Comdev Downloads Security & Risk Analysis

wordpress.org/plugins/comdev-downloads

Comdev Downloads is a powerful plugin for uploading, managing, and tracking download packages, as well as displaying download links.

0 active installs v1.1.0 PHP 7.0+ WP 4.7+ Updated Sep 12, 2024
digital-storedocument-managementdownload-managerecommercefile-manager
92
A · Safe
CVEs total0
Unpatched0
Last CVENever
Safety Verdict

Is Comdev Downloads Safe to Use in 2026?

Generally Safe

Score 92/100

Comdev Downloads has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.

No known CVEs Updated 1yr ago
Risk Assessment

The 'comdev-downloads' plugin v1.1.0 demonstrates a strong security posture based on the provided static analysis. The complete absence of an attack surface, including AJAX handlers, REST API routes, shortcodes, and cron events, significantly reduces the potential entry points for attackers. Furthermore, the code exhibits excellent practices regarding output escaping, with 100% of outputs being properly sanitized. The SQL query analysis is also positive, with a majority utilizing prepared statements. The bundled Freemius library is at version 1.0, which is a minor concern as libraries can contain vulnerabilities over time, but without further information on its specific version and known CVEs, this is a low-risk observation.

The taint analysis reveals no identified flows, which is a very positive sign, indicating no apparent paths for unsanitized data to reach sensitive functions. The vulnerability history is also clean, with no recorded CVEs, suggesting a history of secure development or a lack of historical security scrutiny. The most notable weakness is the complete lack of nonce and capability checks. While the current attack surface is zero, if any new entry points were introduced in future updates, they would be entirely unprotected without these fundamental security measures.

In conclusion, 'comdev-downloads' v1.1.0 appears to be a highly secure plugin at this version, with no critical or high-risk vulnerabilities identified in the static analysis or historical data. Its strengths lie in its minimal attack surface and excellent output sanitization. The primary area for improvement and potential risk lies in the absence of nonce and capability checks, which, while not an immediate threat given the current analysis, represents a significant gap in fundamental WordPress security practices that could become problematic if the attack surface expands in the future.

Key Concerns

  • Missing nonce checks
  • Missing capability checks
  • Bundled Freemius v1.0
Vulnerabilities
None known

Comdev Downloads Security Vulnerabilities

No known vulnerabilities — this is a good sign.
Code Analysis
Analyzed Mar 17, 2026

Comdev Downloads Code Analysis

Dangerous Functions
0
Raw SQL Queries
3
6 prepared
Unescaped Output
0
87 escaped
Nonce Checks
0
Capability Checks
0
File Operations
0
External Requests
0
Bundled Libraries
1

Bundled Libraries

Freemius1.0

SQL Query Safety

67% prepared9 total queries

Output Escaping

100% escaped87 total outputs
Attack Surface

Comdev Downloads Attack Surface

Entry Points0
Unprotected0
WordPress Hooks 20
actioninitadmin\class-comdev-files-admin-items.php:31
actioninitadmin\class-comdev-files-admin-list.php:30
actionadmin_initadmin\class-comdev-files-admin-settings.php:37
actionadmin_menuadmin\class-comdev-files-admin.php:64
actioncomdev_files_display_admin_headeradmin\comdev-files-admin-functions.php:25
actioncomdev_files_display_admin_notificationsadmin\comdev-files-admin-functions.php:40
actionadmin_body_classadmin\comdev-files-admin-functions.php:53
actionplugins_loadedincludes\class-comdev-files.php:146
actionadmin_enqueue_scriptsincludes\class-comdev-files.php:161
actionadmin_enqueue_scriptsincludes\class-comdev-files.php:162
actionwp_enqueue_scriptsincludes\class-comdev-files.php:198
actionwp_enqueue_scriptsincludes\class-comdev-files.php:199
actionafter_setup_themesrc\php\Main.php:58
filtercarbon_fields_should_save_field_valuesrc\php\Main.php:59
actionin_admin_headersrc\php\Main.php:72
filterwoocommerce_order_data_store_cpt_get_orders_querysrc\php\Main.php:73
filtercarbon_fields_should_save_field_valuesrc\php\Main.php:79
actioncarbon_fields_register_fieldssrc\php\PluginCarbonFields.php:32
actioncarbon_fields_register_fieldssrc\php\PluginCarbonFields.php:33
actioncarbon_fields_register_fieldssrc\php\PluginCarbonFields.php:34
Maintenance & Trust

Comdev Downloads Maintenance & Trust

Maintenance Signals

WordPress version tested6.5.8
Last updatedSep 12, 2024
PHP min version7.0
Downloads1K

Community Trust

Rating100/100
Number of ratings1
Active installs0
Developer Profile

Comdev Downloads Developer Profile

comdeveu

1 plugin · 0 total installs

88
trust score
Avg Security Score
92/100
Avg Patch Time
30 days
View full developer profile
Detection Fingerprints

How We Detect Comdev Downloads

Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.

Asset Fingerprints

Asset Paths
/wp-content/plugins/comdev-downloads/includes/assets/css/uikit.min.css/wp-content/plugins/comdev-downloads/includes/assets/css/comdev-files-admin.css/wp-content/plugins/comdev-downloads/includes/assets/js/comdev-files-admin.js
Script Paths
/wp-content/plugins/comdev-downloads/includes/assets/js/comdev-files-admin.js
Version Parameters
comdev-files-admin?ver=uikit?ver=

HTML / DOM Fingerprints

CSS Classes
cdfp-admin-content
Data Attributes
data-uk-tabdata-uk-griddata-uk-filterdata-uk-sort
JS Globals
ComdevFilesAdmin
FAQ

Frequently Asked Questions about Comdev Downloads