
Avenir-soft Direct Download Security & Risk Analysis
wordpress.org/plugins/avenirsoft-directdownloadDownload Button for WooCommerce Free, virtual and downloadable products.
Is Avenir-soft Direct Download Safe to Use in 2026?
Use With Caution
Score 64/100Avenir-soft Direct Download has 1 unpatched vulnerability. Evaluate alternatives or apply available mitigations.
The 'avenirsoft-directdownload' plugin version 1.0 exhibits a mixed security posture. On the positive side, the static analysis indicates a remarkably small attack surface with no detectable AJAX handlers, REST API routes, shortcodes, or cron events that are exposed. Furthermore, all SQL queries are confirmed to use prepared statements, which is a strong security practice. However, several significant concerns are raised by the analysis. The plugin fails to implement any nonce checks or capability checks, leaving potential entry points (if they existed) vulnerable to unauthorized actions or privilege escalation. Most concerning is the complete lack of output escaping across all identified output points, which presents a high risk of Cross-Site Scripting (XSS) vulnerabilities. The vulnerability history further amplifies these concerns, with one unpatched medium severity CVE related to XSS, dating back to 2015. This historical pattern of XSS, combined with the current lack of output escaping and authorization checks, suggests a recurrent weakness in how user-supplied data is handled and validated. While the plugin has minimal direct entry points, the identified weaknesses are critical and could be exploited if any functionality were to be added or discovered.
Key Concerns
- Unpatched CVEs present
- No output escaping
- No nonce checks
- No capability checks
Avenir-soft Direct Download Security Vulnerabilities
CVEs by Year
Severity Breakdown
1 total CVE
Avenir-soft Direct Download <= 1.0 - Cross-Site Scripting
Avenir-soft Direct Download Code Analysis
Output Escaping
Avenir-soft Direct Download Attack Surface
WordPress Hooks 5
Maintenance & Trust
Avenir-soft Direct Download Maintenance & Trust
Maintenance Signals
Community Trust
Avenir-soft Direct Download Alternatives
Free Downloads WooCommerce
download-now-for-woocommerce
Allow users to instantly download your free digital products without going through the checkout.
WP Anything Downloader
wp-anything-downloader
WP Anything Downloader
Downloadify WP
downloadify-wp
Downloadify WP for WordPress Plugin And Theme Downloader.
Hide Real Download Path
hide-real-download-path
This plugin help to hide real download path of your files on server and allow file downloading using a common URL. Also maintain log of your downloads …
LemonInk Ebook Watermarking for WooCommerce
lemonink
Watermark EPUB, MOBI and PDF files in your WooCommerce store using the LemonInk service.
Avenir-soft Direct Download Developer Profile
1 plugin · 10 total installs
How We Detect Avenir-soft Direct Download
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/avenirsoft-directdownload/admin/css/style.cssHTML / DOM Fingerprints
plugin_wrapperdownloadbuttonwindow.location