
Download Plugin Security & Risk Analysis
wordpress.org/plugins/download-pluginDownload any plugin from your WordPress admin panel's Plugins page by just one click! Now, download themes, users, blog posts, pages, custom post …
Is Download Plugin Safe to Use in 2026?
Generally Safe
Score 94/100Download Plugin has a strong security track record. Known vulnerabilities have been patched promptly. It's a solid choice for most WordPress installations.
The 'download-plugin' v2.4.0 exhibits a mixed security posture. While it demonstrates strengths in SQL query handling with 100% prepared statements and a high rate of output escaping (80%), concerns arise from its attack surface. The presence of one unprotected AJAX handler is a significant risk, as it could be exploited by unauthenticated users. The use of the `unserialize` function is also a red flag, potentially leading to Remote Code Execution if not handled with extreme care and sanitization of its input, which is not explicitly detailed as safe in the provided data. Taint analysis shows no critical or high severity flows, which is a positive sign. However, the plugin's historical vulnerability record is concerning. With five known CVEs, including one high-severity vulnerability, and a recent vulnerability in 2025, it suggests a pattern of security weaknesses that require diligent patching and potentially a more robust development process. The common vulnerability types also point to recurring issues like missing authorization and CSRF, which are critical for secure web applications.
Key Concerns
- AJAX handler without auth check
- Dangerous function: unserialize
- One high severity historical CVE
- Flow with unsanitized path
- Output escaping rate below 100%
Download Plugin Security Vulnerabilities
CVEs by Year
Severity Breakdown
5 total CVEs
Download Plugin <= 2.2.8 - Authenticated (Administrator+) Arbitrary File Upload
Download Plugin <= 2.2.0 - Missing Authorization to Authenticated (Subscriber+) User Metadata and Comment Download
Download Plugin <= 2.0.4 - Cross-Site Request Forgery
Download Plugin <= 1.6.2 - Missing Authorization and Sensitive Information Exposure
Download Plugin < 1.6.1 - Cross-Site Request Forgery
Download Plugin Release Timeline
Download Plugin Code Analysis
Dangerous Functions Found
Output Escaping
Data Flow Analysis
Download Plugin Attack Surface
AJAX Handlers 5
WordPress Hooks 28
Maintenance & Trust
Download Plugin Maintenance & Trust
Maintenance Signals
Community Trust
Download Plugin Alternatives
File Manager Pro – Filester
filester
Advanced File Manager and Code Editor. Best WordPress file manager without FTP access. No need to upgrade because this is PRO version.
Download Plugins and Themes in ZIP from Dashboard
download-plugins-dashboard
Download installed plugins and themes in ZIP files directly from your WordPress admin dashboard, download any or all plugins & themes without FTP …
KP Zip Downloader
kp-zip-downloader
This plugin allows administrators to download installed plugins and themes as ZIP files directly from the WordPress dashboard.
Quick Download – Themes and Plugins from WP Dashboard
quick-download
Download Themes and Pluigns directly from WordPress Dashboard.
Download Theme | Plugin | WC products zip from dashboard
woocommerce-downlaod-product-from-admin
download themes | plugins and products from dashboard as Zip file
Download Plugin Developer Profile
7 plugins · 79K total installs
How We Detect Download Plugin
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/download-plugin/vendor/autoload.phpHTML / DOM Fingerprints
dpwap_downloaddpwap_bulk_download