
AIR Download Attachments Security & Risk Analysis
wordpress.org/plugins/air-download-attachmentsThe AIR Download Attachments plugin adds a "Download All Attachments" button to posts, allowing users to download all attached images as a z …
Is AIR Download Attachments Safe to Use in 2026?
Generally Safe
Score 85/100AIR Download Attachments has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.
The 'air-download-attachments' plugin v1.0.1 exhibits a strong security posture based on the provided static analysis. There are no identified entry points like AJAX handlers, REST API routes, shortcodes, or cron events that are exposed to attack. Furthermore, the code signals show no dangerous functions used, all SQL queries are prepared, and all output is properly escaped. The absence of critical or high-severity taint flows and no recorded vulnerability history further bolster this assessment. The plugin appears to be developed with good security practices in mind.
However, a few areas warrant attention. The complete absence of nonce checks and capability checks across the plugin's code, despite having file operations, is a notable concern. While no direct vulnerabilities are evident *in this version*, this lack of authorization and integrity checks could become a problem if new entry points are introduced or if the file operations are leveraged in a sensitive context. The plugin's strengths lie in its clean code regarding direct vulnerabilities and data handling, but the lack of explicit authorization checks represents a potential weakness that could be exploited in future scenarios or with more complex usage.
In conclusion, 'air-download-attachments' v1.0.1 currently presents a very low risk. The development team has demonstrated a good understanding of secure coding principles by avoiding common pitfalls like raw SQL and unescaped output. The lack of historical vulnerabilities is also a positive indicator. The primary area for improvement, and the only notable weakness identified, is the absence of nonce and capability checks, which are crucial for preventing unauthorized actions and ensuring data integrity, especially when file operations are involved.
Key Concerns
- Missing nonce checks
- Missing capability checks
AIR Download Attachments Security Vulnerabilities
AIR Download Attachments Code Analysis
Output Escaping
AIR Download Attachments Attack Surface
WordPress Hooks 4
Maintenance & Trust
AIR Download Attachments Maintenance & Trust
Maintenance Signals
Community Trust
AIR Download Attachments Alternatives
Export Media as ZIP
export-media-as-zip
Export your entire WordPress media library as a single downloadable ZIP file. Simple, fast, and admin-only.
WP Attachment Download
wp-attachment-download
Plugin adds functionality to download posts attachments build with ACF file fields from administration.
GL Import External Images
gl-import-external-images
Import and insert images to WordPress Media Library from external URLs.
Media Vault
media-vault
Protect attachment files from direct access using powerful and flexible restrictions. Offer safe download links for any file in your uploads folder.
Documents Tab for WooCommerce
documents-tab-for-woocommerce
Allow attach various documents and media files to a product as separate tab.
AIR Download Attachments Developer Profile
4 plugins · 11K total installs
How We Detect AIR Download Attachments
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/air-download-attachments/assets/css/air-download-attachments.cssHTML / DOM Fingerprints
air-download-attachmentsair-download-attachments-buttonair_download_attachments<div class="air-download-attachments"><a href="