
Download Media Library Security & Risk Analysis
wordpress.org/plugins/download-media-libraryDownload the files from the Media Library in ZIP format.
Is Download Media Library Safe to Use in 2026?
Use With Caution
Score 60/100Download Media Library has 1 unpatched vulnerability. Evaluate alternatives or apply available mitigations.
The "download-media-library" plugin v0.2.1 exhibits a concerning security posture, despite having no directly exploitable entry points identified in the static analysis. The absence of AJAX handlers, REST API routes, shortcodes, and cron events without authentication checks is a positive sign. However, this limited attack surface also means fewer opportunities to assess its security controls in practice.
The code analysis reveals significant weaknesses, particularly in its handling of SQL queries, with 100% of them not using prepared statements, a major security risk that could lead to SQL injection vulnerabilities. Furthermore, only 33% of output is properly escaped, leaving room for cross-site scripting (XSS) attacks. The presence of two unsanitized path flows in the taint analysis, while not resulting in critical or high severity issues in this scan, indicates a potential for directory traversal or insecure file access, especially given the file operation functions present.
The plugin's vulnerability history is alarming. With one known high-severity CVE that remains unpatched, and its last vulnerability dated at the end of 2025, it strongly suggests a pattern of security flaws. The common vulnerability type being "Exposure of Sensitive Information to an Unauthorized Actor" directly correlates with the identified issues in output escaping and potentially file operations. While the current static analysis didn't find exploitable vulnerabilities, the historical data and code signals point to a plugin that has had and likely continues to have significant security weaknesses.
Key Concerns
- Unpatched high-severity CVE
- 100% of SQL queries unprepared
- Only 33% of output properly escaped
- Taint flow with unsanitized paths
- No capability checks found
- No nonce checks found
Download Media Library Security Vulnerabilities
CVEs by Year
Severity Breakdown
1 total CVE
Download Media Library <= 0.2.1 - Unauthenticated Sensitive Information Exposure
Download Media Library Code Analysis
SQL Query Safety
Output Escaping
Data Flow Analysis
Download Media Library Attack Surface
WordPress Hooks 3
Maintenance & Trust
Download Media Library Maintenance & Trust
Maintenance Signals
Community Trust
Download Media Library Alternatives
Export Media Library
export-media-library
Allows users to export media library files as a compressed zip archive. Links Website Support
Media Library File Download
media-download
A lightweight plugin that adds one-click download and export functionality to your Media Library.
Safe SVG
safe-svg
Enable SVG uploads and sanitize them to stop XML/SVG vulnerabilities in your WordPress website.
Enable Media Replace
enable-media-replace
Easily replace any attached image/file by simply uploading a new file in the Media Library edit view - a real time saver!
AddToAny Share Buttons
add-to-any
Share buttons for WordPress including the AddToAny button, Facebook, Bluesky, Mastodon, WhatsApp, Pinterest, Reddit, many more, and follow icons too.
Download Media Library Developer Profile
2 plugins · 1K total installs
How We Detect Download Media Library
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/download-media-library/assets/js/admin.js/wp-content/plugins/download-media-library/assets/js/admin.jsdownload-media-library/assets/js/admin.js?ver=