
Download Plugins and Themes in ZIP from Dashboard Security & Risk Analysis
wordpress.org/plugins/download-plugins-dashboardDownload installed plugins and themes in ZIP files directly from your WordPress admin dashboard, download any or all plugins & themes without FTP …
Is Download Plugins and Themes in ZIP from Dashboard Safe to Use in 2026?
Generally Safe
Score 95/100Download Plugins and Themes in ZIP from Dashboard has a strong security track record. Known vulnerabilities have been patched promptly.
The 'download-plugins-dashboard' v1.9.9 plugin exhibits a mixed security posture. On the positive side, the static analysis reveals no direct unprotected entry points like unauthenticated AJAX handlers, REST API routes, or shortcodes. The code also demonstrates good practices with 100% of SQL queries utilizing prepared statements and a reasonable number of capability checks. However, a significant concern is the output escaping, with only 57% of outputs properly escaped, indicating a potential for Cross-Site Scripting (XSS) vulnerabilities if user-supplied data is not adequately sanitized before being displayed.
Taint analysis found no critical or high severity issues, which is encouraging. The presence of 5 file operations and 5 nonce checks suggests some interaction with the file system and a moderate level of security implementation. Despite the clean taint analysis for this specific version, the plugin's vulnerability history is a major red flag. With 5 known CVEs, all medium severity, and recurring themes of CSRF, Path Traversal, and XSS, it indicates a pattern of past exploitable weaknesses. The fact that the last vulnerability was recorded in late 2025 suggests that while this specific version (v1.9.9) might not have immediate unpatched critical/high issues, the plugin itself has a track record of security flaws that require careful attention and ongoing monitoring.
In conclusion, while 'download-plugins-dashboard' v1.9.9 presents a seemingly clean bill of health in terms of immediate critical vulnerabilities based on the static and taint analysis for this version, its past vulnerability history cannot be ignored. The moderate output escaping is a potential weakness, and the plugin's track record suggests a higher than average risk of future undiscovered or reintroduced vulnerabilities. Users should proceed with caution and ensure robust security practices are in place.
Key Concerns
- Only 57% of outputs properly escaped
- History of 5 medium severity CVEs
- Common vulnerability types: CSRF, Path Traversal, XSS
Download Plugins and Themes in ZIP from Dashboard Security Vulnerabilities
CVEs by Year
Severity Breakdown
5 total CVEs
Download Plugins and Themes from Dashboard <= 1.9.6 - Cross-Site Request Forgery to Bulk Plugin/Theme Archival
Download Plugins and Themes in ZIP from Dashboard <= 1.9.1 - Reflected Cross-Site Scripting
Download Plugins and Themes from Dashboard <= 1.8.7 - Cross-Site Request Forgery
Download Plugins and Themes from Dashboard <= 1.8.5 - Authenticated (Admin+) Arbitrary File Download
Download Plugins and Themes from Dashboard <= 1.5.0 - Unauthenticated Stored Cross-Site Scripting
Download Plugins and Themes in ZIP from Dashboard Code Analysis
Output Escaping
Data Flow Analysis
Download Plugins and Themes in ZIP from Dashboard Attack Surface
WordPress Hooks 28
Scheduled Events 2
Maintenance & Trust
Download Plugins and Themes in ZIP from Dashboard Maintenance & Trust
Maintenance Signals
Community Trust
Download Plugins and Themes in ZIP from Dashboard Alternatives
Quick Download – Themes and Plugins from WP Dashboard
quick-download
Download Themes and Pluigns directly from WordPress Dashboard.
Download Theme | Plugin | WC products zip from dashboard
woocommerce-downlaod-product-from-admin
download themes | plugins and products from dashboard as Zip file
Download Theme
download-theme
Download any theme from your WordPress admin panel's Appearance page by just one click!
File Manager Pro – Filester
filester
Advanced File Manager and Code Editor. Best WordPress file manager without FTP access. No need to upgrade because this is PRO version.
Download Plugin
download-plugin
Download any plugin from your WordPress admin panel's Plugins page by just one click! Now, download themes, users, blog posts, pages, custom post …
Download Plugins and Themes in ZIP from Dashboard Developer Profile
63 plugins · 136K total installs
How We Detect Download Plugins and Themes in ZIP from Dashboard
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/download-plugins-dashboard/includes/js/theme_download_link.js/wp-content/plugins/download-plugins-dashboard/includes/js/theme_download_link.min.js/wp-content/plugins/download-plugins-dashboard/vendor/autoload.phpdownload-plugins-dashboard/includes/js/theme_download_link.js?ver=download-plugins-dashboard/includes/js/theme_download_link.min.js?ver=HTML / DOM Fingerprints
alg_localize_objectalg_object