Uptodown APK Download Widget Security & Risk Analysis

wordpress.org/plugins/uptodown-apk-download-widget

Add information about any Android app (+3M Apps) right onto your blog and mobile site along with info on APK downloads

100 active installs v0.1.16 PHP + WP 3.0.1+ Updated Jan 29, 2026
androidapkappsdownload
99
A · Safe
CVEs total1
Unpatched0
Last CVEJan 6, 2025
Safety Verdict

Is Uptodown APK Download Widget Safe to Use in 2026?

Generally Safe

Score 99/100

Uptodown APK Download Widget has a strong security track record. Known vulnerabilities have been patched promptly.

1 known CVELast CVE: Jan 6, 2025Updated 2mo ago
Risk Assessment

The uptodown-apk-download-widget plugin exhibits a generally good security posture based on the static analysis. The absence of dangerous functions, SQL injection vulnerabilities, improper output escaping, and file operations are positive indicators. Furthermore, the code employs prepared statements for its SQL queries and includes nonce checks, which are important security practices. The lack of external HTTP requests also reduces potential attack vectors.

However, the plugin's vulnerability history reveals a past medium-severity Cross-Site Scripting (XSS) vulnerability. While this vulnerability is currently patched, its existence suggests that the plugin's developers may have had past challenges in fully sanitizing user input. The static analysis did not reveal any unsanitized taint flows, which is reassuring, but the historical context warrants continued vigilance.

In conclusion, while the current version of the plugin demonstrates strong adherence to secure coding principles in its static analysis, the past XSS vulnerability is a point of concern. The absence of capability checks for its single shortcode entry point could also be a potential oversight, depending on the functionality it exposes. Overall, the plugin is in a decent state, but the historical vulnerability should not be entirely dismissed.

Key Concerns

  • Missing capability checks on entry points
  • Past medium-severity XSS vulnerability history
Vulnerabilities
1

Uptodown APK Download Widget Security Vulnerabilities

CVEs by Year

1 CVE in 2025
2025
Patched Has unpatched

Severity Breakdown

Medium
1

1 total CVE

CVE-2024-12453medium · 6.4Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')

Uptodown APK Download Widget <= 0.1.10 - Authenticated (Contributor+) Stored Cross-Site Scripting

Jan 6, 2025 Patched in 0.1.11 (18d)
Code Analysis
Analyzed Mar 16, 2026

Uptodown APK Download Widget Code Analysis

Dangerous Functions
0
Raw SQL Queries
0
1 prepared
Unescaped Output
0
10 escaped
Nonce Checks
1
Capability Checks
0
File Operations
0
External Requests
0
Bundled Libraries
0

SQL Query Safety

100% prepared1 total queries

Output Escaping

100% escaped10 total outputs
Data Flows
All sanitized

Data Flow Analysis

2 flows
check_options (uptodown_wp_widget.php:155)
Source (user input) Sink (dangerous op) Sanitizer Transform Unsanitized Sanitized
Attack Surface

Uptodown APK Download Widget Attack Surface

Entry Points1
Unprotected0

Shortcodes 1

[utd-widget] uptodown_wp_widget.php:21
WordPress Hooks 4
actionwp_enqueue_scriptsuptodown_wp_widget.php:22
filterthe_contentuptodown_wp_widget.php:23
actionadmin_menuuptodown_wp_widget.php:150
actionadmin_inituptodown_wp_widget.php:151
Maintenance & Trust

Uptodown APK Download Widget Maintenance & Trust

Maintenance Signals

WordPress version tested6.9.4
Last updatedJan 29, 2026
PHP min version
Downloads82K

Community Trust

Rating100/100
Number of ratings2
Active installs100
Developer Profile

Uptodown APK Download Widget Developer Profile

Uptodown

1 plugin · 100 total installs

93
trust score
Avg Security Score
99/100
Avg Patch Time
18 days
View full developer profile
Detection Fingerprints

How We Detect Uptodown APK Download Widget

Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.

Asset Fingerprints

Asset Paths
/wp-content/plugins/uptodown-apk-download-widget/simplehtmldom/simple_html_dom.php
Script Paths
//api.uptodown.com/

HTML / DOM Fingerprints

CSS Classes
utd_widget
Data Attributes
data-packagename
Shortcode Output
<div class="utd_widget" data-packagename="
FAQ

Frequently Asked Questions about Uptodown APK Download Widget