Image Download Button Security & Risk Analysis

wordpress.org/plugins/auto-image-download-button

The plugin adds a customizable download button automatically below every image on post, page and different post types.

90 active installs v2.2.2 PHP 5.6+ WP 5.6+ Updated Mar 5, 2026
auto-image-download-buttondownload-button-below-imagesimage-download-button
100
A · Safe
CVEs total0
Unpatched0
Last CVENever
Safety Verdict

Is Image Download Button Safe to Use in 2026?

Generally Safe

Score 100/100

Image Download Button has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.

No known CVEs Updated 2mo ago
Risk Assessment

Based on the provided static analysis and vulnerability history, the "auto-image-download-button" v2.2.2 plugin exhibits a strong security posture. The absence of any identified AJAX handlers, REST API routes, shortcodes, or cron events with unprotected entry points indicates a limited attack surface. Furthermore, the code signals reveal no dangerous functions, no raw SQL queries, and no file operations, all of which are positive indicators. The high percentage of properly escaped output (93%) is also commendable.

The plugin's vulnerability history is also clean, with no known CVEs, which suggests a history of secure development practices or diligent patching by maintainers. The taint analysis showing zero flows with unsanitized paths further reinforces the apparent security of the code. However, a notable observation is the complete lack of nonce checks and capability checks. While this might not pose an immediate risk given the current attack surface, it represents a potential weakness if new features introducing more dynamic functionalities are added in the future without proper security controls.

In conclusion, the "auto-image-download-button" v2.2.2 plugin appears to be very secure in its current state, with a minimal attack surface and good coding practices regarding SQL and output escaping. The primary area for potential future concern lies in the absence of nonces and capability checks, which, while not a current vulnerability, could become a risk if the plugin's functionality expands.

Key Concerns

  • Missing nonce checks
  • Missing capability checks
Vulnerabilities
None known

Image Download Button Security Vulnerabilities

No known vulnerabilities — this is a good sign.
Version History

Image Download Button Release Timeline

v2.2.1
v2.2.0
v2.1.1
v2.1.0
v2.0.0
v1.1.0
Code Analysis
Analyzed Mar 16, 2026

Image Download Button Code Analysis

Dangerous Functions
0
Raw SQL Queries
0
0 prepared
Unescaped Output
2
27 escaped
Nonce Checks
0
Capability Checks
0
File Operations
0
External Requests
0
Bundled Libraries
0

Output Escaping

93% escaped29 total outputs
Attack Surface

Image Download Button Attack Surface

Entry Points0
Unprotected0
WordPress Hooks 10
actionadmin_menuadmin\admin-settings.php:14
actionadmin_enqueue_scriptsadmin\admin-settings.php:20
actionadmin_enqueue_scriptsadmin\admin-settings.php:31
actionadmin_initadmin\admin-settings.php:136
actionwp_enqueue_scriptsimage-download-button.php:19
filterthe_contentimage-download-button.php:44
actionwp_enqueue_scriptsimage-download-button.php:84
actionadmin_enqueue_scriptsimage-download-button.php:95
actionadd_meta_boxesimage-download-button.php:108
actionsave_postimage-download-button.php:126
Maintenance & Trust

Image Download Button Maintenance & Trust

Maintenance Signals

WordPress version tested6.9.4
Last updatedMar 5, 2026
PHP min version5.6
Downloads5K

Community Trust

Rating100/100
Number of ratings2
Active installs90
Alternatives

Image Download Button Alternatives

No alternatives data available yet.

Developer Profile

Image Download Button Developer Profile

RaptorKit

1 plugin · 90 total installs

94
trust score
Avg Security Score
100/100
Avg Patch Time
30 days
View full developer profile
Detection Fingerprints

How We Detect Image Download Button

Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.

Asset Fingerprints

Asset Paths
/wp-content/plugins/auto-image-download-button/css/download-button-style.css/wp-content/plugins/auto-image-download-button/js/download-button-script.js
Script Paths
/wp-content/plugins/auto-image-download-button/js/download-button-script.js
Version Parameters
auto-image-download-button/css/download-button-style.css?ver=auto-image-download-button/js/download-button-script.js?ver=

HTML / DOM Fingerprints

CSS Classes
image-containercustom-download-button
Data Attributes
data-cdb-enable-download-button
FAQ

Frequently Asked Questions about Image Download Button