Download Monitor – CORS Security & Risk Analysis

wordpress.org/plugins/download-monitor-cors

Download Monitor is a plugin for selling, uploading and managing downloads, tracking downloads and displaying links.

100 active installs v1.0.1 PHP 5.6+ WP 5.4+ Updated Dec 2, 2025
digital-storedocument-managementdocument-management-plugindownload-managerfile-manager
100
A · Safe
CVEs total0
Unpatched0
Last CVENever
Safety Verdict

Is Download Monitor – CORS Safe to Use in 2026?

Generally Safe

Score 100/100

Download Monitor – CORS has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.

No known CVEs Updated 5mo ago
Risk Assessment

Based on the provided static analysis and vulnerability history, the "download-monitor-cors" v1.0.1 plugin appears to have a very strong security posture. The static analysis reveals no identified attack vectors such as unprotected AJAX handlers, REST API routes, shortcodes, or cron events. Furthermore, the code demonstrates excellent security practices by avoiding dangerous functions, exclusively using prepared statements for SQL queries, properly escaping all output, and not performing file operations or external HTTP requests. The absence of taint analysis findings further reinforces this strong assessment, indicating no identified flows with unsanitized paths. The plugin's vulnerability history is also completely clean, with zero known CVEs, unpatched vulnerabilities, or recorded common vulnerability types.

While the lack of identified vulnerabilities and the rigorous adherence to secure coding practices are highly positive, it's important to acknowledge the complete absence of nonce checks and capability checks. Although the current attack surface is zero, if future updates introduce any form of user interaction or data handling, these checks would become critical for maintaining security. Nevertheless, for version 1.0.1 and based on the current data, the plugin exhibits a robust security profile with no immediate risks identified.

Vulnerabilities
None known

Download Monitor – CORS Security Vulnerabilities

No known vulnerabilities — this is a good sign.
Version History

Download Monitor – CORS Release Timeline

v1.0.1Current
v1.0.0
Code Analysis
Analyzed Mar 16, 2026

Download Monitor – CORS Code Analysis

Dangerous Functions
0
Raw SQL Queries
0
0 prepared
Unescaped Output
0
0 escaped
Nonce Checks
0
Capability Checks
0
File Operations
0
External Requests
0
Bundled Libraries
0
Attack Surface

Download Monitor – CORS Attack Surface

Entry Points0
Unprotected0
WordPress Hooks 5
filterdlm_settingsdlm-cors.php:59
actionadmin_initdlm-cors.php:60
filterdlm_xhr_download_headersdlm-cors.php:74
actionsend_headersdlm-cors.php:75
actionadmin_noticesdlm-cors.php:89
Maintenance & Trust

Download Monitor – CORS Maintenance & Trust

Maintenance Signals

WordPress version tested6.9.4
Last updatedDec 2, 2025
PHP min version5.6
Downloads3K

Community Trust

Rating0/100
Number of ratings0
Active installs100
Developer Profile

Download Monitor – CORS Developer Profile

WP Chill

29 plugins · 420K total installs

76
trust score
Avg Security Score
95/100
Avg Patch Time
560 days
View full developer profile
Detection Fingerprints

How We Detect Download Monitor – CORS

Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.

Asset Fingerprints

Asset Paths
/wp-content/plugins/download-monitor-cors/dlm-cors.php

HTML / DOM Fingerprints

FAQ

Frequently Asked Questions about Download Monitor – CORS