[{"data":1,"prerenderedAt":-1},["ShallowReactive",2],{"$fj6HnhCILfxHGtTD3K3Y3wpMkfeYx8XS1nn-JD7ArOCM":3},{"slug":4,"name":5,"version":6,"author":7,"author_profile":8,"description":9,"short_description":10,"active_installs":11,"downloaded":12,"rating":13,"num_ratings":14,"last_updated":15,"tested_up_to":16,"requires_at_least":17,"requires_php":18,"tags":19,"homepage":24,"download_link":25,"security_score":26,"vuln_count":27,"unpatched_count":28,"last_vuln_date":29,"fetched_at":30,"vulnerabilities":31,"developer":102,"crawl_stats":37,"alternatives":110,"analysis":212,"fingerprints":393},"download-plugins-dashboard","Download Plugins and Themes in ZIP from Dashboard","1.9.9","WPFactory","https:\u002F\u002Fprofiles.wordpress.org\u002Fwpcodefactory\u002F","\u003Cblockquote>\n\u003Cp>“Awesome plugin! So helpful in development! I’m a WordPress developer and constantly get into situations where I have to download a theme or plugin from the clients’ servers to debug\u002Fcustomize\u002Fetc. In these situations, “Download Plugins and Themes from Dashboard” is the number one choice and way to go. Works perfectly, as described. Many thanks to the developer. Thumbs up!!” – ⭐⭐⭐⭐⭐ \u003Ca href=\"https:\u002F\u002Fwordpress.org\u002Fsupport\u002Ftopic\u002Fawesome-plugin-so-helpful-in-development\u002F?utm_source=wporg&utm_medium=organic&utm_campaign=readme\" rel=\"ugc\">Hemant Arora\u003C\u002Fa>\u003C\u002Fp>\n\u003C\u002Fblockquote>\n\u003Cp>\u003Ca href=\"https:\u002F\u002Fwpfactory.com\u002Fitem\u002Fdownload-plugins-and-themes-from-dashboard-wordpress-plugin\u002F?utm_source=wporg&utm_medium=organic&utm_campaign=readme\" title=\"Main Page\" rel=\"nofollow ugc\">Main Page\u003C\u002Fa> | \u003Ca href=\"https:\u002F\u002Fwpfactory.com\u002Fsupport\u002Fitem\u002Fdownload-plugins-and-themes-from-dashboard-wordpress-plugin\u002F?utm_source=wporg&utm_medium=organic&utm_campaign=readme\" title=\"Support Forum\" rel=\"nofollow ugc\">Support Forum\u003C\u002Fa> | \u003Ca href=\"https:\u002F\u002Fwpfactory.com\u002Fdocs\u002Fdownload-plugins-and-themes\u002F?utm_source=wporg&utm_medium=organic&utm_campaign=readme\" title=\"Documentation & How to\" rel=\"nofollow ugc\">Documentation & How to\u003C\u002Fa>\u003C\u002Fp>\n\u003Cp>Have you ever found yourself in a need to download a plugin or theme file directly from your WordPress admin dashboard, only to discover you lack FTP or cPanel access?\u003C\u002Fp>\n\u003Cp>This is basically why we created this plugin, to simplify the process for you, so that with just a single click (literally), you can effortlessly download any plugin or theme right from your dashboard, no technical hurdles or external tools required.\u003C\u002Fp>\n\u003Cp>But that’s not all. Imagine you’ve customized a plugin to suit your site’s unique needs, only to realize you want to use those modifications elsewhere. With our plugin, you can easily download those customized files, ensuring your hard work is preserved and easily transferable.\u003C\u002Fp>\n\u003Cp>Say goodbye to complex file management and hello to seamless plugin and theme downloads, all from within your WordPress admin interface.\u003C\u002Fp>\n\u003Cp>Let’s take a look at some of the plugin features.\u003C\u002Fp>\n\u003Ch3>🚀 Main Features: FREE Version\u003C\u002Fh3>\n\u003Ch3>🚀 Download Plugins from WordPress Dashboard\u003C\u002Fh3>\n\u003Cp>The plugin adds a “Download” button in Plugins page next to each plugin, so what with a single click, you can download any plugin from your WordPress admin dashboard, download the plugin files in ZIP format without the need to get a file manager plugin or FTP access.\u003C\u002Fp>\n\u003Ch3>🚀 Download Themes from WordPress Dashboard\u003C\u002Fh3>\n\u003Cp>Similar to plugins, you will have a “Download” button on Appearance > Themes page, where you can easily download any theme (or child theme) files from your website, so you can have a safe copy, or use it locally or elsewhere.\u003C\u002Fp>\n\u003Ch3>🚀 Download All Plugins & Themes in a Click\u003C\u002Fh3>\n\u003Cp>Do you have a lot of plugins or themes that you want to download quickly? The plugin allows you to get all installed plugins and themes with one click in a single combined file.\u003C\u002Fp>\n\u003Ch3>🚀 Add Main Plugin\u002FTheme Directory to ZIP File\u003C\u002Fh3>\n\u003Cp>You can select to include the plugin\u002Ftheme main directory to your file, or have it directly saved from the inner folders level.\u003C\u002Fp>\n\u003Ch3>🚀 Append Plugin\u002FTheme Version Number to ZIP Filename\u003C\u002Fh3>\n\u003Cp>The plugin options allow you to append the version number of your plugins or themes to their ZIP filenames, very useful for better organization and version tracking of files.\u003C\u002Fp>\n\u003Ch3>🚀 Advanced ZIP Libraries Selection\u003C\u002Fh3>\n\u003Cp>Choose between ZipArchive or PclZip libraries for handling ZIP files based on your server & tools needs\u002Fcompatibility.\u003C\u002Fp>\n\u003Ch3>❤️ User Testimonials: See What Others Are Saying!\u003C\u002Fh3>\n\u003Cblockquote>\n\u003Cp>“Very useful !!: This plugin simplifies the WordPress experience by allowing users to effortlessly download plugins and themes directly from the dashboard, making it an excellent alternative for those without CPanel \u002F FTP access.” – ⭐⭐⭐⭐⭐ \u003Ca href=\"https:\u002F\u002Fwordpress.org\u002Fsupport\u002Ftopic\u002Fvery-useful-3392\u002F?utm_source=wporg&utm_medium=organic&utm_campaign=readme\" rel=\"ugc\">storemizer\u003C\u002Fa>\u003C\u002Fp>\n\u003Cp>“Amazing Plugin!: Straightforward with a very simple interface, and gets the job done (even faster than ftp downloading).” – ⭐⭐⭐⭐⭐  \u003Ca href=\"https:\u002F\u002Fwordpress.org\u002Fsupport\u002Ftopic\u002Famazing-plugin-2371\u002F?utm_source=wporg&utm_medium=organic&utm_campaign=readme\" rel=\"ugc\">florijan\u003C\u002Fa>\u003C\u002Fp>\n\u003C\u002Fblockquote>\n\u003Ch3>🏆 Do More: PRO Version\u003C\u002Fh3>\n\u003Cp>If you want to go further, you can get the premium version of \u003Ca href=\"https:\u002F\u002Fwpfactory.com\u002Fitem\u002Fdownload-plugins-and-themes-from-dashboard-wordpress-plugin\u002F\u002F?utm_source=wporg&utm_medium=organic&utm_campaign=readme\" rel=\"nofollow ugc\">Download Plugins and Themes in ZIP from Dashboard\u003C\u002Fa> plugin.\u003C\u002Fp>\n\u003Ch3>🏆 Set Periodical Plugins and\u002For Themes Downloads\u003C\u002Fh3>\n\u003Cp>Set up automated periodic downloads of plugins or themes, to make sure  you always have the latest versions for testing or backup purposes, at intervals ranging from once a minute to every 4 weeks.\u003C\u002Fp>\n\u003Cp>This feature is especially useful for developers or site administrators who regularly update their WordPress installations and want to keep local copies of plugins and themes synchronized.\u003C\u002Fp>\n\u003Ch3>🏆 Append Date & Time to Plugin\u002FTheme ZIP Filename\u003C\u002Fh3>\n\u003Cp>With the scheduled download for plugins\u002Fthemes, you can include the date & time to plugins\u002Fthemes names so you have a well-organized folders by date.\u003C\u002Fp>\n\u003Ch3>🏆 Customize Name & Path for Periodical Plugins Downloads\u003C\u002Fh3>\n\u003Cp>Customize the naming convention and storage location for plugins & themes downloaded periodically, ensuring organized file management and easy access to archived versions.\u003C\u002Fp>\n\u003Ch3>🏆 Customize the Download plugin link\u003C\u002Fh3>\n\u003Cp>Customize the download plugin link on the plugins page with options such as: color, font-weight, and custom text.\u003C\u002Fp>\n\u003Ch3>💯 Why WPFactory?\u003C\u002Fh3>\n\u003Cul>\n\u003Cli>\u003Cstrong>Experience You Can Trust:\u003C\u002Fstrong> Over a decade in the business\u003C\u002Fli>\n\u003Cli>\u003Cstrong>Wide Plugin Selection:\u003C\u002Fstrong> Offering 65+ unique and powerful plugins\u003C\u002Fli>\n\u003Cli>\u003Cstrong>Highly-Rated Support:\u003C\u002Fstrong> Backed by hundreds of 5-star reviews\u003C\u002Fli>\n\u003Cli>\u003Cstrong>Expert Team:\u003C\u002Fstrong> Dedicated developers and technical support at your service\u003C\u002Fli>\n\u003C\u002Ful>\n\u003Ch3>What’s Next? Discover More Plugins by WPFactory\u003C\u002Fh3>\n\u003Cp>WPFactory has a diverse range of plugins tailored to enhance your experience:\u003C\u002Fp>\n\u003Cul>\n\u003Cli>\n\u003Cp>\u003Ca href=\"https:\u002F\u002Fwpfactory.com\u002Fitem\u002Ffile-renaming-on-upload-wordpress-plugin\u002F\" title=\"**Rename Media Files: Improve Your WordPress SEO**\" rel=\"nofollow ugc\">\u003Cstrong>Rename Media Files: Improve Your WordPress SEO\u003C\u002Fstrong>\u003C\u002Fa>: Enhance SEO and organize media effortlessly with Rename Media Files WordPress Plugin. Fix upload issues, santize & optimize filenames, and improve SEO seamlessly. (\u003Cstrong>\u003Ca href=\"https:\u002F\u002Fwordpress.org\u002Fplugins\u002Ffile-renaming-on-upload\u002F\" title=\"Free version\" rel=\"ugc\">Free version\u003C\u002Fa>\u003C\u002Fstrong>)\u003C\u002Fp>\n\u003C\u002Fli>\n\u003Cli>\n\u003Cp>\u003Ca href=\"https:\u002F\u002Fwpfactory.com\u002Fitem\u002Fslugs-manager-wordpress-plugin\u002F?utm_source=wporg&utm_medium=organic&utm_campaign=readme\" title=\"**Slugs Manager: Delete Old Permalinks from WordPress Database**\" rel=\"nofollow ugc\">\u003Cstrong>Slugs Manager: Delete Old Permalinks from WordPress Database\u003C\u002Fstrong>\u003C\u002Fa>: Scan & remove old or outdated slugs (permalinks) in WordPress, keep your database optimized & your URLs SEO-friendly (\u003Cstrong>\u003Ca href=\"https:\u002F\u002Fwordpress.org\u002Fplugins\u002Fremove-old-slugspermalinks\u002F\" title=\"Free version\" rel=\"ugc\">Free version\u003C\u002Fa>\u003C\u002Fstrong>)\u003C\u002Fp>\n\u003C\u002Fli>\n\u003Cli>\n\u003Cp>\u003Ca href=\"https:\u002F\u002Fwpfactory.com\u002Fitem\u002Fback-button-widget-wordpress-plugin\u002F?utm_source=wporg&utm_medium=organic&utm_campaign=readme\" title=\"** Back Button Widget**\" rel=\"nofollow ugc\">\u003Cstrong>Back Button Widget\u003C\u002Fstrong>\u003C\u002Fa>: A simple & customizable back button, add it to any WordPress page using shortcode or widget for enhanced user navigation experience and site accessibility. (\u003Cstrong>\u003Ca href=\"https:\u002F\u002Fwordpress.org\u002Fplugins\u002Fback-button-widget\u002F\" title=\"Free version\" rel=\"ugc\">Free version\u003C\u002Fa>\u003C\u002Fstrong>)\u003C\u002Fp>\n\u003C\u002Fli>\n\u003Cli>\n\u003Cp>\u003Ca href=\"https:\u002F\u002Fwpfactory.com\u002Fitem\u002Fprice-offers-for-woocommerce\u002F?utm_source=wporg&utm_medium=organic&utm_campaign=readme\" title=\"*Name Your Price: Make a Price Offer for WooCommerce**\" rel=\"nofollow ugc\">\u003Cstrong>Name Your Price: Make a Price Offer for WooCommerce\u003C\u002Fstrong>\u003C\u002Fa>: Allow customers to propose their own prices for your products, open a negotiation-driven shopping experience with options to accept, reject, or counter-offer. (\u003Cstrong>\u003Ca href=\"https:\u002F\u002Fwordpress.org\u002Fplugins\u002Fprice-offerings-for-woocommerce\u002F\" title=\"Free version\" rel=\"ugc\">Free version\u003C\u002Fa>\u003C\u002Fstrong>)\u003C\u002Fp>\n\u003C\u002Fli>\n\u003Cli>\n\u003Cp>\u003Ca href=\"https:\u002F\u002Fwpfactory.com\u002Fitem\u002Fcustom-emails-for-woocommerce\u002F?utm_source=wporg&utm_medium=organic&utm_campaign=readme\" title=\"**Additional Custom Emails for WooCommerce**\" rel=\"nofollow ugc\">\u003Cstrong>Additional Custom Emails for WooCommerce\u003C\u002Fstrong>\u003C\u002Fa>: Define & customize more emails based on triggers, choose from multiple recipient options, personalize content, and send emails manually. (\u003Cstrong>\u003Ca href=\"https:\u002F\u002Fwordpress.org\u002Fplugins\u002Fcustom-emails-for-woocommerce\u002F\" title=\"Free version\" rel=\"ugc\">Free version\u003C\u002Fa>\u003C\u002Fstrong>)\u003C\u002Fp>\n\u003C\u002Fli>\n\u003Cli>\n\u003Cp>\u003Ca href=\"https:\u002F\u002Fwpfactory.com\u002Fitem\u002Forder-status-rules-for-woocommerce\u002F?utm_source=wporg&utm_medium=organic&utm_campaign=readme\" title=\"**Automated Order Status Controller for WooCommerce**\" rel=\"nofollow ugc\">\u003Cstrong>Automated Order Status Controller for WooCommerce\u003C\u002Fstrong>\u003C\u002Fa>: Change order statuses programmatically based on a wide range of conditions, like time intervals, user roles and more! (\u003Cstrong>\u003Ca href=\"https:\u002F\u002Fwordpress.org\u002Fplugins\u002Forder-status-rules-for-woocommerce\u002F\" title=\"Free version\" rel=\"ugc\">Free version\u003C\u002Fa>\u003C\u002Fstrong>)\u003C\u002Fp>\n\u003C\u002Fli>\n\u003C\u002Ful>\n\u003Cblockquote>\n\u003Cp>“Right on – job done fast and efficiently!:This plugin is just awesome. It does the job as stated in the tin! Kudos to the devs.” – ⭐⭐⭐⭐⭐ \u003Ca href=\"https:\u002F\u002Fwordpress.org\u002Fsupport\u002Ftopic\u002Fright-on-job-done-fast-and-efficiently-5\u002F?utm_source=wporg&utm_medium=organic&utm_campaign=readme\" rel=\"ugc\">danielepais\u003C\u002Fa>\u003C\u002Fp>\n\u003Cp>“Brilliant!!!:I had deleted a plugin that I bought and their website doesn’t allow you to log in and download. But I did remember a website that had the plugin. Installed this plugin and downloaded the plugin I was needing in an instant. Well done!” – ⭐⭐⭐⭐⭐ \u003Ca href=\"https:\u002F\u002Fwordpress.org\u002Fsupport\u002Ftopic\u002Fbrilliant-1311\u002F?utm_source=wporg&utm_medium=organic&utm_campaign=readme\" rel=\"ugc\">brand9\u003C\u002Fa>\u003C\u002Fp>\n\u003Cp>“Life saver:Thank you for this fantastic plugin, it is a life saver for those who don’t have FTP capabilities.” – ⭐⭐⭐⭐⭐ \u003Ca href=\"https:\u002F\u002Fwordpress.org\u002Fsupport\u002Ftopic\u002Flife-saver-316\u002F?utm_source=wporg&utm_medium=organic&utm_campaign=readme\" rel=\"ugc\">Gabriel Reguly\u003C\u002Fa>\u003C\u002Fp>\n\u003Cp>“Greatly Usable!:Being a WordPress developer I often need to download the themes and plugins from the sites. When I do not have any other details except the site URL and login, then comes the role of this well functional and greatly usable plugin.” – ⭐⭐⭐⭐⭐ \u003Ca href=\"https:\u002F\u002Fwordpress.org\u002Fsupport\u002Ftopic\u002Fgreatly-usable\u002F?utm_source=wporg&utm_medium=organic&utm_campaign=readme\" rel=\"ugc\">Ritu Singh\u003C\u002Fa>\u003C\u002Fp>\n\u003C\u002Fblockquote>\n","Download installed plugins and themes in ZIP files directly from your WordPress admin dashboard, download any or all plugins & themes without FTP  &hellip;",30000,837810,96,28,"2025-12-22T16:55:00.000Z","6.9.4","3.1","5.0.0",[20,21,22,23],"download","download-plugin","download-theme","theme","https:\u002F\u002Fwpfactory.com\u002Fitem\u002Fdownload-plugins-and-themes-from-dashboard\u002F","https:\u002F\u002Fdownloads.wordpress.org\u002Fplugin\u002Fdownload-plugins-dashboard.1.9.9.zip",95,5,0,"2025-12-16 19:02:52","2026-03-15T15:16:48.613Z",[32,48,62,75,90],{"id":33,"url_slug":34,"title":35,"description":36,"plugin_slug":4,"theme_slug":37,"affected_versions":38,"patched_in_version":39,"severity":40,"cvss_score":41,"cvss_vector":42,"vuln_type":43,"published_date":29,"updated_date":44,"references":45,"days_to_patch":47},"CVE-2025-14399","download-plugins-and-themes-from-dashboard-cross-site-request-forgery-to-bulk-plugintheme-archival","Download Plugins and Themes from Dashboard \u003C= 1.9.6 - Cross-Site Request Forgery to Bulk Plugin\u002FTheme Archival","The Download Plugins and Themes in ZIP from Dashboard plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 1.9.6. This is due to missing or incorrect nonce validation on the download_plugin_bulk and download_theme_bulk functions. This makes it possible for unauthenticated attackers to archive all the sites plugins and themes and place them in the `wp-content\u002Fuploads\u002F` directory via a forged request granted they can trick a site administrator into performing an action such as clicking on a link.",null,"\u003C=1.9.6","1.9.7","medium",4.3,"CVSS:3.1\u002FAV:N\u002FAC:L\u002FPR:N\u002FUI:R\u002FS:U\u002FC:N\u002FI:L\u002FA:N","Cross-Site Request Forgery (CSRF)","2025-12-17 07:21:05",[46],"https:\u002F\u002Fwww.wordfence.com\u002Fthreat-intel\u002Fvulnerabilities\u002Fid\u002F845b6bcf-004b-4b92-88d7-3d331fa58c11?source=api-prod",1,{"id":49,"url_slug":50,"title":51,"description":52,"plugin_slug":4,"theme_slug":37,"affected_versions":53,"patched_in_version":54,"severity":40,"cvss_score":55,"cvss_vector":56,"vuln_type":57,"published_date":58,"updated_date":59,"references":60,"days_to_patch":47},"CVE-2024-9232","download-plugins-and-themes-in-zip-from-dashboard-reflected-cross-site-scripting","Download Plugins and Themes in ZIP from Dashboard \u003C= 1.9.1 - Reflected Cross-Site Scripting","The Download Plugins and Themes in ZIP from Dashboard plugin for WordPress is vulnerable to Reflected Cross-Site Scripting due to the use of add_query_arg without appropriate escaping on the URL in all versions up to, and including, 1.9.1. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages that execute if they can successfully trick a user into performing an action such as clicking on a link.","\u003C=1.9.1","1.9.2",6.1,"CVSS:3.1\u002FAV:N\u002FAC:L\u002FPR:N\u002FUI:R\u002FS:C\u002FC:L\u002FI:L\u002FA:N","Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')","2024-10-10 00:00:00","2024-10-11 06:50:21",[61],"https:\u002F\u002Fwww.wordfence.com\u002Fthreat-intel\u002Fvulnerabilities\u002Fid\u002Fc3ea04ba-b609-49cd-aae8-68f5b51df154?source=api-prod",{"id":63,"url_slug":64,"title":65,"description":66,"plugin_slug":4,"theme_slug":37,"affected_versions":67,"patched_in_version":68,"severity":40,"cvss_score":69,"cvss_vector":70,"vuln_type":43,"published_date":71,"updated_date":72,"references":73,"days_to_patch":47},"CVE-2024-7501","download-plugins-and-themes-from-dashboard-cross-site-request-forgery","Download Plugins and Themes from Dashboard \u003C= 1.8.7 - Cross-Site Request Forgery","The Download Plugins and Themes in ZIP from Dashboard plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 1.8.7. This is due to missing or incorrect nonce validation on the download_theme() function. This makes it possible for unauthenticated attackers to download arbitrary themes from the website via a forged request granted they can trick a site administrator into performing an action such as clicking on a link. In versions prior to 1.8.6 it was possible to download the entire sites files.","\u003C=1.8.7","1.8.8",4.2,"CVSS:3.1\u002FAV:N\u002FAC:H\u002FPR:N\u002FUI:R\u002FS:U\u002FC:L\u002FI:L\u002FA:N","2024-08-15 00:00:00","2024-08-16 06:41:00",[74],"https:\u002F\u002Fwww.wordfence.com\u002Fthreat-intel\u002Fvulnerabilities\u002Fid\u002Fdcbfcaeb-2635-4b11-b426-ee04345d5f36?source=api-prod",{"id":76,"url_slug":77,"title":78,"description":79,"plugin_slug":4,"theme_slug":37,"affected_versions":80,"patched_in_version":81,"severity":40,"cvss_score":82,"cvss_vector":83,"vuln_type":84,"published_date":85,"updated_date":86,"references":87,"days_to_patch":89},"CVE-2024-35162","download-plugins-and-themes-from-dashboard-authenticated-admin-arbitrary-file-download","Download Plugins and Themes from Dashboard \u003C= 1.8.5 - Authenticated (Admin+) Arbitrary File Download","The Download Plugins and Themes in ZIP from Dashboard plugin for WordPress is vulnerable to Directory Traversal in all versions up to, and including, 1.8.5 via the download_theme function. This makes it possible for unauthenticated attackers to read the contents of arbitrary files on the server, which can contain sensitive information.","\u003C=1.8.5","1.8.6",4.9,"CVSS:3.1\u002FAV:N\u002FAC:L\u002FPR:H\u002FUI:N\u002FS:U\u002FC:H\u002FI:N\u002FA:N","Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')","2024-05-17 00:00:00","2024-06-06 13:44:04",[88],"https:\u002F\u002Fwww.wordfence.com\u002Fthreat-intel\u002Fvulnerabilities\u002Fid\u002F9adfc632-2e47-4fea-ad87-41840cdab225?source=api-prod",21,{"id":91,"url_slug":92,"title":93,"description":94,"plugin_slug":4,"theme_slug":37,"affected_versions":95,"patched_in_version":96,"severity":40,"cvss_score":55,"cvss_vector":56,"vuln_type":57,"published_date":97,"updated_date":98,"references":99,"days_to_patch":101},"CVE-2019-17239","download-plugins-and-themes-from-dashboard-unauthenticated-stored-cross-site-scripting","Download Plugins and Themes from Dashboard \u003C= 1.5.0 - Unauthenticated Stored Cross-Site Scripting","includes\u002Fsettings\u002Fclass-alg-download-plugins-settings.php in the download-plugins-dashboard plugin through 1.5.0 for WordPress has multiple unauthenticated stored XSS issues.","\u003C1.6.0","1.6.0","2019-10-02 00:00:00","2024-01-22 19:56:02",[100],"https:\u002F\u002Fwww.wordfence.com\u002Fthreat-intel\u002Fvulnerabilities\u002Fid\u002Fab8a13d5-911a-4c25-8d5a-391146971c0c?source=api-prod",1574,{"slug":103,"display_name":7,"profile_url":8,"plugin_count":104,"total_installs":105,"avg_security_score":106,"avg_patch_time_days":107,"trust_score":108,"computed_at":109},"wpcodefactory",63,135890,97,98,77,"2026-04-04T12:13:02.066Z",[111,132,152,172,194],{"slug":112,"name":113,"version":114,"author":115,"author_profile":116,"description":117,"short_description":118,"active_installs":119,"downloaded":120,"rating":28,"num_ratings":28,"last_updated":121,"tested_up_to":122,"requires_at_least":123,"requires_php":124,"tags":125,"homepage":129,"download_link":130,"security_score":131,"vuln_count":28,"unpatched_count":28,"last_vuln_date":37,"fetched_at":30},"quick-download","Quick Download – Themes and Plugins from WP Dashboard","1.0.1","Sajib Talukder","https:\u002F\u002Fprofiles.wordpress.org\u002Fstalukder03\u002F","\u003Cp>\u003Cstrong>Quick Download\u003C\u002Fstrong> plugin lets you download installed plugins and themes ZIP files directly from your admin dashboard.\u003C\u002Fp>\n\u003Cp>After installation \u003Cstrong>Download ZIP\u003C\u002Fstrong> button will be automatically added to all plugins and themes.\u003C\u002Fp>\n\u003Ch3>Features\u003C\u002Fh3>\n\u003Cul>\n\u003Cli>Easy to install\u003C\u002Fli>\n\u003Cli>No required settings in the admin\u003C\u002Fli>\n\u003C\u002Ful>\n","Download Themes and Pluigns directly from WordPress Dashboard.",50,1661,"2024-09-16T06:59:00.000Z","6.6.5","","5.6",[20,126,127,23,128],"download-plugin-from-dashboard","download-theme-from-dashboard","zip","http:\u002F\u002Fsajib.me\u002Fplugins\u002Fquick-download","https:\u002F\u002Fdownloads.wordpress.org\u002Fplugin\u002Fquick-download.1.0.1.zip",92,{"slug":133,"name":134,"version":135,"author":136,"author_profile":137,"description":138,"short_description":139,"active_installs":140,"downloaded":141,"rating":142,"num_ratings":143,"last_updated":123,"tested_up_to":144,"requires_at_least":145,"requires_php":123,"tags":146,"homepage":123,"download_link":149,"security_score":150,"vuln_count":28,"unpatched_count":28,"last_vuln_date":37,"fetched_at":151},"woocommerce-downlaod-product-from-admin","Download Theme | Plugin | WC products zip from dashboard","0.7","Omid Shamloo","https:\u002F\u002Fprofiles.wordpress.org\u002Fgoback2\u002F","\u003Ch3>download themes | plugins and products from dashboard as Zip file\u003C\u002Fh3>\n\u003Cp>sometime you need to get your plugins or downloadable products , and you don’t have host panel access in that time,now there is no need to going to hosting panel and get missed files , with this plugin you can download WooCommerce downloadable products from WordPress dashboard , just click on Dll button next to products lists\u003C\u002Fp>\n","download themes | plugins and products from dashboard as Zip file",40,3090,60,2,"6.5.8","3.0",[21,22,147,148],"plugin-download","theme-download","https:\u002F\u002Fdownloads.wordpress.org\u002Fplugin\u002Fwoocommerce-downlaod-product-from-admin.zip",100,"2026-03-15T10:48:56.248Z",{"slug":22,"name":153,"version":154,"author":155,"author_profile":156,"description":157,"short_description":158,"active_installs":159,"downloaded":160,"rating":161,"num_ratings":162,"last_updated":163,"tested_up_to":164,"requires_at_least":145,"requires_php":123,"tags":165,"homepage":169,"download_link":170,"security_score":150,"vuln_count":47,"unpatched_count":28,"last_vuln_date":171,"fetched_at":30},"Download Theme","1.1.2","Metagauss","https:\u002F\u002Fprofiles.wordpress.org\u002Fmetagauss\u002F","\u003Cp>Download Theme allows you to download any theme directly from your WordPress dashboard. It adds the download link right on the theme listing page, on each theme, as shown in the screenshot.\u003C\u002Fp>\n\u003Col>\n\u003Cli>Just activate this plugin.\u003C\u002Fli>\n\u003Cli>You can see Download link on each theme box on Appearance page.\u003C\u002Fli>\n\u003Cli>Click on any of them and that theme’s zip will be downloaded to your computer.\u003C\u002Fli>\n\u003Cli>Cheers!\u003C\u002Fli>\n\u003C\u002Fol>\n\u003Ch4>Download Theme Services\u003C\u002Fh4>\n\u003Cp>Download Theme now offers Theme Services. If you need expert help setting up your WordPress theme, simply go to your WordPress dashboard, navigate to the Help button in the top right corner, and click on Get Help Now.\u003C\u002Fp>\n\u003Ch4>Download Plugin\u003C\u002Fh4>\n\u003Cp>If you want to download any plugin from your WordPress admin panel’s Plugins page, then use our other plugin – \u003Ca href=\"https:\u002F\u002Fwordpress.org\u002Fplugins\u002Fdownload-plugin\" rel=\"ugc\">Download Plugin\u003C\u002Fa>\u003C\u002Fp>\n","Download any theme from your WordPress admin panel's Appearance page by just one click!",4000,127909,80,7,"2025-04-23T11:55:00.000Z","6.8.5",[22,166,23,167,168],"download-theme-zip","theme-zip","themes","http:\u002F\u002Fmetagauss.com","https:\u002F\u002Fdownloads.wordpress.org\u002Fplugin\u002Fdownload-theme.1.1.2.zip","2023-05-24 00:00:00",{"slug":173,"name":174,"version":175,"author":176,"author_profile":177,"description":178,"short_description":179,"active_installs":180,"downloaded":181,"rating":107,"num_ratings":182,"last_updated":183,"tested_up_to":16,"requires_at_least":145,"requires_php":123,"tags":184,"homepage":189,"download_link":190,"security_score":191,"vuln_count":192,"unpatched_count":28,"last_vuln_date":193,"fetched_at":30},"filester","File Manager Pro – Filester","2.0.2","Ninja Team","https:\u002F\u002Fprofiles.wordpress.org\u002Fninjateam\u002F","\u003Cp>Filester is a WP File Manager Pro plugin, but you can download and use it completely for free. It comes with all the \u003Cstrong>premium features\u003C\u002Fstrong> of other WordPress advanced file manager plugins out there.\u003C\u002Fp>\n\u003Cp>Filester helps you manage \u003Cstrong>WordPress configuration files\u003C\u002Fstrong>, while \u003Ca href=\"https:\u002F\u002F1.envato.market\u002FFileBird-Folders-Plugin\" rel=\"nofollow ugc\">FileBird\u003C\u002Fa> allows you to manage\u002Fupload\u002Fdownload \u003Cstrong>media library folders\u003C\u002Fstrong>.\u003C\u002Fp>\n\u003Cp>With Filester – File Manager Pro, you can copy, paste, create an archive, download, upload, edit, delete, preview, duplicate, and get info of the WordPress configuration and directory files \u003Cstrong>without FTP access\u003C\u002Fstrong>.\u003C\u002Fp>\n\u003Cp>This file manager plugin is dedicated to boosting your productivity in managing WordPress. All necessary file operations are fully provided and tested on a variety of servers and browsers.\u003C\u002Fp>\n\u003Cp>Another thing you will appreciate about it is the clean and compact UI\u002FUX, which makes editing and transferring directory files and folders extra fast.\u003C\u002Fp>\n\u003Cp>\u003Cstrong>Did you know?\u003C\u002Fstrong>\u003Cbr \u002F>\nMore than \u003Ca href=\"https:\u002F\u002Fwww.wordfence.com\u002Fblog\u002F2020\u002F09\u002Fmillions-of-sites-targeted-in-file-manager-vulnerability-attacks\u002F\" rel=\"nofollow ugc\">700,000 WordPress websites\u003C\u002Fa> were attacked during September 2020.\u003Cbr \u002F>\nMalicious bots are looking to exploit vulnerable versions of WP file manager plugins.\u003Cbr \u002F>\nFortunately, Filester comes with this vulnerability \u003Cstrong>fixed\u003C\u002Fstrong>!\u003Cbr \u002F>\nFilester poses no risk to you, so rest assured! 🤗\u003C\u002Fp>\n\u003Ch3>⚡️ FEATURES\u003C\u002Fh3>\n\u003Cul>\n\u003Cli>\u003Cstrong>Drag & drop interface:\u003C\u002Fstrong> Easily move and arrange files\u003C\u002Fli>\n\u003Cli>\u003Cstrong>Smart context menu:\u003C\u002Fstrong> Right-click on any files to make operations\u003C\u002Fli>\n\u003Cli>\u003Cstrong>Manage files and folders:\u003C\u002Fstrong> Copy, move, upload, create folder\u002Ffile, rename, duplicate, etc.\u003C\u002Fli>\n\u003Cli>\u003Cstrong>Built-in advanced code editor:\u003C\u002Fstrong> Integrated development environment ACE Editor, CodeMirror, CKEditor, TinyMCE, and others\u003C\u002Fli>\n\u003Cli>\u003Cstrong>Flexible configuration:\u003C\u002Fstrong> Access rights, uploadable file types\u002Fextensions, maximum file size limit, and more\u003C\u002Fli>\n\u003Cli>\u003Cstrong>Create\u002Fextract archives:\u003C\u002Fstrong> .zip, .rar, .xz, .tar, .gzip\u003C\u002Fli>\n\u003Cli>\u003Cstrong>Great UI\u002FUX design:\u003C\u002Fstrong> Clean, high-quality & productivity-driven \u003C\u002Fli>\n\u003Cli>\u003Cstrong>User authority settings:\u003C\u002Fstrong> File extensions to be locked, file visibility, root path access, .htaccess file \u003C\u002Fli>\n\u003Cli>\u003Cstrong>Edit media files:\u003C\u002Fstrong> Using Photopea & TUI Image Editor\u003C\u002Fli>\n\u003Cli>\u003Cstrong>Multiple languages supported:\u003C\u002Fstrong> English, German, Spanish, Italian, French, Japanese, etc.\u003C\u002Fli>\n\u003Cli>\u003Cstrong>RTL supported:\u003C\u002Fstrong> Hebrew, Arabic, Persian, Kurdish, etc.\u003C\u002Fli>\n\u003C\u002Ful>\n\u003Ch3>🙌 OTHER FEATURES\u003C\u002Fh3>\n\u003Cul>\n\u003Cli>Local file system\u003C\u002Fli>\n\u003Cli>Simple client-server API based on JSON\u003C\u002Fli>\n\u003Cli>List and icon view\u003C\u002Fli>\n\u003Cli>Multi-root support\u003C\u002Fli>\n\u003Cli>Hidden files\u002Ffolders options\u003C\u002Fli>\n\u003Cli>Set hidden files for other users\u003C\u002Fli>\n\u003Cli>Root path for each user role\u003C\u002Fli>\n\u003Cli>Easy to navigate\u003C\u002Fli>\n\u003Cli>6 themes for your preferred interface\u003C\u002Fli>\n\u003C\u002Ful>\n\u003Ch3>🔑 HOW IT WORKS\u003C\u002Fh3>\n\u003Cp>Filester plugin helps you easily manage WordPress files so that you don’t have to access directories via FTP or cPanel.\u003C\u002Fp>\n\u003Cp>This plugin creates a new menu \u003Cstrong>File Manager\u003C\u002Fstrong> in your WordPress dashboard. From then on, you can view all server files, configuration, and media files on your current WordPress website.\u003C\u002Fp>\n\u003Cp>You can edit, copy, upload\u002Fdownload files\u002Ffolders to your server from File Manager section. This toolbar is similar to the settings in an FTP client. It allows you to preview, edit, upload, download, duplicate and delete files or folders.\u003C\u002Fp>\n\u003Cp>With Filester, it’s easy to modify the auto-update mechanism with each new version of WordPress. You can quickly \u003Cstrong>search for specific text or code\u003C\u002Fstrong> within your WordPress files and replace it efficiently.\u003C\u002Fp>\n\u003Cp>With built-in code editors, you can edit code files with syntax highlighting and code completion features for themes, plugins, and custom code snippets. It takes one click to download a plugin’s \u003Cstrong>ZIP file\u003C\u002Fstrong> to your local storage. It helps track changes made to files and revert to previous versions if needed.\u003C\u002Fp>\n\u003Cp>All webmasters can also \u003Ca href=\"https:\u002F\u002Fninjateam.org\u002Fdownload-wordpress-media-library\u002F\" rel=\"nofollow ugc\">download WordPress media library\u003C\u002Fa> using Filester download options as well.\u003C\u002Fp>\n\u003Ch3>🎏 COMPATIBILITY\u003C\u002Fh3>\n\u003Cp>Filester works seamlessly with all major WordPress themes, page builders, and website builders.\u003C\u002Fp>\n\u003Cp>💙 \u003Cstrong>Like Filester?\u003C\u002Fstrong> \u003Ca href=\"https:\u002F\u002Fwordpress.org\u002Fsupport\u002Fplugin\u002Ffilester\u002Freviews\u002F?filter=5\" rel=\"ugc\">Share your experience\u003C\u002Fa> and empower other users to manage WordPress like a pro.\u003C\u002Fp>\n\u003Cp>👉 Check out NinjaTeam \u003Ca href=\"https:\u002F\u002Fninjateam.org\u002Fcategory\u002Ftutorials\u002F\" rel=\"nofollow ugc\">WordPress tutorials\u003C\u002Fa>.\u003C\u002Fp>\n\u003Ch4>CREDIT\u003C\u002Fh4>\n\u003Cp>Big thanks to elFinder – open-source file manager for web.\u003C\u002Fp>\n","Advanced File Manager and Code Editor. Best WordPress file manager without FTP access. No need to upgrade because this is PRO version.",100000,1341884,146,"2026-01-12T14:11:00.000Z",[21,185,186,187,188],"file-manager","files","wordpress-file-manager","wp-file-manager","https:\u002F\u002Fninjateam.org\u002Ffilester","https:\u002F\u002Fdownloads.wordpress.org\u002Fplugin\u002Ffilester.2.0.2.zip",91,9,"2025-06-19 00:00:00",{"slug":21,"name":195,"version":196,"author":155,"author_profile":156,"description":197,"short_description":198,"active_installs":199,"downloaded":200,"rating":201,"num_ratings":202,"last_updated":203,"tested_up_to":164,"requires_at_least":204,"requires_php":124,"tags":205,"homepage":169,"download_link":209,"security_score":210,"vuln_count":27,"unpatched_count":28,"last_vuln_date":211,"fetched_at":30},"Download Plugin","2.4.0","\u003Ch4>Download Plugin for WordPress\u003C\u002Fh4>\n\u003Cp>Download Plugin can easily download plugins, themes, users, blog posts, pages, comments, attachments, and more directly from your WordPress dashboard. Download Plugin can also download data from any plugin that uses custom post types, including WooCommerce products, Easy Digital Downloads, Portfolio Post Types, Slider Revolution, bbPress, WP Job Manager, JetPack, and many more.\u003C\u002Fp>\n\u003Cp>\u003Cstrong>Download Plugins\u003C\u002Fstrong>: A download button is placed beside each plugin, allowing you to download the plugin in a zip file format. You can also select multiple plugins and use the bulk download option to download all selected plugins with a single click.\u003C\u002Fp>\n\u003Cp>\u003Cstrong>Download Themes\u003C\u002Fstrong>: Similar to plugins, a download button is placed beside each theme in your WordPress dashboard. You can download themes in a zip file format.\u003C\u002Fp>\n\u003Cp>\u003Cstrong>Download Users\u003C\u002Fstrong>: With the Download Plugin, you can download individual user data or multiple users’ metadata in a CSV file format. This feature simplifies user data management, allowing easy download and save user information.\u003C\u002Fp>\n\u003Cp>\u003Cstrong>Download Blog Posts\u003C\u002Fstrong>: Export blog posts individually or in bulk with just a click. Download Plugin allows you to download blog posts in a CSV format for backup or migration purposes.\u003C\u002Fp>\n\u003Cp>\u003Cstrong>Download Pages\u003C\u002Fstrong>: Download single or multiple pages from your WordPress site. This feature is perfect for backing up your content or transferring pages between sites.\u003C\u002Fp>\n\u003Cp>\u003Cstrong>Download Custom Posts\u003C\u002Fstrong>: Download data from plugin that use custom post types. Download single custom post or a bulk download of multiple posts.\u003C\u002Fp>\n\u003Cp>\u003Cstrong>Download Comments\u003C\u002Fstrong>: Download comments either individually or in bulk. Save user feedback and engagement safely.\u003C\u002Fp>\n\u003Col>\n\u003Cli>Just activate this plugin.\u003C\u002Fli>\n\u003Cli>You can see Download link below each plugin name on plugins page.\u003C\u002Fli>\n\u003Cli>Click on any of them and that plugin’s zip will be downloaded to your computer.\u003C\u002Fli>\n\u003Cli>Cheers!\u003C\u002Fli>\n\u003C\u002Fol>\n\u003Cblockquote>\n\u003Cp>Must-have utility plugin that allows you to download any plugin directly from WordPress Dashboard!\u003C\u002Fp>\n\u003C\u002Fblockquote>\n\u003Cp>WordPress download plugin is a utility plugin that does one thing, and does it perfectly. It may sound simple, but this feature plugs a hole in current set of WordPress plugin functionality. As a site admin you must be aware that you can search and install WordPress plugins directly from the dashboard, or you can upload the plugin as zip files, assuming you received it from another site (for example, a commercial plugin). Once installed, all plugins list themselves inside Dashboard -> Plugins page. After deactivating and deleting them, they simply disappear. All files are removed from the server instantly. WordPress does not allow you to backup or download the plugins before you jettison them from your site. If you also manage your server and are fairly comfortable doing so, you may find a more contrived way to download installed plugins via directory manager app or FTP. Obviously, this requires more than a single click and not for everyone.\u003C\u002Fp>\n\u003Cp>What exactly are plugins and how this plugin helps you save time or bail you out from difficult situations? Plugins are files and\u002F or directories, which are created inside your WordPress installation (defined by WordPress) when you first install them. Both active and deactivated files reside inside them. When you upload zip package of a plugin, WordPress extracts it and places the directory inside it in the plugins folder. Our plugin allows you to reverse the process. It will convert any plugin installed on your site into a zip package ready to be reinstalled later or moved to another site. It accomplishes this by simply adding a new link “Download” under the plugin title to already existing links. It is a single click process and hardly takes any time. Our plugin does not create any other page in the dashboard or clutter menus. It is lightweight, efficient and completely invisible until you need it.\u003C\u002Fp>\n\u003Cp>So why would you need it? While there can be many reasons, here are the primary we think you will find it useful.\u003C\u002Fp>\n\u003Ch4>A. Backup\u003C\u002Fh4>\n\u003Cp>The foremost and most common reason – when you wish to make backup of the plugin for future installation.\u003C\u002Fp>\n\u003Ch4>B. Premium\u002F Commercial Plugins\u003C\u002Fh4>\n\u003Cp>If you have purchased the plugin from a vendor site, you may want to make a backup of your new purchase to make sure you have it handy if the vendor is no longer available or your account is expired. Please note: Do check terms of use for commercial plugins on publisher’s site.\u003C\u002Fp>\n\u003Ch4>C. Migrating to a different site\u003C\u002Fh4>\n\u003Cp>So you have found yourselves dependent on some specific plugins that you want to use on all of your sites? You can download these plugins from your current site do a folder on your hard disk from where you can upload to your other sites.\u003C\u002Fp>\n\u003Ch4>D. Preserving Changes\u003C\u002Fh4>\n\u003Cp>If you DIY type and made modifications to plugin files to suit your requirements, you will want to make sure you have an archived copy of the plugin if the files get overwritten by an update etc.\u003C\u002Fp>\n\u003Ch4>Starter Guide\u003C\u002Fh4>\n\u003Cp>\u003Ca href=\"https:\u002F\u002Fmetagauss.com\u002Fdownload-plugin-guide\u002F\" rel=\"nofollow ugc\">Checkout Download plugin guide\u003C\u002Fa> for more information.\u003C\u002Fp>\n\u003Ch4>Recommended Plugins (Free Download From WordPress.org)\u003C\u002Fh4>\n\u003Cp>\u003Ca href=\"https:\u002F\u002Fwordpress.org\u002Fplugins\u002Fdownload-theme\u002F\" rel=\"ugc\">Download Theme Plugin:\u003C\u002Fa> allows you to download any theme from your WordPress admin panel’s Appearance page.\u003C\u002Fp>\n\u003Cp>\u003Ca href=\"https:\u002F\u002Fwordpress.org\u002Fplugins\u002Fcustom-registration-form-builder-with-submission-manager\u002F\" rel=\"ugc\">User Registration and Login Plugin:\u003C\u002Fa> Take total control of end-to-end user registration process on your site with RegistrationMagic plugin.\u003C\u002Fp>\n\u003Cp>\u003Ca href=\"https:\u002F\u002Fwordpress.org\u002Fplugins\u002Fprofilegrid-user-profiles-groups-and-communities\u002F\" rel=\"ugc\">User Profiles and Membership Plugin:\u003C\u002Fa> Build awesome user profiles, restrict content and launch memberships with ProfileGrid plugin.\u003C\u002Fp>\n\u003Cp>\u003Ca href=\"https:\u002F\u002Fwordpress.org\u002Fplugins\u002Feventprime-event-calendar-management\u002F\" rel=\"ugc\">User Events and Calendar Plugin:\u003C\u002Fa> Manage user events, sell tickets and publish event calendar with EventPrime plugin.\u003C\u002Fp>\n","Download any plugin from your WordPress admin panel's Plugins page by just one click! Now, download themes, users, blog posts, pages, custom post &hellip;",50000,930336,88,22,"2026-03-06T07:06:00.000Z","4.8",[20,21,206,207,208],"download-plugin-zip","plugin-zip","plugins","https:\u002F\u002Fdownloads.wordpress.org\u002Fplugin\u002Fdownload-plugin.2.4.0.zip",94,"2025-07-03 13:38:05",{"attackSurface":213,"codeSignals":318,"taintFlows":342,"riskAssessment":382,"analyzedAt":392},{"hooks":214,"ajaxHandlers":310,"restRoutes":311,"shortcodes":312,"cronEvents":313,"entryPointCount":28,"unprotectedCount":28},[215,221,226,230,233,235,238,241,244,248,252,255,259,263,268,272,275,277,279,281,284,286,290,293,299,302,304,307],{"type":216,"name":217,"callback":218,"file":219,"line":220},"filter","plugin_action_links","add_plugin_download_action_links","includes\\class-alg-download-plugins-core.php",44,{"type":222,"name":223,"callback":224,"file":219,"line":225},"action","admin_enqueue_scripts","add_theme_download_links",45,{"type":222,"name":227,"callback":228,"file":219,"line":229},"admin_init","download_plugin",48,{"type":222,"name":227,"callback":231,"file":219,"line":232},"download_theme",49,{"type":222,"name":227,"callback":234,"file":219,"line":119},"download_plugin_bulk",{"type":222,"name":227,"callback":236,"file":219,"line":237},"download_theme_bulk",51,{"type":222,"name":227,"callback":239,"file":219,"line":240},"download_plugin_all",54,{"type":222,"name":227,"callback":242,"file":219,"line":243},"download_theme_all",55,{"type":216,"name":245,"callback":246,"file":219,"line":247},"cron_schedules","cron_add_custom_intervals",58,{"type":222,"name":249,"callback":250,"file":219,"line":251},"alg_download_plugins_cron","cron_alg_download_plugins",59,{"type":222,"name":253,"callback":254,"file":219,"line":142},"alg_download_themes_cron","cron_alg_download_themes",{"type":216,"name":256,"callback":257,"file":219,"line":258},"alg_download_plugins_version_separator_char","change_version_separator",67,{"type":216,"name":260,"callback":261,"file":219,"line":262},"bulk_actions-plugins","bulk_action",70,{"type":216,"name":264,"callback":265,"priority":266,"file":219,"line":267},"handle_bulk_actions-plugins","bulk_action_download_plugin",10,71,{"type":222,"name":269,"callback":270,"file":219,"line":271},"admin_notices","alg_download_plugin_bulk_action_notices",72,{"type":222,"name":269,"callback":273,"file":219,"line":274},"create_zip_error_message",198,{"type":222,"name":269,"callback":273,"file":219,"line":276},227,{"type":222,"name":269,"callback":273,"file":219,"line":278},358,{"type":222,"name":269,"callback":273,"file":219,"line":280},366,{"type":222,"name":269,"callback":282,"file":219,"line":283},"system_requirements_error_message",627,{"type":222,"name":269,"callback":273,"file":219,"line":285},701,{"type":222,"name":287,"callback":288,"file":289,"line":161},"init","add_cross_selling_library","includes\\class-alg-download-plugins.php",{"type":222,"name":287,"callback":291,"file":289,"line":292},"localize",83,{"type":222,"name":294,"callback":295,"priority":296,"file":297,"line":298},"admin_menu","add_plugin_menu",90,"includes\\settings\\class-alg-download-plugins-settings.php",34,{"type":222,"name":227,"callback":300,"file":297,"line":301},"save_settings",35,{"type":222,"name":269,"callback":269,"file":297,"line":303},36,{"type":222,"name":269,"callback":305,"file":297,"line":306},"admin_notice__error",113,{"type":222,"name":269,"callback":308,"file":297,"line":309},"admin_notice__success",139,[],[],[],[314,316],{"hook":253,"callback":253,"file":219,"line":315},251,{"hook":249,"callback":249,"file":219,"line":317},273,{"dangerousFunctions":319,"sqlUsage":320,"outputEscaping":322,"fileOperations":27,"externalRequests":28,"nonceChecks":27,"capabilityChecks":162,"bundledLibraries":341},[],{"prepared":28,"raw":28,"locations":321},[],{"escaped":323,"rawEcho":192,"locations":324},12,[325,328,330,332,334,335,336,337,339],{"file":219,"line":326,"context":327},647,"raw output",{"file":219,"line":329,"context":327},652,{"file":219,"line":331,"context":327},817,{"file":219,"line":333,"context":327},901,{"file":297,"line":232,"context":327},{"file":297,"line":243,"context":327},{"file":297,"line":201,"context":327},{"file":297,"line":338,"context":327},150,{"file":297,"line":340,"context":327},160,[],[343,361,374],{"entryPoint":344,"graph":345,"unsanitizedCount":28,"severity":360},"\u003Cclass-alg-download-plugins-core> (includes\\class-alg-download-plugins-core.php:0)",{"nodes":346,"edges":357},[347,352],{"id":348,"type":349,"label":350,"file":219,"line":351},"n0","source","$_GET (x2)",600,{"id":353,"type":354,"label":355,"file":219,"line":326,"wp_function":356},"n1","sink","echo() [XSS]","echo",[358],{"from":348,"to":353,"sanitized":359},true,"low",{"entryPoint":362,"graph":363,"unsanitizedCount":28,"severity":360},"save_settings (includes\\settings\\class-alg-download-plugins-settings.php:110)",{"nodes":364,"edges":372},[365,368],{"id":348,"type":349,"label":366,"file":297,"line":367},"$_POST",120,{"id":353,"type":354,"label":369,"file":297,"line":370,"wp_function":371},"update_option() [Settings Manipulation]",128,"update_option",[373],{"from":348,"to":353,"sanitized":359},{"entryPoint":375,"graph":376,"unsanitizedCount":28,"severity":360},"\u003Cclass-alg-download-plugins-settings> (includes\\settings\\class-alg-download-plugins-settings.php:0)",{"nodes":377,"edges":380},[378,379],{"id":348,"type":349,"label":366,"file":297,"line":367},{"id":353,"type":354,"label":369,"file":297,"line":370,"wp_function":371},[381],{"from":348,"to":353,"sanitized":359},{"summary":383,"deductions":384},"The 'download-plugins-dashboard' v1.9.9 plugin exhibits a mixed security posture.  On the positive side, the static analysis reveals no direct unprotected entry points like unauthenticated AJAX handlers, REST API routes, or shortcodes. The code also demonstrates good practices with 100% of SQL queries utilizing prepared statements and a reasonable number of capability checks.  However, a significant concern is the output escaping, with only 57% of outputs properly escaped, indicating a potential for Cross-Site Scripting (XSS) vulnerabilities if user-supplied data is not adequately sanitized before being displayed.\n\nTaint analysis found no critical or high severity issues, which is encouraging. The presence of 5 file operations and 5 nonce checks suggests some interaction with the file system and a moderate level of security implementation.  Despite the clean taint analysis for this specific version, the plugin's vulnerability history is a major red flag.  With 5 known CVEs, all medium severity, and recurring themes of CSRF, Path Traversal, and XSS, it indicates a pattern of past exploitable weaknesses. The fact that the last vulnerability was recorded in late 2025 suggests that while this specific version (v1.9.9) might not have immediate unpatched critical\u002Fhigh issues, the plugin itself has a track record of security flaws that require careful attention and ongoing monitoring.\n\nIn conclusion, while 'download-plugins-dashboard' v1.9.9 presents a seemingly clean bill of health in terms of immediate critical vulnerabilities based on the static and taint analysis for this version, its past vulnerability history cannot be ignored. The moderate output escaping is a potential weakness, and the plugin's track record suggests a higher than average risk of future undiscovered or reintroduced vulnerabilities. Users should proceed with caution and ensure robust security practices are in place.",[385,387,390],{"reason":386,"points":162},"Only 57% of outputs properly escaped",{"reason":388,"points":389},"History of 5 medium severity CVEs",15,{"reason":391,"points":266},"Common vulnerability types: CSRF, Path Traversal, XSS","2026-03-16T17:23:26.095Z",{"wat":394,"direct":404},{"assetPaths":395,"generatorPatterns":398,"scriptPaths":399,"versionParams":401},[396,397],"\u002Fwp-content\u002Fplugins\u002Fdownload-plugins-dashboard\u002Fincludes\u002Fjs\u002Ftheme_download_link.js","\u002Fwp-content\u002Fplugins\u002Fdownload-plugins-dashboard\u002Fincludes\u002Fjs\u002Ftheme_download_link.min.js",[],[400],"\u002Fwp-content\u002Fplugins\u002Fdownload-plugins-dashboard\u002Fvendor\u002Fautoload.php",[402,403],"download-plugins-dashboard\u002Fincludes\u002Fjs\u002Ftheme_download_link.js?ver=","download-plugins-dashboard\u002Fincludes\u002Fjs\u002Ftheme_download_link.min.js?ver=",{"cssClasses":405,"htmlComments":406,"htmlAttributes":407,"restEndpoints":408,"jsGlobals":409,"shortcodeOutput":412},[],[],[],[],[410,411],"alg_localize_object","alg_object",[]]