WP-Force Images Download Security & Risk Analysis

wordpress.org/plugins/wp-force-images-download

A simple plugin that force the download of images or pictures such as jpeg,png etc.

90 active installs v1.9 PHP + WP 3.0+ Updated Oct 25, 2025
featured-imgae-downloadforce-images-downloadgenerate-download-buttonpictures-download-buttontemplatetag-force-download
99
A · Safe
CVEs total1
Unpatched0
Last CVEOct 21, 2025
Safety Verdict

Is WP-Force Images Download Safe to Use in 2026?

Generally Safe

Score 99/100

WP-Force Images Download has a strong security track record. Known vulnerabilities have been patched promptly.

1 known CVELast CVE: Oct 21, 2025Updated 5mo ago
Risk Assessment

The 'wp-force-images-download' v1.9 plugin exhibits a generally positive security posture based on the static analysis. The plugin effectively utilizes prepared statements for all SQL queries, has a high percentage of properly escaped output, and implements a good number of nonce and capability checks. The limited attack surface, with no unprotected AJAX handlers or REST API routes, is also a strong indicator of good security practices. Taint analysis revealing no unsanitized paths further reinforces this, suggesting a low risk of common injection vulnerabilities.

However, the presence of one known medium-severity vulnerability in its history, specifically related to Cross-Site Scripting (XSS), warrants attention. While currently patched, it indicates a past weakness in output neutralization that could potentially re-emerge if code is modified without careful consideration. The plugin also performs file operations and external HTTP requests, which, while not inherently insecure, represent potential vectors for compromise if not handled with extreme care and proper sanitization, though the static analysis did not flag any specific issues here. The plugin's reliance on a single shortcode as its sole entry point is a strength in terms of attack surface, but it's crucial that this shortcode's implementation is robust against any potential input manipulation.

Overall, 'wp-force-images-download' v1.9 appears to be a relatively secure plugin. Its strengths lie in its proactive use of security measures like prepared statements and output escaping, and its small, protected attack surface. The historical medium-severity XSS vulnerability is a cautionary note, emphasizing the need for ongoing vigilance and thorough code reviews for any future updates. The performance of file operations and external requests should be continuously monitored for any subtle vulnerabilities that might arise.

Key Concerns

  • Historical medium severity XSS vulnerability
Vulnerabilities
1

WP-Force Images Download Security Vulnerabilities

CVEs by Year

1 CVE in 2025
2025
Patched Has unpatched

Severity Breakdown

Medium
1

1 total CVE

CVE-2025-11809medium · 6.4Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')

WP-Force Images Download <= 1.8 - Authenticated (Contributor+) Stored Cross-Site Scripting via Shortcode

Oct 21, 2025 Patched in 1.9 (9d)
Code Analysis
Analyzed Mar 16, 2026

WP-Force Images Download Code Analysis

Dangerous Functions
0
Raw SQL Queries
0
0 prepared
Unescaped Output
6
68 escaped
Nonce Checks
10
Capability Checks
1
File Operations
7
External Requests
3
Bundled Libraries
0

Output Escaping

92% escaped74 total outputs
Data Flows
All sanitized

Data Flow Analysis

3 flows
<fd> (fd.php:0)
Source (user input) Sink (dangerous op) Sanitizer Transform Unsanitized Sanitized
Attack Surface

WP-Force Images Download Attack Surface

Entry Points1
Unprotected0

Shortcodes 1

[wpfid] wp_fid.php:266
WordPress Hooks 11
actionadmin_menuinc.php:15
filterplugin_action_linksinc.php:90
actionadmin_initinc.php:145
actionadmin_noticesinc.php:283
actionadmin_initinc.php:318
actionadmin_initinc.php:346
actionadmin_initwp_fid.php:68
actionwp_enqueue_scriptswp_fid.php:77
actionwp_enqueue_scriptswp_fid.php:94
actionadmin_post_nopriv_wpfid_downloadwp_fid.php:308
actionadmin_post_wpfid_downloadwp_fid.php:309
Maintenance & Trust

WP-Force Images Download Maintenance & Trust

Maintenance Signals

WordPress version tested6.8.5
Last updatedOct 25, 2025
PHP min version
Downloads9K

Community Trust

Rating98/100
Number of ratings8
Active installs90
Alternatives

WP-Force Images Download Alternatives

No alternatives data available yet.

Developer Profile

WP-Force Images Download Developer Profile

Nazakat Ali

2 plugins · 110 total installs

94
trust score
Avg Security Score
100/100
Avg Patch Time
9 days
View full developer profile
Detection Fingerprints

How We Detect WP-Force Images Download

Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.

Asset Fingerprints

Asset Paths
/wp-content/plugins/wp-force-images-download/style.css
Version Parameters
wp-force-images-download/style.css?ver=

HTML / DOM Fingerprints

CSS Classes
wpfid_button
Data Attributes
wpfid_image_size_optionwpfid_iconwpfid_btn_stylenew_name_attrwpfid_field
Shortcode Output
[wpfidwp_fid_short
FAQ

Frequently Asked Questions about WP-Force Images Download