
Download PDF After Submit Form Security & Risk Analysis
wordpress.org/plugins/download-pdf-after-submit-formEasily allow users to download PDFs after submitting a form with customizable shortcodes. No coding required – just install and configure!
Is Download PDF After Submit Form Safe to Use in 2026?
Generally Safe
Score 100/100Download PDF After Submit Form has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.
The 'download-pdf-after-submit-form' plugin version 2.2.6 demonstrates a generally good security posture based on the provided static analysis. It exhibits strong practices in several key areas, including a complete absence of dangerous functions, SQL injection vulnerabilities (all queries use prepared statements), and a very high rate of properly escaped output. The plugin also avoids file operations and external HTTP requests, further reducing potential attack vectors. Furthermore, the lack of known CVEs and a clean vulnerability history indicate a stable and well-maintained codebase. However, there is one notable weakness: the absence of capability checks on any entry points. While the attack surface is currently small and has only one unprotected entry point (a shortcode), any future expansion of functionality or modifications that introduce new entry points without proper capability checks could expose the plugin to privilege escalation or unauthorized access vulnerabilities. The presence of a nonce check is a positive sign, but it is not a substitute for robust authorization checks.
Key Concerns
- No capability checks on entry points
Download PDF After Submit Form Security Vulnerabilities
Download PDF After Submit Form Code Analysis
Output Escaping
Data Flow Analysis
Download PDF After Submit Form Attack Surface
Shortcodes 1
WordPress Hooks 9
Maintenance & Trust
Download PDF After Submit Form Maintenance & Trust
Maintenance Signals
Community Trust
Download PDF After Submit Form Alternatives
No alternatives data available yet.
Download PDF After Submit Form Developer Profile
7 plugins · 730 total installs
How We Detect Download PDF After Submit Form
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.