Easy Digital Downloads – eCommerce Payments and Subscriptions made easy
by Syed Balkhi · eCommerce
Also makes 95 other plugins · 21.6M+ installs across the portfolio →
The #1 eCommerce plugin to sell digital products & subscriptions. Accept payments with Stripe & PayPal. Sell ebooks, software & more.
94 health vs 68 average across 5,561 eCommerce plugins
Directory ranking optimization
How it's scored →How well this listing is tuned to rank in WordPress.org search, on the factors an owner controls. Not popularity, optimization.
Excellent listing optimization
Well tuned across the board
Daily downloads
Since 2022-10-05 · 1,421 days · wp.org + Plugin Pulse archive
30-day downloads
Rolling 30-day volume · peaks are release surges
55.8K
now · peak 101.6K
Directory rank vs rivals
wp.org popularity rank over time · higher is better · when a rival's line climbs above yours, they've overtaken you
Rating trend
Star average over time · dips mark rough releases
Update activity
How busy the existing users are, measured as downloads in the last 30 days for every 1,000 active sites. A spike means a new release everyone's pulling; a long, slow decline means an aging user base that updates less.
Release cadence
Actively maintainedHow often this plugin actually ships. A steady rhythm is the maintenance signal a single "last updated" date can't show.
16
releases in the last 12 months
2mo ago
latest release · v3.6.9
233
tagged releases on record
Recent releases
What its installed base runs
via wordpress.orgShare of active installs on each version of this plugin. Green is the current release; a big slice on older versions is a user base that has stopped updating.
Estimated active installs
The public count shows “40K+”. Our estimate pins where the real number sits.
Refined from the date this plugin crossed into its current band.
Install history · since 2016-03-20 · 1,500 observations
Estimated value
What this plugin might earn a year, and what it might sell for. Modeled from public signals; we don't see anyone's books.
Est. annual revenue
Est. acquisition value
No paid tier is visible, so we don't put a figure on revenue or sale value: that would be guessing. The install base is a real asset to an acquirer, just not one public data lets us price. The recent download trend is too spiky to read.
Details
Recent reviews
All reviews on wp.org ↗- ★★★★★ alain22041mo ago
Réponse rapide et efficace
Read on wp.org ↗ - ★★★★★ graham492mo ago
I was struggling with some of the more complex issues within WordPress and although I struggled with the EDD AI support, when I got through to a human being the problem was solved totally and politely (I would also add with a high degree of patience!). I’m most grateful. GH
Read on wp.org ↗ - ★★★★★ Md. Sarwar Zaman2mo ago
If you sell digital assets, EDD is the absolute best framework available. It’s built cleanly on core WordPress standards, handles complex workflows flawlessly right out of the box, and is backed by a remarkably responsive, expert support team.
Read on wp.org ↗ - ★★★★★ dfathers3mo ago
We were experiencing issues with the Easy Digital Downloads shopping cart and contacted support for assistance. Within approximately two hours, their team responded and resolved the issue. The support was professional, efficient, and very helpful. Easy Digital Downloads is a strong plugin, and the quality of support gives us confidence using it for our digital product sales. Highly recommended.
Read on wp.org ↗ - ★★★★★ ninoloco3mo ago
I LOVE this plugin!! I use it on two websites and haven’t had any problems at all most of the time. It’s great that the basic version of the plugin is free. That’s fair for business beginners like me. Thank you so much for that. Please don’t change this plugin!
Read on wp.org ↗ - ★★★★★ danwpc3mo ago
EDD has worked smoothly for years on my products. Customer support is always excellent. Great product, great service!
Read on wp.org ↗ - ★★★★★ 2fishone5mo ago
this plugin works well
Read on wp.org ↗ - ★★★★★ Fetch Designs5mo ago
EDD is a fantastic solution. It’s a solid plugin, built with great WordPress best practices, backed by super support and has a lot of great features.
Read on wp.org ↗
Latest updates
via wp.org changelogRecent releases and news for this plugin
- — Version 3.6.9 NEW: PayPal – Added support for Fastlane and additional payment methods for newly connected stores. Admin: Improved notice compatibility. Admin: Hardened sanitization of the banned emails setting. Admin: Sorted Checkout 3.6.9
- — Version 3.6.8 NEW: Stripe – Added support for BLIK payments. Admin: Fixed the orders table filter by total not working with the “greater than” condition. Admin: Fixed manual order tax calculation requiring an address field change to t 3.6.8
- — Version 3.6.7 NEW: Blocks – Introducing the Profile Editor Block. NEW: Checkout – Added a Business Name field to checkout addresses. NEW: Checkout – Returning customers can now log in via a secure email link at checkout. NEW: Purchase 3.6.7
- — Version 3.6.6 Admin: Added compatibility with WordPress 7.0 admin changes. Cart: Fixed cart validation when adding multiple items at the same time. Cart: Improved mixed cart behavior with Stripe. Cart: Fixed a potential fatal error wh 3.6.6
- — Version 3.6.5 NEW: Cron – Cron events are now more reliable and based on Action Scheduler. Cart: Fixed an unused variable in the cart class. Cart: The error handler has been improved to show messages more consistently. Checkout: Impro 3.6.5
- — Version 3.6.4 New: Manage logs with the Log Retention Settings. Admin: Some help icons could get duplicated. Blocks: Login block could prevent WordPress admin email confirmation from working. Checkout: Improved billing address conditi 3.6.4
Known vulnerabilities
via Wordfence Intelligence44 disclosed vulnerabilities on record for this plugin, all fixed in the current version. Sites on older versions stay exposed until they update.
- 2026-07-28 CVE-2026-12476 Unrestricted Upload of File with Dangerous Type Affects <= 3.6.9 Patched in 3.6.9.1
- 2026-07-27 CVE-2026-66476 Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') Affects <= 3.6.9 Patched in 3.6.9.1
- Medium · 4.3 Easy Digital Downloads <= 3.6.2 - Unvalidated Redirect in Password Reset Flow via edd_redirect ↗2025-12-30 CVE-2025-14783 Weak Password Recovery Mechanism for Forgotten Password Affects <= 3.6.2 Patched in 3.6.3
- 2025-11-05 CVE-2025-11271 Reliance on Untrusted Inputs in a Security Decision Affects <= 3.5.2 Patched in 3.5.3
- 2025-05-28 CVE-2025-4670 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') Affects <= 3.3.8.1 Patched in 3.3.9
- 2025-03-24 CVE-2025-2252 Exposure of Sensitive Information to an Unauthorized Actor Affects <= 3.3.6.1 Patched in 3.3.7
- 2025-01-17 CVE-2024-13517 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') Affects <= 3.3.2 Patched in 3.3.3
- 2024-08-09 CVE-2024-6691 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') Affects <= 3.3.2 Patched in 3.3.3
- 2024-08-09 CVE-2024-6692 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') Affects <= 3.3.2 Patched in 3.3.3
- 2024-08-01 CVE-2024-5057 Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') Affects <= 3.2.12 Patched in 3.3.1
- 2024-05-09 CVE-2024-32100 Exposure of Sensitive Information to an Unauthorized Actor Affects <= 3.2.11 Patched in 3.2.12
- 2024-04-03 CVE-2024-2302 Insertion of Sensitive Information into Log File Affects <= 3.2.9 Patched in 3.2.10
- 2024-02-02 CVE-2024-0659 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') Affects <= 3.2.6 Patched in 3.2.7
- Medium · 6.4 Easy Digital Downloads <= 3.2.5 - Authenticated (Contributor+) Stored Cross-Site Scripting ↗2023-12-27 CVE-2023-51684 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') Affects <= 3.2.5 Patched in 3.2.6
- Medium · 4.3 Easy Digital Downloads <= 3.1.1.4.2 - Cross-Site Request Forgery via edd_trigger_upgrades ↗2023-06-07 Cross-Site Request Forgery (CSRF) Affects < 3.1.2 Patched in 3.1.2
- Medium · 6.4 Easy Digital Downloads <= 3.1.0.4 - Authenticated (Contributor+) Stored Cross-Site Scripting via Shortcode ↗2023-01-30 CVE-2023-0380 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') Affects <= 3.1.0.4 Patched in 3.1.0.5
- Critical · 9.8 Easy Digital Downloads < 3.1.0.4 - SQL Injection ↗2023-01-12 CVE-2023-23489 Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') Affects <= 3.1.0.3 Patched in 3.1.0.4
- 2022-09-28 CVE-2022-3600 Improper Neutralization of Formula Elements in a CSV File Affects <= 3.1.0.1.1 Patched in 3.1.0.2
- Critical · 9.8 Easy Digital Downloads <= 3.0.1 - PHP Object Injection ↗
- 2022-03-28 CVE-2022-0706 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') Affects < 2.11.6 Patched in 2.11.6
- 2021-10-21 CVE-2021-39354 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') Affects <= 2.11.2 Patched in 2.11.2.1
- Medium · 5.4 Easy Digital Downloads – Simple eCommerce for Selling Digital Files <= 2.11.2 - Reflected Cross-Site Scripting ↗2021-10-19 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') Affects <= 2.11.2 Patched in 2.11.2.1
- 2021-05-04 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') Affects <= 2.10.3 Patched in 2.10.4
- Medium · 4.3 Easy Digital Downloads – Simple eCommerce for Selling Digital Files <= 2.10.2 - Cross-Site Request Forgery ↗2021-04-16 Cross-Site Request Forgery (CSRF) Affects <= 2.10.2 Patched in 2.10.3
- 2021-04-14 Cross-Site Request Forgery (CSRF) Affects < 2.10.3 Patched in 2.10.3
- Critical · 9.8 Easy Digital Downloads – Simple eCommerce for Selling Digital Files <= 2.3.2 - SQL Injection ↗2020-09-22 CVE-2015-9324 Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') Affects <= 2.3.2 Patched in 2.3.3
- Medium · 6.1 Easy Digital Downloads – Simple eCommerce for Selling Digital Files <= 2.9.15 - Stored Cross-Site Scripting ↗2019-06-12 CVE-2019-15116 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') Affects < 2.9.16 Patched in 2.9.16
- Critical · 9.8 Easy Digital Downloads <= 2.5.7 - PHP Object Injection ↗2016-03-02 Deserialization of Untrusted Data Affects <= 2.5.7 Patched in 2.5.8
- 2015-04-20 CVE-2015-9512 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') Affects 1.8 - 1.8.6 Patched in 1.8.7
- Medium · 6.1 Easy Digital Downloads – Simple eCommerce for Selling Digital Files <= 2.3.6 - Cross-Site Scripting ↗2015-04-20 CVE-2015-9505 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') Affects < 1.8.7 Patched in 1.8.7
Vulnerability records provided by Wordfence Intelligence. Copyright 2012-2026 Defiant Inc. License and terms.
CVE records: Copyright 1999-2026 The MITRE Corporation. CVE terms of use.
Behavioral tests
via WP HiveAutomated install-time checks, tested on PHP 8.1.12 · WP 7.0
Languages
via translate.wordpress.orgTranslated into 93 languages, 13 at 90% or more
Plus 69 more locales with partial translations.
Growth timeline
Install-tier crossings we have observed, and how long each tier took to outgrow
- 2026-01-01 50K+ → 40K+ down after 136 days in tier
- 2025-08-18 40K+ → 50K+ up after 24 days in tier
- 2025-07-25 50K+ → 40K+ down after 6 days in tier
- 2025-07-19 40K+ → 50K+ up after 67 days in tier
- 2025-05-13 50K+ → 40K+ down
Competes with
The plugins that solve the same job, ranked by shared tags then reach, closest match first. The letter on the right is each plugin's health grade (A best, F worst).
-
SureCart – Ecommerce Made Easy For Selling Physical Products, Digital Downloads, Subscriptions, Donations, & Payments 80K+ installs · 4.7★ · 3 shared tags A -
Contact Form 7 – PayPal & Stripe Add-on 7K+ installs · 4.1★ · 3 shared tags A -
WooCommerce PayPal Payments 800K+ installs · 2.9★ · 2 shared tags B -
WooCommerce Stripe Payment Gateway 700K+ installs · 3.1★ · 2 shared tags B -
Mollie Payments for WooCommerce 100K+ installs · 3.6★ · 2 shared tags B -
Download Manager 100K+ installs · 4.1★ · 2 shared tags A
Embed this report card
Drop a live Pulse card for Easy Digital Downloads – eCommerce Payments and Subscriptions made easy into a readme, a review or a deck. It updates itself.
<iframe src="https://plugins.wpmayor.com/embed/easy-digital-downloads" width="480" height="300" style="border:0" loading="lazy" title="Easy Digital Downloads – eCommerce Payments and Subscriptions made easy — Plugin Pulse"></iframe> Easy Digital Downloads – eCommerce Payments and Subscriptions made easy: 40K+ active installs, 4.7★ (590 reviews). Plugin Pulse (WP Mayor), as of 2026-08-25. https://plugins.wpmayor.com/plugin/easy-digital-downloads