Digital Asset Manager Security & Risk Analysis

wordpress.org/plugins/digital-asset-manager

Helps you to store and manage all of your digital assets in one place.

20 active installs v1.2.0 PHP 5.6+ WP 4.0.0+ Updated Jan 22, 2025
backupeditorfile-managerfileswp-file-manager
92
A · Safe
CVEs total0
Unpatched0
Last CVENever
Safety Verdict

Is Digital Asset Manager Safe to Use in 2026?

Generally Safe

Score 92/100

Digital Asset Manager has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.

No known CVEs Updated 1yr ago
Risk Assessment

The digital-asset-manager plugin v1.2.0 exhibits a mixed security posture. On the positive side, the code demonstrates good practices regarding SQL queries, with 100% using prepared statements and a high percentage of outputs being properly escaped. The absence of known CVEs and vulnerabilities in its history is also a strong indicator of a well-maintained and secure codebase. Furthermore, the plugin doesn't engage in file operations or external HTTP requests, limiting potential attack vectors.

However, a significant concern arises from the attack surface. The plugin exposes two AJAX handlers, both of which lack authentication checks. This means any unauthenticated user could potentially trigger these handlers, leading to a Cross-Site Request Forgery (CSRF) or other unintended actions if the handlers perform sensitive operations. While the taint analysis found no critical or high severity flows, and nonce checks are present on some actions, the unprotected AJAX endpoints represent a clear and present risk that requires immediate attention.

In conclusion, while the plugin has a clean vulnerability history and adheres to good coding practices in areas like SQL and output sanitization, the lack of authentication on its AJAX endpoints is a critical oversight. This weakness, despite the absence of known historical vulnerabilities or critical taint flows, creates a direct pathway for potential exploitation. The plugin's strengths are overshadowed by this specific, yet significant, security flaw.

Key Concerns

  • Unprotected AJAX handlers
  • Exposed attack surface without auth checks
Vulnerabilities
None known

Digital Asset Manager Security Vulnerabilities

No known vulnerabilities — this is a good sign.
Code Analysis
Analyzed Mar 16, 2026

Digital Asset Manager Code Analysis

Dangerous Functions
0
Raw SQL Queries
0
0 prepared
Unescaped Output
10
201 escaped
Nonce Checks
4
Capability Checks
2
File Operations
0
External Requests
0
Bundled Libraries
0

Output Escaping

95% escaped211 total outputs
Attack Surface
2 unprotected

Digital Asset Manager Attack Surface

Entry Points2
Unprotected2

AJAX Handlers 2

noprivwp_ajax_dam_retrieve_asset_download_urlincludes\class-digital-asset-manager.php:210
authwp_ajax_dam_retrieve_asset_download_urlincludes\class-digital-asset-manager.php:211
WordPress Hooks 21
filterdam_asset_post_type_argsadmin\post-types\class-dam-posttype-assets.php:75
filterdam_asset_tags_taxonomy_argsadmin\taxonomies\class-dam-taxonomy-asset-tags.php:51
filterdam_asset_type_taxonomy_argsadmin\taxonomies\class-dam-taxonomy-asset-type.php:51
actionplugins_loadedincludes\class-digital-asset-manager.php:151
actionadmin_enqueue_scriptsincludes\class-digital-asset-manager.php:165
actionadmin_enqueue_scriptsincludes\class-digital-asset-manager.php:166
actioninitincludes\class-digital-asset-manager.php:169
actionsave_postincludes\class-digital-asset-manager.php:172
filteruse_block_editor_for_post_typeincludes\class-digital-asset-manager.php:175
filtermanage_dam-asset_posts_columnsincludes\class-digital-asset-manager.php:178
filtermanage_dam-asset_posts_custom_columnincludes\class-digital-asset-manager.php:179
filterpost_column_taxonomy_linksincludes\class-digital-asset-manager.php:180
actioninitincludes\class-digital-asset-manager.php:183
actioninitincludes\class-digital-asset-manager.php:186
actioninitincludes\class-digital-asset-manager.php:189
actionadmin_menuincludes\class-digital-asset-manager.php:192
actionadmin_initincludes\class-digital-asset-manager.php:193
actionwp_enqueue_scriptsincludes\class-digital-asset-manager.php:207
actionwp_enqueue_scriptsincludes\class-digital-asset-manager.php:208
filtertemplate_includeincludes\class-digital-asset-manager.php:214
filterpre_get_postsincludes\class-digital-asset-manager.php:215
Maintenance & Trust

Digital Asset Manager Maintenance & Trust

Maintenance Signals

WordPress version tested6.7.5
Last updatedJan 22, 2025
PHP min version5.6
Downloads2K

Community Trust

Rating0/100
Number of ratings0
Active installs20
Developer Profile

Digital Asset Manager Developer Profile

2ByteCode

3 plugins · 130 total installs

92
trust score
Avg Security Score
97/100
Avg Patch Time
30 days
View full developer profile
Detection Fingerprints

How We Detect Digital Asset Manager

Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.

Asset Fingerprints

Asset Paths
/wp-content/plugins/digital-asset-manager/admin/css/digital-asset-manager-admin.css/wp-content/plugins/digital-asset-manager/admin/js/digital-asset-manager-admin.js
Script Paths
/wp-content/plugins/digital-asset-manager/admin/js/digital-asset-manager-admin.js
Version Parameters
digital-asset-manager-admin.css?ver=digital-asset-manager-admin.js?ver=

HTML / DOM Fingerprints

JS Globals
DigitalAssetManager
FAQ

Frequently Asked Questions about Digital Asset Manager