Wp Theme plugin Download Security & Risk Analysis

wordpress.org/plugins/wp-theme-plugin-download

Download plugins and themes on your site as a .zip and ready to install on another site.

3K active installs v1.3 PHP + WP 3.0+ Updated Sep 1, 2020
clone-pluginclone-themesplugin-downloadtheme-downloadwordpress-download
85
A · Safe
CVEs total0
Unpatched0
Last CVENever
Safety Verdict

Is Wp Theme plugin Download Safe to Use in 2026?

Generally Safe

Score 85/100

Wp Theme plugin Download has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.

No known CVEs Updated 5yr ago
Risk Assessment

The "wp-theme-plugin-download" v1.3 plugin exhibits a generally strong security posture based on the provided static analysis. The complete absence of unprotected AJAX handlers, REST API routes, shortcodes, and cron events, combined with 100% usage of prepared statements for SQL queries and proper output escaping, indicates good development practices in these critical areas. The presence of a nonce check and the lack of critical or high-severity taint flows further bolster its security. However, the analysis does reveal one flow with unsanitized paths. While this is not classified as a critical or high-severity issue, it warrants attention as it represents a potential weakness where user-supplied data might not be adequately validated before being used in a file operation, potentially leading to unintended behavior or information disclosure in specific scenarios.

The plugin has a clean vulnerability history with no recorded CVEs, which is a positive indicator. This suggests that the plugin has either not been a target for attackers or has been developed with sufficient security awareness to avoid common vulnerabilities. The lack of recorded vulnerabilities of any type is a strong point. In conclusion, the plugin is well-implemented in many core security areas. The single unsanitized path flow is the primary area of concern, though its severity is not explicitly high according to the analysis. The absence of known vulnerabilities is a significant strength. Further investigation into the specific nature of the unsanitized path flow is recommended to fully assess its impact.

Key Concerns

  • Flow with unsanitized paths
Vulnerabilities
None known

Wp Theme plugin Download Security Vulnerabilities

No known vulnerabilities — this is a good sign.
Code Analysis
Analyzed Mar 16, 2026

Wp Theme plugin Download Code Analysis

Dangerous Functions
0
Raw SQL Queries
0
0 prepared
Unescaped Output
0
1 escaped
Nonce Checks
1
Capability Checks
0
File Operations
2
External Requests
0
Bundled Libraries
0

Output Escaping

100% escaped1 total outputs
Data Flows
1 unsanitized

Data Flow Analysis

2 flows1 with unsanitized paths
ab_download (wp-theme-plugin-download.php:141)
Source (user input) Sink (dangerous op) Sanitizer Transform Unsanitized Sanitized
Attack Surface

Wp Theme plugin Download Attack Surface

Entry Points0
Unprotected0
WordPress Hooks 4
actionplugins_loadedwp-theme-plugin-download.php:12
filterplugin_action_linkswp-theme-plugin-download.php:22
filtertheme_action_linkswp-theme-plugin-download.php:24
actionadmin_footer-themes.phpwp-theme-plugin-download.php:26
Maintenance & Trust

Wp Theme plugin Download Maintenance & Trust

Maintenance Signals

WordPress version tested5.5.18
Last updatedSep 1, 2020
PHP min version
Downloads62K

Community Trust

Rating100/100
Number of ratings14
Active installs3K
Developer Profile

Wp Theme plugin Download Developer Profile

Abhay

6 plugins · 4K total installs

84
trust score
Avg Security Score
85/100
Avg Patch Time
30 days
View full developer profile
Detection Fingerprints

How We Detect Wp Theme plugin Download

Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.

Asset Fingerprints

Asset Paths
/wp-content/plugins/wp-theme-plugin-download/ab_download.php
Script Paths
wp-content/plugins/wp-theme-plugin-download/wp-theme-plugin-download.php
Version Parameters
wp-theme-plugin-download/wp-theme-plugin-download.php?ver=

HTML / DOM Fingerprints

CSS Classes
download
Data Attributes
id="wp-downloader"
JS Globals
jQuery
FAQ

Frequently Asked Questions about Wp Theme plugin Download