
Lana Downloads Manager Security & Risk Analysis
wordpress.org/plugins/lana-downloads-managerDownloadable files management system
Is Lana Downloads Manager Safe to Use in 2026?
Generally Safe
Score 97/100Lana Downloads Manager has a strong security track record. Known vulnerabilities have been patched promptly.
The "lana-downloads-manager" plugin, in version 1.12.0, exhibits a mixed security posture. While it demonstrates good practices by implementing nonce and capability checks on a significant portion of its entry points and using prepared statements for most SQL queries, there are areas for concern. The static analysis reveals a single flow with an unsanitized path, which is a potential risk for path traversal vulnerabilities. Additionally, 27% of output escaping is not properly handled, increasing the risk of Cross-Site Scripting (XSS) vulnerabilities. The plugin's historical vulnerability data is particularly concerning, with three known medium-severity CVEs related to XSS, Path Traversal, and sensitive information exposure. The fact that the last vulnerability was very recent (July 2025) and that there are currently no unpatched vulnerabilities suggests a history of security issues, although the developers have addressed them in the past. The absence of unpatched vulnerabilities in this specific version is a positive sign, but the recurring vulnerability types and the presence of unsanitized paths in the static analysis warrant caution.
Key Concerns
- Flow with unsanitized path found
- 27% of outputs not properly escaped
- 3 past medium severity CVEs
Lana Downloads Manager Security Vulnerabilities
CVEs by Year
Severity Breakdown
3 total CVEs
Lana Downloads Manager <= 1.10.0 - Authenticated (Administrator+) Stored Cross-Site Scripting
Lana Downloads Manager <= 1.9.0 - Authenticated (Admin+) Arbitrary File Download
Lana Downloads Manager <= 1.7.1 - Authenticated (Contributor+) Arbitrary File Download
Lana Downloads Manager Code Analysis
SQL Query Safety
Output Escaping
Data Flow Analysis
Lana Downloads Manager Attack Surface
AJAX Handlers 1
Shortcodes 1
WordPress Hooks 36
Maintenance & Trust
Lana Downloads Manager Maintenance & Trust
Maintenance Signals
Community Trust
Lana Downloads Manager Alternatives
Simple Download Counter
simple-download-counter
Simply counts the number of times your files are downloaded. Display download links and counts using shortcodes.
Download Manager
download-manager
This File Management & Digital Store plugin will help you to control file downloads & sell digital products from your WP site.
Download Monitor
download-monitor
Powerful Download Manager Plugin for WordPress
Download Manager Addons for Elementor
wpdm-elementor
Download Manager Addons for Elementor
Document Library Lite
document-library-lite
Create a WordPress document library to manage, search and download files.
Lana Downloads Manager Developer Profile
13 plugins · 4K total installs
How We Detect Lana Downloads Manager
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/lana-downloads-manager/assets/js/ LanaDownloads.js/wp-content/plugins/lana-downloads-manager/assets/css/ LanaDownloads.css/wp-content/plugins/lana-downloads-manager/assets/js/ LanaDownloads.jslana-downloads-manager/assets/js/ LanaDownloads.js?ver=lana-downloads-manager/assets/css/ LanaDownloads.css?ver=HTML / DOM Fingerprints
lana-downloads-manager<!-- create dir --><!-- create log table --><!-- create table --><!-- use lana downloads base folder -->+4 moredata-lana-downloads-manager-iddata-lana-downloads-manager-actionLanaDownloads[lana_downloads_manager_download_list][lana_downloads_manager_download_details]