Download Count for WooCommerce Security & Risk Analysis

wordpress.org/plugins/download-count-for-woocommerce

Displays the number of products downloaded by customers.

20 active installs v1.21 PHP 8.0+ WP 4.6+ Updated Mar 29, 2026
countdownloadproductwoocommerce
100
A · Safe
CVEs total0
Unpatched0
Last CVENever
Safety Verdict

Is Download Count for WooCommerce Safe to Use in 2026?

Generally Safe

Score 100/100

Download Count for WooCommerce has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.

No known CVEs Updated 1mo ago
Risk Assessment

The "download-count-for-woocommerce" plugin version 1.21 exhibits a generally strong security posture based on the provided static analysis. The absence of any identified AJAX handlers, REST API routes, shortcodes, or cron events significantly limits the plugin's attack surface, and importantly, there are no unprotected entry points. Code signals also indicate good practices in output escaping, with 100% of outputs being properly escaped. The lack of dangerous functions, file operations, and external HTTP requests further contribute to a secure foundation.

However, a notable concern arises from the presence of two SQL queries that are not using prepared statements. While the total number is low, the lack of prepared statements in any SQL query represents a potential risk for SQL injection vulnerabilities, especially if the data used in these queries is derived from user input. The absence of any recorded vulnerability history or taint flow issues is positive, suggesting a history of secure development. Nevertheless, the unmitigated SQL queries remain the primary area of concern from this analysis.

In conclusion, the plugin demonstrates good overall security hygiene by minimizing its attack surface and properly escaping outputs. The vulnerability history is also reassuring. The most significant weakness lies in the use of raw SQL queries. Addressing this by implementing prepared statements for all SQL operations would further enhance the plugin's security and eliminate a potential vector for attacks.

Key Concerns

  • Raw SQL queries without prepared statements
Vulnerabilities
None known

Download Count for WooCommerce Security Vulnerabilities

No known vulnerabilities — this is a good sign.
Version History

Download Count for WooCommerce Release Timeline

v1.21Current
v1.20
v1.19
v1.18
v1.17
v1.16
v1.15
v1.14
v1.13
v1.12
v1.11
v1.10
v1.09
v1.08
v1.07
v1.06
v1.05
v1.04
v1.03
v1.02
Code Analysis
Analyzed Mar 16, 2026

Download Count for WooCommerce Code Analysis

Dangerous Functions
0
Raw SQL Queries
2
0 prepared
Unescaped Output
0
0 escaped
Nonce Checks
0
Capability Checks
0
File Operations
0
External Requests
0
Bundled Libraries
0

SQL Query Safety

0% prepared2 total queries
Attack Surface

Download Count for WooCommerce Attack Surface

Entry Points0
Unprotected0
WordPress Hooks 1
actionbefore_woocommerce_initdownloadcountwoo.php:41
Maintenance & Trust

Download Count for WooCommerce Maintenance & Trust

Maintenance Signals

WordPress version tested7.0
Last updatedMar 29, 2026
PHP min version8.0
Downloads4K

Community Trust

Rating0/100
Number of ratings0
Active installs20
Developer Profile

Download Count for WooCommerce Developer Profile

Katsushi Kawamori

54 plugins · 56K total installs

79
trust score
Avg Security Score
100/100
Avg Patch Time
178 days
View full developer profile
Detection Fingerprints

How We Detect Download Count for WooCommerce

Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.

Asset Fingerprints

HTML / DOM Fingerprints

FAQ

Frequently Asked Questions about Download Count for WooCommerce