
DLM Changelog Add-on Security & Risk Analysis
wordpress.org/plugins/dlm-changelogAn add-on for Mike Jolley's Download Monitor which adds version changelog functionality.
Is DLM Changelog Add-on Safe to Use in 2026?
Generally Safe
Score 85/100DLM Changelog Add-on has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.
The 'dlm-changelog' v1.2.1 plugin presents a mixed security posture. While it demonstrates good practices by avoiding dangerous functions, performing all SQL queries with prepared statements, and having no file operations or external HTTP requests, significant concerns arise from its attack surface and output escaping practices. The presence of one AJAX handler without authentication checks is a notable vulnerability, as it can be triggered by any user, potentially leading to unauthorized actions or information disclosure depending on its functionality. Furthermore, the low percentage of properly escaped output across 17 total outputs suggests a high risk of Cross-Site Scripting (XSS) vulnerabilities, allowing attackers to inject malicious scripts into the site, which could compromise user sessions or deface the website. The absence of known CVEs and past vulnerabilities is a positive indicator of its development history, suggesting the developers may be responsive to security issues. However, the current static analysis reveals critical weaknesses that overshadow this positive history, particularly the unprotected AJAX endpoint and the prevalent unescaped output, which represent immediate threats.
Key Concerns
- AJAX handler without authentication check
- Low percentage of properly escaped output
DLM Changelog Add-on Security Vulnerabilities
DLM Changelog Add-on Release Timeline
DLM Changelog Add-on Code Analysis
Output Escaping
Data Flow Analysis
DLM Changelog Add-on Attack Surface
AJAX Handlers 1
Shortcodes 1
WordPress Hooks 11
Maintenance & Trust
DLM Changelog Add-on Maintenance & Trust
Maintenance Signals
Community Trust
DLM Changelog Add-on Alternatives
Download Monitor & Restrict Content integration
download-monitor-restrict-content-integration
The WordPress gallery plugin that's highly customizable & you can use to impress your clients. Create beautiful image galleries in minutes.
Download Monitor & Paid Membership Pro integration
download-monitor-paid-membership-pro-integration
The WordPress gallery plugin that's highly customizable & you can use to impress your clients. Create beautiful image galleries in minutes.
Download Monitor & LearnDash integration
download-monitor-learndash-integration
The WordPress gallery plugin that's highly customizable & you can use to impress your clients. Create beautiful image galleries in minutes.
Download Monitor Page Addon QR Code
download-monitor-page-addon-qr-code
Add a QR Code below Download button for Mike Jolley's Download Monitor Page Addon
Meta for WooCommerce
facebook-for-woocommerce
Get the Official Meta for WooCommerce plugin for powerful ways to help grow your business.
DLM Changelog Add-on Developer Profile
1 plugin · 10 total installs
How We Detect DLM Changelog Add-on
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/dlm-changelog/assets/css/shortcode.css