
Download Counter Security & Risk Analysis
wordpress.org/plugins/download-counterCounts the number of downloads for files and displays a table with the results.
Is Download Counter Safe to Use in 2026?
Mostly Safe
Score 74/100Download Counter is generally safe to use. 2 past CVEs were resolved. Keep it updated.
The 'download-counter' plugin v1.4 exhibits a mixed security posture. On one hand, it demonstrates good practices like a high percentage of prepared SQL statements and properly escaped output, along with the absence of file operations and external HTTP requests, suggesting a developer conscious of common web vulnerabilities. However, the presence of two 'unserialize' calls is a significant concern, as it can lead to Remote Code Execution if not handled with extreme care. While the static analysis shows no unprotected entry points and a reasonable number of nonce checks, the taint analysis highlights one flow with unsanitized paths, which could potentially be exploited for path traversal attacks, especially given the plugin's vulnerability history that includes this very type of vulnerability.
Key Concerns
- Unpatched High Severity CVE
- High severity taint flow with unsanitized paths
- Use of dangerous 'unserialize' function
- Vulnerability history includes Path Traversal
- Vulnerability history includes XSS
Download Counter Security Vulnerabilities
CVEs by Year
Severity Breakdown
2 total CVEs
Download Counter <= 1.3 - Authenticated (Contributor+) Stored Cross-Site Scripting via name Parameter
Download Counter <= 1.4 - Unauthenticated Arbitrary File Read
Download Counter Code Analysis
Dangerous Functions Found
SQL Query Safety
Output Escaping
Data Flow Analysis
Download Counter Attack Surface
Shortcodes 4
WordPress Hooks 9
Maintenance & Trust
Download Counter Maintenance & Trust
Maintenance Signals
Community Trust
Download Counter Alternatives
Post Views Counter
post-views-counter
Post Views Counter allows you to collect and display how many times a post, page, or other content has been viewed in a simple, fast and reliable way.
Visitor Traffic Real Time Statistics
visitors-traffic-real-time-statistics
This plugin will help you to track your visitors, browsers, operating systems, visits and much more in one dashboard page.
WP Post Statistics (Visitors & Visits Counter)
wp-post-real-time-statistics
a simple tool to know your post statistics
Kama Click Counter
kama-clic-counter
Count clicks on any link across the site. Creates a beautiful file download block in post content. Includes a widget for top downloads.
ExtraWatch (Live Stats, Realtime tracking, Visits on a map and more)
extrawatch
See visits and clicks on your website in realtime!
Download Counter Developer Profile
2 plugins · 50 total installs
How We Detect Download Counter
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/download-counter/download-counter.phpdownload-counter.php?ver=HTML / DOM Fingerprints
[download_counter_url[download_counter_count[download_counter_size[download_counter_date