AIR Download Attachments Security & Risk Analysis

wordpress.org/plugins/air-download-attachments

The AIR Download Attachments plugin adds a "Download All Attachments" button to posts, allowing users to download all attached images as a z …

10 active installs v1.0.1 PHP 5.6+ WP 4.8+ Updated Nov 26, 2023
attachmentsdownloadimagesmediazip
85
A · Safe
CVEs total0
Unpatched0
Last CVENever
Safety Verdict

Is AIR Download Attachments Safe to Use in 2026?

Generally Safe

Score 85/100

AIR Download Attachments has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.

No known CVEs Updated 2yr ago
Risk Assessment

The 'air-download-attachments' plugin v1.0.1 exhibits a strong security posture based on the provided static analysis. There are no identified entry points like AJAX handlers, REST API routes, shortcodes, or cron events that are exposed to attack. Furthermore, the code signals show no dangerous functions used, all SQL queries are prepared, and all output is properly escaped. The absence of critical or high-severity taint flows and no recorded vulnerability history further bolster this assessment. The plugin appears to be developed with good security practices in mind.

However, a few areas warrant attention. The complete absence of nonce checks and capability checks across the plugin's code, despite having file operations, is a notable concern. While no direct vulnerabilities are evident *in this version*, this lack of authorization and integrity checks could become a problem if new entry points are introduced or if the file operations are leveraged in a sensitive context. The plugin's strengths lie in its clean code regarding direct vulnerabilities and data handling, but the lack of explicit authorization checks represents a potential weakness that could be exploited in future scenarios or with more complex usage.

In conclusion, 'air-download-attachments' v1.0.1 currently presents a very low risk. The development team has demonstrated a good understanding of secure coding principles by avoiding common pitfalls like raw SQL and unescaped output. The lack of historical vulnerabilities is also a positive indicator. The primary area for improvement, and the only notable weakness identified, is the absence of nonce and capability checks, which are crucial for preventing unauthorized actions and ensuring data integrity, especially when file operations are involved.

Key Concerns

  • Missing nonce checks
  • Missing capability checks
Vulnerabilities
None known

AIR Download Attachments Security Vulnerabilities

No known vulnerabilities — this is a good sign.
Code Analysis
Analyzed Mar 17, 2026

AIR Download Attachments Code Analysis

Dangerous Functions
0
Raw SQL Queries
0
0 prepared
Unescaped Output
0
4 escaped
Nonce Checks
0
Capability Checks
0
File Operations
3
External Requests
0
Bundled Libraries
0

Output Escaping

100% escaped4 total outputs
Attack Surface

AIR Download Attachments Attack Surface

Entry Points0
Unprotected0
WordPress Hooks 4
actionplugins_loadedair-download-attachments.php:48
actionwp_enqueue_scriptsair-download-attachments.php:62
filterthe_contentair-download-attachments.php:93
actiontemplate_redirectair-download-attachments.php:144
Maintenance & Trust

AIR Download Attachments Maintenance & Trust

Maintenance Signals

WordPress version tested6.4.8
Last updatedNov 26, 2023
PHP min version5.6
Downloads1K

Community Trust

Rating0/100
Number of ratings0
Active installs10
Developer Profile

AIR Download Attachments Developer Profile

Dan Zakirov

4 plugins · 11K total installs

89
trust score
Avg Security Score
93/100
Avg Patch Time
30 days
View full developer profile
Detection Fingerprints

How We Detect AIR Download Attachments

Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.

Asset Fingerprints

Asset Paths
/wp-content/plugins/air-download-attachments/assets/css/air-download-attachments.css

HTML / DOM Fingerprints

CSS Classes
air-download-attachmentsair-download-attachments-button
Data Attributes
air_download_attachments
Shortcode Output
<div class="air-download-attachments"><a href="
FAQ

Frequently Asked Questions about AIR Download Attachments