Download Button Security & Risk Analysis

wordpress.org/plugins/download-button

Download Button plugins will help you to add download buttons in your posts. You needn't to remember the url of download button image any more. Just write [dwn|Your file's url|btn] , where ever need to place an download button . If you want the link to be open in a new tab or window write: [dwn|Your file's url|outbtn] . There are 3 button embeded is this version to use them write [dwn|Your file's url|btn] , [dwn|Your file's url|btn2] , or [dwn|Your file's url|btn3] , to open windows in new tab write: [dwn|Your file's url|outbtn], [dwn|Your file's url|outbtn2], or [dwn|Your file's url|outbtn3]. Examples : http://img403.imageshack.us/img403/2892/screenshot1gc.jpg and http://img403.imageshack.us/img403/5764/screenshot2vw.jpg

10 active installs v0.7 PHP + WP + Updated Feb 6, 2010
85
A · Safe
CVEs total0
Unpatched0
Last CVENever
Safety Verdict

Is Download Button Safe to Use in 2026?

Generally Safe

Score 85/100

Download Button has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.

No known CVEs Updated 16yr ago
Risk Assessment

The "download-button" v0.7 plugin exhibits a strong security posture based on the provided static analysis. The absence of identified dangerous functions, SQL injection vulnerabilities through prepared statements, and the complete use of output escaping are excellent indicators of secure coding practices. Furthermore, the lack of file operations and external HTTP requests minimizes potential attack vectors. The plugin also demonstrates a good understanding of WordPress security by not exposing unprotected AJAX handlers, REST API routes, shortcodes, or cron events. The vulnerability history is also clear, with no recorded CVEs, which is a positive sign of the plugin's stability and security over time. While the lack of explicit nonce and capability checks is noted, the current analysis shows no exploitable entry points to leverage this absence. Overall, the plugin appears to be securely developed with no immediate critical vulnerabilities detected in the static analysis or historical data.

Vulnerabilities
None known

Download Button Security Vulnerabilities

No known vulnerabilities — this is a good sign.
Code Analysis
Analyzed Mar 17, 2026

Download Button Code Analysis

Dangerous Functions
0
Raw SQL Queries
0
0 prepared
Unescaped Output
0
0 escaped
Nonce Checks
0
Capability Checks
0
File Operations
0
External Requests
0
Bundled Libraries
0
Attack Surface

Download Button Attack Surface

Entry Points0
Unprotected0
WordPress Hooks 1
filterthe_contentDownload Button.php:10
Maintenance & Trust

Download Button Maintenance & Trust

Maintenance Signals

WordPress version tested
Last updatedFeb 6, 2010
PHP min version
Downloads5K

Community Trust

Rating0/100
Number of ratings0
Active installs10
Alternatives

Download Button Alternatives

No alternatives data available yet.

Developer Profile

Download Button Developer Profile

arifnezami

4 plugins · 40 total installs

86
trust score
Avg Security Score
89/100
Avg Patch Time
30 days
View full developer profile
Detection Fingerprints

How We Detect Download Button

Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.

Asset Fingerprints

Asset Paths
/wp-content/plugins/download-button/pics/dwnbtn.png/wp-content/plugins/download-button/pics/dwnbtn2.png/wp-content/plugins/download-button/pics/dwnbtn3.png
Version Parameters
download-button/pics/dwnbtn.png?ver=download-button/pics/dwnbtn2.png?ver=download-button/pics/dwnbtn3.png?ver=

HTML / DOM Fingerprints

Shortcode Output
a href=""><img src="" target="_blank"><img src="/wp-content/plugins/download-button/pics/dwnbtn.png" /></a>
FAQ

Frequently Asked Questions about Download Button