Attachment Download Manager for Gmail Security & Risk Analysis

wordpress.org/plugins/gmail-imap-email-attachment-manager

Attachment Download Manager for Gmail is a simple and efficient WordPress plugin designed to connect your Gmail account from wordpress. ---

0 active installs v1.0.0 PHP 7.4+ WP 5.0+ Updated Dec 31, 2024
download-gmail-attachmentgmailgmail-connectimapsave-gmail-attachment
92
A · Safe
CVEs total0
Unpatched0
Last CVENever
Safety Verdict

Is Attachment Download Manager for Gmail Safe to Use in 2026?

Generally Safe

Score 92/100

Attachment Download Manager for Gmail has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.

No known CVEs Updated 1yr ago
Risk Assessment

Based on the static analysis and vulnerability history, the "gmail-imap-email-attachment-manager" plugin v1.0.0 appears to have a strong security posture. The absence of any identified critical or high severity taint flows, dangerous functions, or file operations is highly encouraging. Furthermore, the plugin demonstrates good practices by ensuring 100% of output is properly escaped and 80% of its SQL queries utilize prepared statements. The presence of nonce checks further bolsters its security against common AJAX-based attacks.

However, a key area of concern is the complete lack of capability checks across all entry points. While the current analysis doesn't reveal immediate exploitable issues, the absence of proper authorization checks on AJAX handlers, shortcodes, and REST API routes leaves the plugin vulnerable to privilege escalation or unauthorized actions if a vulnerability were discovered in the future that bypassed nonce checks or if a new attack vector emerged. The historical data of zero known CVEs is positive, suggesting a well-maintained codebase to date, but it does not eliminate the need for robust authorization mechanisms.

In conclusion, the plugin exhibits strong defensive coding practices in areas like output escaping and SQL sanitization, coupled with a clean vulnerability history. Its main weakness lies in the lack of capability checks on its entry points, representing a significant potential risk that, while not currently exploited, should be addressed to ensure comprehensive security.

Key Concerns

  • Missing capability checks on entry points
Vulnerabilities
None known

Attachment Download Manager for Gmail Security Vulnerabilities

No known vulnerabilities — this is a good sign.
Code Analysis
Analyzed Mar 17, 2026

Attachment Download Manager for Gmail Code Analysis

Dangerous Functions
0
Raw SQL Queries
1
4 prepared
Unescaped Output
0
87 escaped
Nonce Checks
4
Capability Checks
0
File Operations
0
External Requests
0
Bundled Libraries
0

SQL Query Safety

80% prepared5 total queries

Output Escaping

100% escaped87 total outputs
Data Flows
All sanitized

Data Flow Analysis

5 flows
download_attachments (inc\class-bv-ajax.php:71)
Source (user input) Sink (dangerous op) Sanitizer Transform Unsanitized Sanitized
Attack Surface

Attachment Download Manager for Gmail Attack Surface

Entry Points3
Unprotected0

AJAX Handlers 2

authwp_ajax_gmail_download_attachmentsinc\class-bv-ajax.php:32
authwp_ajax_test_connectioninc\class-bv-ajax.php:33

Shortcodes 1

[gmail_sceheduled_downloads] inc\class-bv-cron.php:30
WordPress Hooks 5
actioninitattachment-download-manager-for-gmail.php:46
actiongmail_sceheduled_downloadsinc\class-bv-cron.php:31
actionadmin_enqueue_scriptsinc\class-bv-enqueuescript.php:30
actionadmin_menuinc\class-bv-pluginpages.php:30
actionadmin_initinc\class-imapsettings.php:29
Maintenance & Trust

Attachment Download Manager for Gmail Maintenance & Trust

Maintenance Signals

WordPress version tested6.7.5
Last updatedDec 31, 2024
PHP min version7.4
Downloads640

Community Trust

Rating0/100
Number of ratings0
Active installs0
Developer Profile

Attachment Download Manager for Gmail Developer Profile

brainvireinfo

14 plugins · 7K total installs

87
trust score
Avg Security Score
90/100
Avg Patch Time
14 days
View full developer profile
Detection Fingerprints

How We Detect Attachment Download Manager for Gmail

Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.

Asset Fingerprints

Asset Paths
/wp-content/plugins/gmail-imap-email-attachment-manager/assets/css/gmail-imap-help-page-style.css/wp-content/plugins/gmail-imap-email-attachment-manager/assets/js/gmail-imap-script.js
Script Paths
/wp-content/plugins/gmail-imap-email-attachment-manager/assets/js/gmail-imap-script.js
Version Parameters
gmail-imap-email-attachment-manager/assets/css/gmail-imap-help-page-style.css?ver=gmail-imap-email-attachment-manager/assets/js/gmail-imap-script.js?ver=

HTML / DOM Fingerprints

Data Attributes
data-nonce
JS Globals
bv_ajax
Shortcode Output
[gmail_sceheduled_downloads]
FAQ

Frequently Asked Questions about Attachment Download Manager for Gmail