Plugin Pulse
← Pulse

Download Manager

by Shahjada · eCommerce

Also makes 5 other plugins · 113.1K+ installs across the portfolio →

This File Management & Digital Store plugin will help you to control file downloads & sell digital products from your WP site.

How scoring works →
85 Health · A
Maintenance 100/100
Rating quality 79/100
Support 70/100

85 health vs 68 average across 5,561 eCommerce plugins

Directory ranking optimization

How it's scored →

How well this listing is tuned to rank in WordPress.org search, on the factors an owner controls. Not popularity, optimization.

89 / 100

Excellent listing optimization

Biggest win: Support resolution

Update recency 100/100
WP compatibility 100/100
Rating quality 82/100
Listing tuning 100/100
Support resolution 50/100

To rank higher: Mark more forum threads resolved — the resolved ratio feeds the ranking.

Get the full rank-higher report →

Daily downloads

Since 2022-10-05 · 1,421 days · wp.org + Plugin Pulse archive

-60% vs prior 30d
2.8KDownloads · Aug 26

30-day downloads

Rolling 30-day volume · peaks are release surges

88.1K

now · peak 271.5K

88.5K30d downloads · Aug 26

Directory rank vs rivals

wp.org popularity rank over time · higher is better · when a rival's line climbs above yours, they've overtaken you

Download Manager · #458 you Download Monitor · #512 Download Manager Add · #2821 Document Library Lit · #3469

Rating trend

Star average over time · dips mark rough releases

4.1Stars · Aug 26

Update activity

How busy the existing users are, measured as downloads in the last 30 days for every 1,000 active sites. A spike means a new release everyone's pulling; a long, slow decline means an aging user base that updates less.

885per 1k installs · Aug 26

Release cadence

Actively maintained
from wp.org release tags

How often this plugin actually ships. A steady rhythm is the maintenance signal a single "last updated" date can't show.

45

releases in the last 12 months

1mo ago

latest release · v3.3.66

173

tagged releases on record

Recent releases

3.3.66 · 1mo ago3.3.65 · 1mo ago3.3.64 · 1mo ago3.3.63 · 2mo ago3.3.62 · 2mo ago3.3.61 · 2mo ago3.3.60 · 2mo ago3.3.59 · 2mo ago3.3.58 · 2mo ago3.3.57 · 3mo ago3.3.56 · 3mo ago3.3.55 · 4mo ago3.3.54 · 4mo ago3.3.53 · 5mo ago

What its installed base runs

via wordpress.org

Share of active installs on each version of this plugin · 72% run the current release. Green is the current release; a big slice on older versions is a user base that has stopped updating.

v3.3 72%
v3.2 17%
Older / other versions 11%

Estimated active installs

The public count shows “100K+”. Our estimate pins where the real number sits.

modeled estimate
100K–200K ≈150K

Modeled within the band wp.org reports; tightens as we track daily.

Install history · since 2015-03-10 · 1,494 observations

100KInstalls · Aug 26

Estimated value

What this plugin might earn a year, and what it might sell for. Modeled from public signals; we don't see anyone's books.

Est. annual revenue

N/A

Est. acquisition value

N/A

No paid tier is visible, so we don't put a figure on revenue or sale value: that would be guessing. The install base is a real asset to an acquirer, just not one public data lets us price. A declining trend compresses what a buyer would pay.

Details

Version
3.3.68
Last updated
4d ago
Added
2010-02-10 · 16 yrs old
Requires WP
5.3
Tested up to
7.1
Requires PHP

Recent review vibe

read from the latest 12 reviews to 2026-07-13
Positive PraisePerformanceFeature requests

Reviewers keep praising the support team by name and say the plugin covers what they need, with one asking for a translation module and flagging the new Glassmorphism Card theme for slowing page loads.

Recent reviews

All reviews on wp.org ↗
  1. promise521
    1mo ago

    For a few days now, I have been dealing with Tahasin, due to problems on my site. This brother has been great. Keep it up brother. I wish I could rate your service 10 stars. thanks again Download Manager. You are a great company to work with.

    Read on wp.org ↗
  2. gorkova
    3mo ago

    Very kind and hardworking people, and the helpful support is excellent and very efficient.

    Read on wp.org ↗
  3. Fred
    4mo ago

    Great plugin and excellent support!

    Read on wp.org ↗
  4. purepixels
    4mo ago

    This plugin is perfect. It improved a lot over the last few years. We use it already for almost 10 years and we’ve seen the whole product and interface improve over the years. Everything you might need from a download manager is in there. And, if you ever run into issues or you have questions, the support (via chat and email) is very quick to help you out. We love this plugin. The Pro version is highly recommended !

    Read on wp.org ↗
  5. jds2mpo
    5mo ago

    Great Support on a few occasions

    Read on wp.org ↗
  6. Furkan Özden
    5mo ago

    Eklenti harika. Çeviri kısmının incelenmesi gerek. Örneğin page-template-default.php içinde [txt=Download][download_count]yer alan kısımda hata var. [txt=Download] yazması lazım. Kendi Türkçe çevirinizi yapabiliyorsunuz. Keşke sisteme yükleyip kullanıcılarla ilerleyen bir çeviri modülü olsa. Bu şekiled her güncelleme sonrası yedek aldığım çeviri dosyasını yüklemem gerekiyor. Son güncelleme ile eklenen Glassmorphism Card teması sayfa yükleme hızını büyük ölçüde yavaşlatıyor. Bulunan temalar yeterliydi.

    Read on wp.org ↗
  7. cesare1360
    5mo ago

    RISOLTO…Uaoooo….!!!Innanzitutto complimenti perché siete velocissimi a rispondere.Vi ringrazio vivamente per avermi illuminato sull’errore che stavo facendo e quindi di configurare bene le chiavi. Io mi sono perso sulle varie soluzioni che ti propone la console di google mentre era tutto molto più semplice.Siete unici! Siete avanti!!!

    Read on wp.org ↗
  8. vickyh
    6mo ago

    I’m using the free version of the plugin and have had a couple of issues recently. I posted my question on their forum and on both occasions they came back really quickly with answers and solutions. Very impressed with this level of support, especially as I’m only using the free version.

    Read on wp.org ↗

Latest updates

via wp.org changelog

Recent releases and news for this plugin

  1. Version 3.3.66 Security: Author+ Stored Cross-Site Scripting via Package Title – the title was run through stripcslashes() when rendered, which decoded C-style escape sequences back into active markup after save-time sanitization had a 3.3.66
  2. Version 3.3.65 Fixed: The [wpdm_changelog] shortcode rendered unstyled, because its markup was emitted without the wrapper element that the front-end stylesheet scopes every changelog rule to 3.3.65
  3. Version 3.3.64 Fixed: The [changelog] template tag rendered unstyled, because the front-end stylesheet still targeted an older markup structure – entry content was hidden outright, the timeline had no layout and the icons rendered at t 3.3.64
  4. Version 3.3.63 New: Activity Reports – scheduled weekly or monthly summary emails covering downloads, top packages, trending items, user activity, category breakdown and storage usage, with configurable sections, recipients, schedule a 3.3.63
  5. Version 3.3.62 Improved: Expirable download link handling Improved: Emailed and shareable download links are now kept in a durable, indexed store instead of post meta, so they survive cache clears and no longer bloat package meta Impro 3.3.62
  6. Version 3.3.61 Fixed: Authenticated (Contributor+) Stored Cross-Site Scripting via the no_data_msg attribute of the wpdm_all_packages shortcode ( Reported by Wordfence ) 3.3.61

Known vulnerabilities

via Wordfence Intelligence

83 disclosed vulnerabilities on record for this plugin, all fixed in the current version. Sites on older versions stay exposed until they update.

  1. 2026-08-05 CVE-2026-14292 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') Affects < 3.3.66 Patched in 3.3.66
  2. 2026-07-31 CVE-2026-16685 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') Affects <= 3.3.66 Patched in 3.3.67
  3. 2026-07-08 CVE-2026-14343 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') Affects <= 3.3.61 Patched in 3.3.62
  4. 2026-06-30 CVE-2026-13733 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') Affects <= 3.3.60 Patched in 3.3.61
  5. 2026-04-09 CVE-2026-4057 Missing Authorization Affects <= 3.3.51 Patched in 3.3.52
  6. 2026-04-08 CVE-2026-5357 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') Affects <= 3.3.52 Patched in 3.3.53
  7. 2026-03-18 CVE-2026-2571 Exposure of Sensitive Information to an Unauthorized Actor Affects <= 3.3.49 Patched in 3.3.50
  8. 2026-02-19 CVE-2026-39676 Missing Authorization Affects <= 3.3.52 Patched in 3.3.53
  9. 2026-02-17 CVE-2026-1666 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') Affects <= 3.3.46 Patched in 3.3.47
  10. 2026-02-10 CVE-2026-39615 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') Affects <= 3.3.53 Patched in 3.3.54
  11. 2026-01-05 CVE-2025-15364 Missing Support for Integrity Check Affects <= 3.3.40 Patched in 3.3.41
  12. 2025-12-17 CVE-2025-13498 Missing Authorization Affects <= 3.3.32 Patched in 3.3.33
  13. 2025-11-07 CVE-2025-12177 Use of Hard-coded Cryptographic Key Affects <= 3.3.30 Patched in 3.3.31
  14. 2025-09-30 CVE-2025-63070 Exposure of Sensitive Information to an Unauthorized Actor Affects <= 3.3.32 Patched in 3.3.33
  15. 2025-09-26 CVE-2025-60092 Exposure of Sensitive Information to an Unauthorized Actor Affects <= 3.3.25 Patched in 3.3.26
  16. 2025-09-26 CVE-2025-60093 Cross-Site Request Forgery (CSRF) Affects <= 3.3.24 Patched in 3.3.25
  17. 2025-09-18 CVE-2025-10146 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') Affects <= 3.3.23 Patched in 3.3.24
  18. 2025-06-18 CVE-2025-4367 Improper Neutralization of Script-Related HTML Tags in a Web Page (Basic XSS) Affects <= 3.3.18 Patched in 3.3.19
  19. 2025-04-18 CVE-2025-3404 Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') Affects <= 3.3.12 Patched in 3.3.13
  20. 2025-04-17 CVE-2025-3056 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') Affects <= 3.3.12 Patched in 3.3.13
  21. 2025-03-12 CVE-2025-1785 Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') Affects <= 3.3.08 Patched in 3.3.09
  22. 2025-01-17 CVE-2024-13126 Files or Directories Accessible to External Parties Affects <= 3.3.06 Patched in 3.3.07
  23. 2024-12-19 CVE-2024-56217 Missing Authorization Affects <= 3.3.03 Patched in 3.3.04
  24. 2024-12-18 CVE-2024-11740 Improper Control of Generation of Code ('Code Injection') Affects <= 3.3.03 Patched in 3.3.04
  25. 2024-12-18 CVE-2024-11768 Improper Authorization Affects <= 3.3.03 Patched in 3.3.04
  26. 2024-11-29 CVE-2024-10706 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') Affects <= 3.3.02 Patched in 3.3.03
  27. 2024-10-09 CVE-2024-8444 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') Affects <= 3.2.99 Patched in 3.3.00
  28. 2024-09-23 CVE-2024-8284 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') Affects <= 3.2.98 Patched in 3.2.99
  29. 2024-07-30 CVE-2024-6208 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') Affects <= 3.2.97 Patched in 3.2.98
  30. 2024-06-12 CVE-2024-2098 Authentication Bypass by Alternate Name Affects <= 3.2.89 Patched in 3.2.90
  31. 2024-06-11 CVE-2024-5266 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') Affects <= 3.2.92 Patched in 3.2.94
  32. 2024-06-11 CVE-2024-1766 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') Affects <= 3.2.86 Patched in 3.2.87
  33. 2024-06-04 CVE-2024-4001 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') Affects <= 3.2.93 Patched in 3.2.94
  34. 2024-05-30 CVE-2024-4160 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') Affects <= 3.2.90 Patched in 3.2.91
  35. 2024-03-16 CVE-2024-29114 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') Affects <= 3.2.84 Patched in 3.2.85
  36. 2024-02-28 CVE-2023-6954 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') Affects <= 3.2.85 Patched in 3.2.86
  37. 2024-02-28 CVE-2023-6785 Improper Access Control Affects <= 3.2.84 Patched in 3.2.85
  38. 2023-11-29 CVE-2023-6421 Incorrect Authorization Affects <= 3.2.82 Patched in 3.2.83
  39. 2023-05-12 CVE-2023-2305 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') Affects <= 3.2.70 Patched in 3.2.71
  40. 2023-05-08 CVE-2023-1524 Improper Authorization Affects <= 3.2.70 Patched in 3.2.71
  41. 2023-04-10 CVE-2023-1809 Exposure of Sensitive Information to an Unauthorized Actor Affects 4.0 - 6.3.0 Patched in 6.3.0
  42. 2022-12-20 CVE-2022-4476 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') Affects <= 3.2.61 Patched in 3.2.62
  43. 2022-11-29 CVE-2022-45836 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') Affects <= 3.2.59 Patched in 3.2.60
  44. 2022-09-05 CVE-2022-2926 Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') Affects < 3.2.55 Patched in 3.2.55
  45. 2022-08-17 CVE-2022-2436 Deserialization of Untrusted Data Affects <= 3.2.49 Patched in 3.2.50
  46. 2022-08-04 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') Affects <= 3.2.53 Patched in 3.2.54
  47. 2022-08-02 CVE-2022-34347 Cross-Site Request Forgery (CSRF) Affects <= 3.2.48 Patched in 3.2.49
  48. 2022-08-02 CVE-2022-36288 Cross-Site Request Forgery (CSRF) Affects <= 3.2.48 Patched in 3.2.49
  49. 2022-08-01 CVE-2022-2362 Authentication Bypass by Spoofing Affects <= 3.2.49 Patched in 3.2.50
  50. 2022-07-27 CVE-2022-2431 Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') Affects <= 3.2.50 Patched in 3.2.51
  51. 2022-07-06 CVE-2022-34658 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') Affects <= 3.2.48 Patched in 3.2.49
  52. 2022-06-27 CVE-2022-2168 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') Affects <= 3.2.43 Patched in 3.2.44
  53. 2022-06-23 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') Affects <= 3.2.43 Patched in 3.2.44
  54. 2022-06-21 CVE-2022-2101 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') Affects <= 3.2.46 Patched in 3.2.47
  55. 2022-06-02 CVE-2022-1985 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') Affects <= 3.2.42 Patched in 3.2.43
  56. 2022-03-16 CVE-2022-0828 Inadequate Encryption Strength Affects < 3.2.39 Patched in 3.2.39
  57. 2022-02-02 CVE-2021-25087 Improper Access Control Affects < 3.2.35 Patched in 3.2.35
  58. 2022-01-20 CVE-2021-25069 Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') Affects < 3.2.34 Patched in 3.2.34
  59. 2021-11-29 CVE-2021-24969 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') Affects < 3.2.22 Patched in 3.2.22
  60. 2021-09-29 CVE-2021-24773 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') Affects < 3.2.16 Patched in 3.2.16
  61. 2021-08-09 Cross-Site Request Forgery (CSRF) Affects < 3.2.13 Patched in 3.2.13
  62. 2021-07-29 CVE-2021-34639 Unrestricted Upload of File with Dangerous Type Affects <= 3.1.24 Patched in 3.1.25
  63. 2021-07-29 CVE-2021-34638 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') Affects <= 3.1.24 Patched in 3.1.25
  64. 2021-04-30 Cross-Site Request Forgery (CSRF) Affects < 3.1.22 Patched in 3.1.22
  65. 2021-04-30 Missing Authorization Affects < 3.1.23 Patched in 3.1.23
  66. 2021-04-30 Unrestricted Upload of File with Dangerous Type Affects < 3.1.19 Patched in 3.1.19
  67. 2021-04-16 Missing Authorization Affects < 3.1.18 Patched in 3.1.18
  68. 2019-06-16 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') Affects < 2.9.97 Patched in 2.9.97
  69. 2019-04-13 CVE-2019-15889 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') Affects < 2.9.94 Patched in 2.9.94
  70. 2018-01-09 Cross-Site Request Forgery (CSRF) Affects <= 2.9.6 Patched in 2.9.61
  71. 2017-07-13 CVE-2017-2217 URL Redirection to Untrusted Site ('Open Redirect') Affects < 2.9.51 Patched in 2.9.51
  72. 2017-06-16 CVE-2017-18032 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') Affects <= 2.9.51 Patched in 2.9.52
  73. 2017-06-13 CVE-2017-2216 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') Affects < 2.9.50 Patched in 2.9.50
  74. 2017-03-01 Cross-Site Request Forgery (CSRF) Affects <= 2.9.45 Patched in 2.9.46
  75. 2016-01-19 Exposure of Sensitive Information to an Unauthorized Actor Affects < 2.8.8 Patched in 2.8.8
  76. 2016-01-19 Improper Privilege Management Affects < 2.8.8 Patched in 2.8.8
  77. 2016-01-19 Missing Authorization Affects < 2.8.8 Patched in 2.8.8
  78. 2015-07-16 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') Affects <= 2.7.94 Patched in 2.7.95
  79. 2014-12-15 Improper Control of Generation of Code ('Code Injection') Affects < 2.7.5 Patched in 2.7.5
  80. 2014-11-24 CVE-2014-9260 Missing Authorization Affects < 2.7.3 Patched in 2.7.3
  81. 2014-08-01 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') Affects <= 2.2.2 Patched in 2.2.3
  82. 2013-12-08 CVE-2013-7319 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') Affects <= 2.5.8 Patched in 2.5.9
  83. 2013-12-07 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') Affects <= 2.5.8 Patched in 2.5.9

Vulnerability records provided by Wordfence Intelligence. Copyright 2012-2026 Defiant Inc. License and terms.

CVE records: Copyright 1999-2026 The MITRE Corporation. CVE terms of use.

Behavioral tests

via WP Hive

Automated install-time checks, tested on PHP 8.1.12 · WP 7.0.1

Low memory footprint
Low page-speed impact
Runs on latest PHP + WP
No PHP errors
No JS errors
Activates cleanly
No resource errors
No external HTTP errors
Optimized database use
Frequently updated

Languages

via translate.wordpress.org

Translated into 39 languages, 3 at 90% or more

Dutch 100%
Dutch (Formal) 100%
English (UK) 98%
French (France) 85%
Japanese 67%
Russian 64%
Swedish 60%
Polish 59%
Italian 58%
Spanish (Spain) 56%
Spanish (Chile) 54%
Ukrainian 51%
Catalan 50%
Spanish (Ecuador) 50%
Spanish (Venezuela) 50%
Greek 49%
Spanish (Colombia) 49%
Korean 48%
German (Formal) 44%
German 37%
Spanish (Mexico) 37%
Hungarian 36%
Norwegian (Bokmål) 35%
Chinese (China) 31%

Plus 15 more locales with partial translations.

Growth timeline

Install-tier crossings we have observed, and how long each tier took to outgrow

No tier crossings observed yet.

Competes with

The plugins that solve the same job, ranked by shared tags then reach, closest match first. The letter on the right is each plugin's health grade (A best, F worst).

Compare head to head →

Embed this report card

Drop a live Pulse card for Download Manager into a readme, a review or a deck. It updates itself.

<iframe src="https://plugins.wpmayor.com/embed/download-manager" width="480" height="300" style="border:0" loading="lazy" title="Download Manager — Plugin Pulse"></iframe>
Preview card ↗

Download Manager: 100K+ active installs, 4.1★ (1,006 reviews). Plugin Pulse (WP Mayor), as of 2026-08-25. https://plugins.wpmayor.com/plugin/download-manager