DLM – Advanced Settings Security & Risk Analysis

wordpress.org/plugins/dlm-advanced-settings

Download Monitor is a plugin for uploading and managing downloads, tracking downloads and displaying links.

0 active installs v1.0.4 PHP 7.4+ WP 5.4+ Updated Jul 10, 2025
advanced-settingsdownload-monitordownload-monitor-filtersfiltershooks
100
A · Safe
CVEs total0
Unpatched0
Last CVENever
Safety Verdict

Is DLM – Advanced Settings Safe to Use in 2026?

Generally Safe

Score 100/100

DLM – Advanced Settings has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.

No known CVEs Updated 10mo ago
Risk Assessment

The plugin 'dlm-advanced-settings' v1.0.4 exhibits an excellent security posture based on the provided static analysis. The absence of any identified attack surface points, including AJAX handlers, REST API routes, shortcodes, and cron events, suggests a minimal exposure to external manipulation. Furthermore, the code demonstrates robust security practices with 100% of SQL queries using prepared statements and all output properly escaped, eliminating common vulnerability vectors like SQL injection and Cross-Site Scripting (XSS). The lack of identified dangerous functions, file operations, external HTTP requests, and no-auth checks for entry points further reinforces this positive assessment.

The vulnerability history is also remarkably clean, with no recorded CVEs, indicating a history of secure development and maintenance. The absence of any taint analysis findings further confirms the lack of exploitable paths. This plugin appears to be developed with a strong emphasis on security, implementing best practices to prevent common web application vulnerabilities. The only area that might be considered a minor weakness, though not a direct security risk based on the provided data, is the absence of nonce checks and capability checks. While the current lack of an attack surface makes this less critical, it could become a point of concern if future features introduce new entry points without these essential security measures.

In conclusion, 'dlm-advanced-settings' v1.0.4 is a highly secure plugin. Its design, with no exposed attack surface and diligent code practices regarding SQL and output handling, is commendable. The lack of historical vulnerabilities further solidifies its strong security profile. While the absence of nonce and capability checks on entry points is noted, it does not currently represent an exploitable risk given the plugin's current structure.

Key Concerns

  • Missing nonce checks
  • Missing capability checks
Vulnerabilities
None known

DLM – Advanced Settings Security Vulnerabilities

No known vulnerabilities — this is a good sign.
Version History

DLM – Advanced Settings Release Timeline

v1.0.4Current
v1.0.3
v1.0.1
v1.0.0
Code Analysis
Analyzed Apr 16, 2026

DLM – Advanced Settings Code Analysis

Dangerous Functions
0
Raw SQL Queries
0
0 prepared
Unescaped Output
0
25 escaped
Nonce Checks
0
Capability Checks
0
File Operations
0
External Requests
0
Bundled Libraries
0

Output Escaping

100% escaped25 total outputs
Attack Surface

DLM – Advanced Settings Attack Surface

Entry Points0
Unprotected0
WordPress Hooks 8
actionadmin_headclass-dlm-as-hooks.php:319
actionadmin_noticesdlm-advanced-settings.php:164
actionadmin_initdlm-advanced-settings.php:233
filterdlm_admin_menu_linksdlm-advanced-settings.php:234
actioninitdlm-advanced-settings.php:235
actioninitdlm-advanced-settings.php:236
actionpre_update_optiondlm-advanced-settings.php:237
actionplugins_loadeddlm-advanced-settings.php:567
Maintenance & Trust

DLM – Advanced Settings Maintenance & Trust

Maintenance Signals

WordPress version tested6.8.5
Last updatedJul 10, 2025
PHP min version7.4
Downloads1K

Community Trust

Rating0/100
Number of ratings0
Active installs0
Developer Profile

DLM – Advanced Settings Developer Profile

Razvan Aldea

3 plugins · 3K total installs

94
trust score
Avg Security Score
100/100
Avg Patch Time
30 days
View full developer profile
Detection Fingerprints

How We Detect DLM – Advanced Settings

Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.

Asset Fingerprints

Asset Paths
/wp-content/plugins/dlm-advanced-settings/assets/css/backend.css/wp-content/plugins/dlm-advanced-settings/assets/js/backend.js
Script Paths
/wp-content/plugins/dlm-advanced-settings/assets/js/backend.js
Version Parameters
dlm-advanced-settings/assets/css/backend.css?ver=dlm-advanced-settings/assets/js/backend.js?ver=

HTML / DOM Fingerprints

CSS Classes
wpchill-togglewpchill-toggle__inputwpchill-toggle__itemswpchill-toggle__trackwpchill-toggle__items__rightwpchill-toggle__items__left
HTML Comments
<!-- Cycle through settings. -->
Data Attributes
data-dlm-advanced-settings
JS Globals
dlmAdvancedSettings
FAQ

Frequently Asked Questions about DLM – Advanced Settings