
GitHub Release Downloads Security & Risk Analysis
wordpress.org/plugins/github-release-downloadsGet the download count, links and more information for releases of GitHub repositories.
Is GitHub Release Downloads Safe to Use in 2026?
Generally Safe
Score 85/100GitHub Release Downloads has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.
The github-release-downloads plugin v2.3.1 exhibits a generally strong security posture, with no known vulnerabilities in its history and a clean static analysis report regarding dangerous functions, SQL injection risks, and taint flows. The plugin effectively utilizes prepared statements for all SQL queries and implements capability checks for its entry points, which is a positive sign of secure development practices. However, there are some areas for improvement. The plugin has a notable lack of nonce checks on its AJAX handlers, which could leave it susceptible to Cross-Site Request Forgery (CSRF) attacks if an attacker can trick a logged-in user into executing unintended actions. Additionally, the output escaping is only moderately effective, with 43% of outputs not being properly escaped, potentially leading to Cross-Site Scripting (XSS) vulnerabilities if user-controlled data is reflected directly in the output without sufficient sanitization. While the plugin has a clean history and no critical code signals, these identified weaknesses, particularly the absence of nonce checks and imperfect output escaping, represent potential security risks that should be addressed.
Key Concerns
- AJAX handlers lack nonce checks
- Insufficient output escaping
GitHub Release Downloads Security Vulnerabilities
GitHub Release Downloads Release Timeline
GitHub Release Downloads Code Analysis
Output Escaping
Data Flow Analysis
GitHub Release Downloads Attack Surface
AJAX Handlers 1
Shortcodes 3
WordPress Hooks 5
Maintenance & Trust
GitHub Release Downloads Maintenance & Trust
Maintenance Signals
Community Trust
GitHub Release Downloads Alternatives
Continuous Delivery for Digital Goods and Downloads
continuous-delivery
Continuous Delivery for Digital Goods and Downloads expands your WordPress download portal to a fully-fledged Continuous Delivery pipeline.
Release Deploy for Easy Digital Downloads
release-deploy-edd
Automate your EDD workflow. Push a tag, create a GitHub release, and files are instantly available—supports private repos, no local storage.
Rundiz Downloads
rundiz-downloads
Download manager for WordPress that support GitHub auto update.
Simple Download Monitor
simple-download-monitor
Easily manage downloadable files and monitor downloads of your digital files from your WordPress site.
Prevent Direct Access – Protect WordPress Files
prevent-direct-access
A simple way to prevent search engines and the public from indexing and accessing your files without complex user authentication.
GitHub Release Downloads Developer Profile
1 plugin · 70 total installs
How We Detect GitHub Release Downloads
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/github-release-downloads/css/style.css/wp-content/plugins/github-release-downloads/js/admin-notices.jsgithub-release-downloads/js/admin-notices.js?ver=HTML / DOM Fingerprints
release-downloads-headerrelease-descriptionrelease-downloadsrelease-namerelease-sizerelease-download-countrelease-sourcegrd_dismiss_notice_idgrd_dismiss_notice<h2 class="release-downloads-header"><div class="release-description"><ul class="release-downloads"><a href="