataTables.min.js?ver=wpdm-premium-packages/assets/js/jquery.mCustomScrollbar.concat.min.js?ver=wpdm-premium-packages/assets/js/script.js?ver=wpdm-premium-packages/assets/js/select2.js?ver=wpdm-premium-packages/assets/js/sweet-alert.js?ver=HTML / DOM Fingerprints
wpdm-premium-packagewpdm-pp-cart-widgetwpdm-pp-cart-contentswpdm-pp-checkout-formwpdm-pp-order-detailswpdm-pp-add-to-cartwpdm-pp-product-pricewpdm-pp-coupon-form+2 more<!-- WPDMPP Settings --><!-- WPDMPP Premium Package Shortcodes --><!-- End WPDMPP Premium Package Shortcodes -->data-package-iddata-product-iddata-pricedata-currencydata-cart-urldata-checkout-url+2 morewpdmpp_ajax_objectwpdmpp_cartwpdmpp_checkout/wp-json/wpdmpp/v1/cart/wp-json/wpdmpp/v1/order/wp-json/wpdmpp/v1/payment[wpdm_cart][wpdm_checkout][wpdm_order_details][wpdm_buy_now]