
Download After Email – Subscribe & Download Form Plugin Security & Risk Analysis
wordpress.org/plugins/download-after-emailDownload After Email is a free Subscribe & Download plugin that allows you to gain subscribers by offering free downloads.
Is Download After Email – Subscribe & Download Form Plugin Safe to Use in 2026?
Mostly Safe
Score 76/100Download After Email – Subscribe & Download Form Plugin is generally safe to use. 2 past CVEs were resolved. Keep it updated.
The 'download-after-email' plugin v2.1.9 presents a mixed security posture with several concerning areas despite some good practices. The plugin demonstrates a strong adherence to secure coding practices concerning SQL queries and output escaping, with 96% and 98% respectively being properly handled. It also incorporates a reasonable number of nonce and capability checks. However, a significant concern arises from the attack surface, where 4 out of 10 AJAX handlers lack authentication checks, leaving them vulnerable to unauthorized access and potential exploitation. The taint analysis, while not revealing critical or high severity issues, did identify 2 high-severity flows with unsanitized paths, indicating a risk of sensitive data handling or execution pathways being compromised if not properly validated.
The vulnerability history reveals a pattern of medium severity issues, specifically related to missing authorization and uncontrolled resource consumption. The presence of an unpatched CVE, even if medium severity, is a direct and ongoing risk that cannot be ignored. The fact that the last vulnerability was recent (2026-01-24) suggests ongoing security challenges with this plugin. Overall, while the plugin has strengths in its core coding practices, the unprotected AJAX endpoints, taint flow concerns, and unpatched vulnerability significantly increase its risk profile.
Key Concerns
- Unprotected AJAX handlers
- Unpatched CVE
- High severity taint flows
Download After Email – Subscribe & Download Form Plugin Security Vulnerabilities
CVEs by Year
Severity Breakdown
2 total CVEs
Download After Email <= 2.1.9 - Missing Authorization
Download After Email 2.1.5 - 2.1.6 - Unauthorized Repeated Form Submissions
Download After Email – Subscribe & Download Form Plugin Code Analysis
SQL Query Safety
Output Escaping
Data Flow Analysis
Download After Email – Subscribe & Download Form Plugin Attack Surface
AJAX Handlers 10
Shortcodes 1
WordPress Hooks 26
Scheduled Events 1
Maintenance & Trust
Download After Email – Subscribe & Download Form Plugin Maintenance & Trust
Maintenance Signals
Community Trust
Download After Email – Subscribe & Download Form Plugin Alternatives
MC4WP: Mailchimp for WordPress
mailchimp-for-wp
The #1 Mailchimp plugin for WordPress. Allows you to add a multitude of newsletter sign-up methods to your site.
MailChimp Forms by MailMunch
mailchimp-forms-by-mailmunch
MailChimp Forms to get more email subscribers. Subscribe your WordPress visitors to your MailChimp lists easily.
MC4WP: Mailchimp Top Bar
mailchimp-top-bar
Adds a Mailchimp opt-in form to the top or bottom of your WordPress site.
Another Mailchimp Widget
another-mailchimp-widget
Simple Mailchimp subscription form to your lists and groups.
Convertful – Your Ultimate On-Site Conversion Tool
convertful
All the modern on-site conversion solutions, natively integrates with all modern Email Marketing Platforms.
Download After Email – Subscribe & Download Form Plugin Developer Profile
1 plugin · 7K total installs
How We Detect Download After Email – Subscribe & Download Form Plugin
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/download-after-email/css/dae-style.css/wp-content/plugins/download-after-email/js/dae-script.jsdownload-after-email/css/dae-style.css?ver=download-after-email/js/dae-script.js?ver=HTML / DOM Fingerprints
dae-form-containerdae-download-linkdae-subscriber-formdae-success-message<!-- DAE deny access download files --><!-- DAEPdata-dae-iddata-dae-filedae_ajax_object[download_after_email][download-after-email]