Download PDF After Submit Form Security & Risk Analysis

wordpress.org/plugins/download-pdf-after-submit-form

Easily allow users to download PDFs after submitting a form with customizable shortcodes. No coding required – just install and configure!

500 active installs v2.2.6 PHP 7.4+ WP 5.8+ Updated Mar 15, 2026
download-pdf-after-submit-formlock-pdf-after-signingpassword-protect-a-pdfrestricted-content-downloadrestricted-pdf
100
A · Safe
CVEs total0
Unpatched0
Last CVENever
Safety Verdict

Is Download PDF After Submit Form Safe to Use in 2026?

Generally Safe

Score 100/100

Download PDF After Submit Form has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.

No known CVEs Updated 19d ago
Risk Assessment

The 'download-pdf-after-submit-form' plugin version 2.2.6 demonstrates a generally good security posture based on the provided static analysis. It exhibits strong practices in several key areas, including a complete absence of dangerous functions, SQL injection vulnerabilities (all queries use prepared statements), and a very high rate of properly escaped output. The plugin also avoids file operations and external HTTP requests, further reducing potential attack vectors. Furthermore, the lack of known CVEs and a clean vulnerability history indicate a stable and well-maintained codebase. However, there is one notable weakness: the absence of capability checks on any entry points. While the attack surface is currently small and has only one unprotected entry point (a shortcode), any future expansion of functionality or modifications that introduce new entry points without proper capability checks could expose the plugin to privilege escalation or unauthorized access vulnerabilities. The presence of a nonce check is a positive sign, but it is not a substitute for robust authorization checks.

Key Concerns

  • No capability checks on entry points
Vulnerabilities
None known

Download PDF After Submit Form Security Vulnerabilities

No known vulnerabilities — this is a good sign.
Code Analysis
Analyzed Mar 16, 2026

Download PDF After Submit Form Code Analysis

Dangerous Functions
0
Raw SQL Queries
0
0 prepared
Unescaped Output
1
82 escaped
Nonce Checks
1
Capability Checks
0
File Operations
0
External Requests
0
Bundled Libraries
0

Output Escaping

99% escaped83 total outputs
Data Flows
All sanitized

Data Flow Analysis

2 flows
dpbsf_shortcode_wrapper (index.php:31)
Source (user input) Sink (dangerous op) Sanitizer Transform Unsanitized Sanitized
Attack Surface

Download PDF After Submit Form Attack Surface

Entry Points1
Unprotected0

Shortcodes 1

[formtodownload] index.php:290
WordPress Hooks 9
actionwp_enqueue_scriptsinclude\enqueue.php:9
actionadmin_enqueue_scriptsinclude\enqueue.php:17
actioninitinclude\posttype.php:6
actionadmin_headinclude\posttype.php:54
actionadd_meta_boxesinclude\posttype.php:78
filtergettextinclude\posttype.php:91
actionadmin_menuinclude\posttype.php:93
actionadmin_initindex.php:294
actionadmin_menuindex.php:316
Maintenance & Trust

Download PDF After Submit Form Maintenance & Trust

Maintenance Signals

WordPress version tested6.9.4
Last updatedMar 15, 2026
PHP min version7.4
Downloads11K

Community Trust

Rating64/100
Number of ratings6
Active installs500
Alternatives

Download PDF After Submit Form Alternatives

No alternatives data available yet.

Developer Profile

Download PDF After Submit Form Developer Profile

Md. Shahinur Islam

7 plugins · 730 total installs

94
trust score
Avg Security Score
100/100
Avg Patch Time
11 days
View full developer profile
Detection Fingerprints

How We Detect Download PDF After Submit Form

Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.

Asset Fingerprints

HTML / DOM Fingerprints

FAQ

Frequently Asked Questions about Download PDF After Submit Form