Plugin Pulse
← Pulse

CM Download Manager – Organize, Protect & Share Files in WordPress

by CreativeMindsSolutions · Uncategorized

Also makes 18 other plugins · 19.9K+ installs across the portfolio →

Manage and protect your downloads in WordPress with secure access, categories, and powerful file sharing.

How scoring works →
81 Health · B
Maintenance 97/100
Rating quality 71/100
Support 70/100

81 health vs 55 average across 20,718 Uncategorized plugins

Directory ranking optimization

How it's scored →

How well this listing is tuned to rank in WordPress.org search, on the factors an owner controls. Not popularity, optimization.

95 / 100

Excellent listing optimization

Well tuned across the board

Update recency 100/100
WP compatibility 100/100
Rating quality 80/100
Listing tuning 100/100

Daily downloads

Since 2024-09-16 · 730 days · wp.org + Plugin Pulse archive

+7% vs prior 30d
13Downloads · Sep 26

30-day downloads

Rolling 30-day volume · peaks are release surges

407

now · peak 429

40730d downloads · Sep 16

Update activity

How busy the existing users are, measured as downloads in the last 30 days for every 1,000 active sites. A spike means a new release everyone's pulling; a long, slow decline means an aging user base that updates less.

4.1Kper 1k installs · Sep 16

Estimated active installs

The public count shows “100+”. Our estimate pins where the real number sits.

modeled estimate
100–200 ≈170

Modeled within the band wp.org reports; tightens as we track daily.

Install history · since 2026-09-15 · 2 observations

100Installs · Sep 16

Estimated value

What this plugin might earn a year, and what it might sell for. Modeled from public signals; we don't see anyone's books.

low confidence

Est. annual revenue

$0–$130 ≈$11

Est. acquisition value

$0–$520 ≈$23

We can't see a pro tier, so this plugin may earn little or nothing from these installs. A small install base leaves thin data to model from.

How we estimate this

Assumptions

  • Free → paid conversion. 0.05%–0.5% of active installs pay for something. No pro tier is visible, so this band starts near zero.
  • Annual price per customer. $49–$129 a year, typical for WordPress plugins rather than this plugin's own pricing.
  • Acquisition multiple. 2x–4x annual revenue, the going range for small WordPress-plugin businesses, the typical range for a steady plugin.
  • Install base. 100–200 active installs, from our install estimate (wp.org only publishes the floor).

Inputs

Active installs
100–200
Category
Uncategorized
Pro tier
none detected
Download trend
steady (30d downloads flat vs prior 30d)
Reviews
43
Last updated
116 days ago

Revenue is installs × conversion × price; value is revenue × a typical acquisition multiple. Every factor is an assumption band, so the output is a wide range on purpose. If you're buying or selling, treat this as a starting point for due diligence.

Details

Version
3.1.1
Last updated
4mo ago
Added
2013-05-11 · 13 yrs old
Requires WP
Tested up to
7.0.4
Requires PHP
5.2.4

Known vulnerabilities

via Wordfence Intelligence

10 disclosed vulnerabilities on record for this plugin, all fixed in the current version. Sites on older versions stay exposed until they update.

  1. 2025-03-27 CVE-2025-30910 Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') Affects <= 2.9.6 Patched in 3.0.0
  2. 2024-03-25 CVE-2024-1962 Cross-Site Request Forgery (CSRF) Affects < 2.9.1 Patched in 2.9.1
  3. 2024-03-25 CVE-2024-1232 Cross-Site Request Forgery (CSRF) Affects < 2.9.0 Patched in 2.9.0
  4. 2024-03-25 CVE-2024-1231 Cross-Site Request Forgery (CSRF) Affects < 2.9.0 Patched in 2.9.0
  5. 2022-09-05 CVE-2022-3076 Unrestricted Upload of File with Dangerous Type Affects <= 2.8.5 Patched in 2.8.6
  6. 2021-04-13 CVE-2020-24145 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') Affects < 2.8.0 Patched in 2.8.0
  7. 2021-04-13 CVE-2020-24146 Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') Affects < 2.8.0 Patched in 2.8.0
  8. 2020-10-22 CVE-2020-27344 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') Affects < 2.8.0 Patched in 2.8.0
  9. 2014-12-01 CVE-2014-9129 Cross-Site Request Forgery (CSRF) Affects <= 2.0.6 Patched in 2.0.7
  10. 2014-11-10 CVE-2014-8877 Improper Control of Generation of Code ('Code Injection') Affects <= 2.0.3 Patched in 2.0.4

Vulnerability records provided by Wordfence Intelligence. Copyright 2012-2026 Defiant Inc. License and terms.

CVE records: Copyright 1999-2026 The MITRE Corporation. CVE terms of use.

Growth timeline

Install-tier crossings we have observed, and how long each tier took to outgrow

No tier crossings observed yet.

Competes with

The plugins that solve the same job, ranked by shared tags then reach, closest match first. The letter on the right is each plugin's health grade (A best, F worst).

Compare head to head →

Embed this report card

Drop a live Pulse card for CM Download Manager – Organize, Protect & Share Files in WordPress into a readme, a review or a deck. It updates itself.

<iframe src="https://plugins.wpmayor.com/embed/cm-download-manager" width="480" height="300" style="border:0" loading="lazy" title="CM Download Manager – Organize, Protect & Share Files in WordPress — Plugin Pulse"></iframe>
Preview card ↗

CM Download Manager – Organize, Protect & Share Files in WordPress: 100+ active installs, 3.9★ (43 reviews). Plugin Pulse (WP Mayor), as of 2026-09-16. https://plugins.wpmayor.com/plugin/cm-download-manager