
dwnldr Security & Risk Analysis
wordpress.org/plugins/dwnldrSometimes there is no need for a huge, complex download manager, and let's face it there's rarely a need for an attachment page (who uses th …
Is dwnldr Safe to Use in 2026?
Generally Safe
Score 85/100dwnldr has a strong security track record. Known vulnerabilities have been patched promptly.
The 'dwnldr' plugin v1.031 exhibits a mixed security posture. On the positive side, the static analysis reveals no apparent direct attack surface through common WordPress entry points like AJAX, REST API, shortcodes, or cron events. Furthermore, all SQL queries utilize prepared statements, indicating good database interaction practices, and there are no external HTTP requests or bundled libraries, which can sometimes introduce vulnerabilities. However, a significant concern is the complete lack of output escaping for all identified output points (9 total). This leaves the plugin highly susceptible to Cross-Site Scripting (XSS) vulnerabilities, where malicious scripts could be injected into the website. The absence of nonce and capability checks also means that any potential vulnerabilities discovered in the future would be easier to exploit. The vulnerability history, though dated, shows a past XSS vulnerability, which aligns with the current finding of unescaped output and suggests a recurring weakness.
While the plugin currently has no unpatched CVEs and a relatively small number of total CVEs historically, the lack of output escaping is a critical flaw that significantly increases the risk of exploitation. The absence of any taint analysis results is not necessarily a strength but rather an indication that the static analysis tooling might not have detected complex data flow issues, or the plugin's code is too simple to trigger such findings. The main takeaway is the high risk associated with the unescaped output, which creates a clear pathway for XSS attacks, despite the absence of a large attack surface.
Key Concerns
- Unescaped output for all identified outputs
- No capability checks
- No nonce checks
dwnldr Security Vulnerabilities
CVEs by Year
Severity Breakdown
1 total CVE
dwnldr < 1.01 - Cross-Site Scripting
dwnldr Code Analysis
Output Escaping
dwnldr Attack Surface
WordPress Hooks 5
Maintenance & Trust
dwnldr Maintenance & Trust
Maintenance Signals
Community Trust
dwnldr Alternatives
Fluent Forms PDF Generator
fluentforms-pdf
Generate PDF from Your Form Submissions and Download/Email Them
Attachments
attachments
Attachments allows you to simply append any number of items from your WordPress Media Library to Posts, Pages, and Custom Post Types
Document Gallery
document-gallery
This plugin generates thumbnails for documents and displays them in a gallery-like format for easy sharing.
Send PDF for Contact Form 7
send-pdf-for-contact-form-7
Create, customize and send PDF attachments with Contact Form 7 form
PDF Ink Lite – PDF Watermark & Password Protection
waterwoo-pdf
The original WordPress PDF Watermark & password plugin (fka WaterWoo) Automatically 'tattoo' & protect PDFs for WooCommerce, EDD, an …
dwnldr Developer Profile
2 plugins · 310 total installs
How We Detect dwnldr
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
HTML / DOM Fingerprints
dwnldr_logs