Monster Downloader Security & Risk Analysis

wordpress.org/plugins/monster-downloader

Monster Downloader is the best plugin for download plugin and themes.Perfect plugin for quickly downloading themes and plugins.

70 active installs v1.0.2 PHP + WP 6.0.2+ Updated May 9, 2024
wp-best-theme-plugin-downloaderwp-downloader-pluswp-plugin-downloaderwp-theme-downloader
92
A · Safe
CVEs total0
Unpatched0
Last CVENever
Safety Verdict

Is Monster Downloader Safe to Use in 2026?

Generally Safe

Score 92/100

Monster Downloader has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.

No known CVEs Updated 1yr ago
Risk Assessment

The "monster-downloader" v1.0.2 plugin exhibits a generally good security posture, with a notable absence of critical vulnerabilities in its history and static analysis. The plugin demonstrates good practices by implementing nonce checks on all AJAX handlers and capability checks, indicating an effort to protect against common WordPress attack vectors. Furthermore, the majority of its SQL queries utilize prepared statements and a high percentage of output is properly escaped, which are positive indicators of secure coding.

Key Concerns

  • Flows with unsanitized paths found
  • File operations present
  • External HTTP requests present
  • SQL queries not using prepared statements
  • Output not properly escaped
Vulnerabilities
None known

Monster Downloader Security Vulnerabilities

No known vulnerabilities — this is a good sign.
Code Analysis
Analyzed Mar 16, 2026

Monster Downloader Code Analysis

Dangerous Functions
0
Raw SQL Queries
2
3 prepared
Unescaped Output
203
561 escaped
Nonce Checks
14
Capability Checks
2
File Operations
2
External Requests
3
Bundled Libraries
0

SQL Query Safety

60% prepared5 total queries

Output Escaping

73% escaped764 total outputs
Data Flows
3 unsanitized

Data Flow Analysis

12 flows3 with unsanitized paths
render_license_page (includes\sdk\classes\class-license.php:315)
Source (user input) Sink (dangerous op) Sanitizer Transform Unsanitized Sanitized
Attack Surface

Monster Downloader Attack Surface

Entry Points6
Unprotected0

AJAX Handlers 5

authwp_ajax_pbsettings-get-iconsincludes\sdk\settings\functions\actions.php:53
authwp_ajax_pbsettings-exportincludes\sdk\settings\functions\actions.php:91
authwp_ajax_pbsettings-importincludes\sdk\settings\functions\actions.php:128
authwp_ajax_pbsettings-resetincludes\sdk\settings\functions\actions.php:156
authwp_ajax_pbsettings-chosenincludes\sdk\settings\functions\actions.php:196

REST API Routes 1

POST/wp-json/pluginbazar/activate_licenseincludes\sdk\classes\class-license.php:67
WordPress Hooks 51
actionadmin_initincludes\sdk\classes\class-client.php:71
actionrest_api_initincludes\sdk\classes\class-license.php:41
actionadmin_menuincludes\sdk\classes\class-license.php:261
actionadmin_noticesincludes\sdk\classes\class-license.php:262
actioninitincludes\sdk\classes\class-notifications.php:31
actionadmin_noticesincludes\sdk\classes\class-notifications.php:32
actionwp_enqueue_scriptsincludes\sdk\settings\classes\abstract.class.php:21
actionadmin_menuincludes\sdk\settings\classes\admin-options.class.php:107
actionadmin_bar_menuincludes\sdk\settings\classes\admin-options.class.php:108
actionnetwork_admin_menuincludes\sdk\settings\classes\admin-options.class.php:112
filteradmin_footer_textincludes\sdk\settings\classes\admin-options.class.php:489
actionadd_meta_boxes_commentincludes\sdk\settings\classes\comment-options.class.php:40
actionedit_commentincludes\sdk\settings\classes\comment-options.class.php:41
actioncustomize_registerincludes\sdk\settings\classes\customize-options.class.php:43
actioncustomize_save_afterincludes\sdk\settings\classes\customize-options.class.php:44
actionwp_enqueue_scriptsincludes\sdk\settings\classes\customize-options.class.php:48
actionadd_meta_boxesincludes\sdk\settings\classes\metabox-options.class.php:52
actionsave_postincludes\sdk\settings\classes\metabox-options.class.php:53
actionedit_attachmentincludes\sdk\settings\classes\metabox-options.class.php:54
actionwp_nav_menu_item_custom_fieldsincludes\sdk\settings\classes\nav-menu-options.class.php:32
actionwp_update_nav_menu_itemincludes\sdk\settings\classes\nav-menu-options.class.php:33
filterwp_edit_nav_menu_walkerincludes\sdk\settings\classes\nav-menu-options.class.php:35
actionadmin_initincludes\sdk\settings\classes\profile-options.class.php:32
actionshow_user_profileincludes\sdk\settings\classes\profile-options.class.php:44
actionedit_user_profileincludes\sdk\settings\classes\profile-options.class.php:45
actionpersonal_options_updateincludes\sdk\settings\classes\profile-options.class.php:47
actionedit_user_profile_updateincludes\sdk\settings\classes\profile-options.class.php:48
actionafter_setup_themeincludes\sdk\settings\classes\setup.class.php:74
actioninitincludes\sdk\settings\classes\setup.class.php:75
actionswitch_themeincludes\sdk\settings\classes\setup.class.php:76
actionadmin_enqueue_scriptsincludes\sdk\settings\classes\setup.class.php:77
actionwp_enqueue_scriptsincludes\sdk\settings\classes\setup.class.php:78
actionwp_headincludes\sdk\settings\classes\setup.class.php:79
filteradmin_body_classincludes\sdk\settings\classes\setup.class.php:80
actionadmin_footerincludes\sdk\settings\classes\shortcode-options.class.php:49
actioncustomize_controls_print_footer_scriptsincludes\sdk\settings\classes\shortcode-options.class.php:50
actionelementor/editor/before_enqueue_scriptsincludes\sdk\settings\classes\shortcode-options.class.php:61
actionelementor/editor/footerincludes\sdk\settings\classes\shortcode-options.class.php:62
actionelementor/editor/footerincludes\sdk\settings\classes\shortcode-options.class.php:63
actionenqueue_block_editor_assetsincludes\sdk\settings\classes\shortcode-options.class.php:311
actionmedia_buttonsincludes\sdk\settings\classes\shortcode-options.class.php:315
actionadmin_initincludes\sdk\settings\classes\taxonomy-options.class.php:43
actionadmin_footerincludes\sdk\settings\fields\icon\icon.php:41
actioncustomize_controls_print_footer_scriptsincludes\sdk\settings\fields\icon\icon.php:42
actionadmin_print_footer_scriptsincludes\sdk\settings\fields\link\link.php:65
actionprint_default_editor_scriptsincludes\sdk\settings\fields\wp_editor\wp_editor.php:62
actioninitmonster-downloader.php:38
actionadmin_enqueue_scriptsmonster-downloader.php:42
filterplugin_action_linksmonster-downloader.php:43
actionadmin_initmonster-downloader.php:44
actionadmin_menumonster-downloader.php:45
Maintenance & Trust

Monster Downloader Maintenance & Trust

Maintenance Signals

WordPress version tested6.5.8
Last updatedMay 9, 2024
PHP min version
Downloads3K

Community Trust

Rating0/100
Number of ratings0
Active installs70
Alternatives

Monster Downloader Alternatives

No alternatives data available yet.

Developer Profile

Monster Downloader Developer Profile

pluginbazar

5 plugins · 100 total installs

86
trust score
Avg Security Score
89/100
Avg Patch Time
30 days
View full developer profile
Detection Fingerprints

How We Detect Monster Downloader

Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.

Asset Fingerprints

Asset Paths
/wp-content/plugins/monster-downloader/assets/admin/js/scripts.js/wp-content/plugins/monster-downloader/assets/admin/css/style.css
Script Paths
/wp-content/plugins/monster-downloader/assets/admin/js/scripts.js
Version Parameters
monster-downloader/assets/admin/js/scripts.js?ver=monster-downloader/assets/admin/css/style.css?ver=

HTML / DOM Fingerprints

CSS Classes
monster-downloader-table-colum
Data Attributes
monster-downloader
JS Globals
monsterDownload
FAQ

Frequently Asked Questions about Monster Downloader