
Image Download Button Security & Risk Analysis
wordpress.org/plugins/auto-image-download-buttonThe plugin adds a customizable download button automatically below every image on post, page and different post types.
Is Image Download Button Safe to Use in 2026?
Generally Safe
Score 100/100Image Download Button has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.
Based on the provided static analysis and vulnerability history, the "auto-image-download-button" v2.2.2 plugin exhibits a strong security posture. The absence of any identified AJAX handlers, REST API routes, shortcodes, or cron events with unprotected entry points indicates a limited attack surface. Furthermore, the code signals reveal no dangerous functions, no raw SQL queries, and no file operations, all of which are positive indicators. The high percentage of properly escaped output (93%) is also commendable.
The plugin's vulnerability history is also clean, with no known CVEs, which suggests a history of secure development practices or diligent patching by maintainers. The taint analysis showing zero flows with unsanitized paths further reinforces the apparent security of the code. However, a notable observation is the complete lack of nonce checks and capability checks. While this might not pose an immediate risk given the current attack surface, it represents a potential weakness if new features introducing more dynamic functionalities are added in the future without proper security controls.
In conclusion, the "auto-image-download-button" v2.2.2 plugin appears to be very secure in its current state, with a minimal attack surface and good coding practices regarding SQL and output escaping. The primary area for potential future concern lies in the absence of nonces and capability checks, which, while not a current vulnerability, could become a risk if the plugin's functionality expands.
Key Concerns
- Missing nonce checks
- Missing capability checks
Image Download Button Security Vulnerabilities
Image Download Button Release Timeline
Image Download Button Code Analysis
Output Escaping
Image Download Button Attack Surface
WordPress Hooks 10
Maintenance & Trust
Image Download Button Maintenance & Trust
Maintenance Signals
Community Trust
Image Download Button Alternatives
No alternatives data available yet.
Image Download Button Developer Profile
1 plugin · 90 total installs
How We Detect Image Download Button
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/auto-image-download-button/css/download-button-style.css/wp-content/plugins/auto-image-download-button/js/download-button-script.js/wp-content/plugins/auto-image-download-button/js/download-button-script.jsauto-image-download-button/css/download-button-style.css?ver=auto-image-download-button/js/download-button-script.js?ver=HTML / DOM Fingerprints
image-containercustom-download-buttondata-cdb-enable-download-button