Download Manager
by Shahjada · eCommerce
Also makes 5 other plugins · 113.1K+ installs across the portfolio →
This File Management & Digital Store plugin will help you to control file downloads & sell digital products from your WP site.
85 health vs 68 average across 5,561 eCommerce plugins
Directory ranking optimization
How it's scored →How well this listing is tuned to rank in WordPress.org search, on the factors an owner controls. Not popularity, optimization.
Excellent listing optimization
Biggest win: Support resolution
To rank higher: Mark more forum threads resolved — the resolved ratio feeds the ranking.
Get the full rank-higher report →Daily downloads
Since 2022-10-05 · 1,421 days · wp.org + Plugin Pulse archive
30-day downloads
Rolling 30-day volume · peaks are release surges
88.1K
now · peak 271.5K
Directory rank vs rivals
wp.org popularity rank over time · higher is better · when a rival's line climbs above yours, they've overtaken you
Rating trend
Star average over time · dips mark rough releases
Update activity
How busy the existing users are, measured as downloads in the last 30 days for every 1,000 active sites. A spike means a new release everyone's pulling; a long, slow decline means an aging user base that updates less.
Release cadence
Actively maintainedHow often this plugin actually ships. A steady rhythm is the maintenance signal a single "last updated" date can't show.
45
releases in the last 12 months
1mo ago
latest release · v3.3.66
173
tagged releases on record
Recent releases
What its installed base runs
via wordpress.orgShare of active installs on each version of this plugin · 72% run the current release. Green is the current release; a big slice on older versions is a user base that has stopped updating.
Estimated active installs
The public count shows “100K+”. Our estimate pins where the real number sits.
Modeled within the band wp.org reports; tightens as we track daily.
Install history · since 2015-03-10 · 1,494 observations
Estimated value
What this plugin might earn a year, and what it might sell for. Modeled from public signals; we don't see anyone's books.
Est. annual revenue
Est. acquisition value
No paid tier is visible, so we don't put a figure on revenue or sale value: that would be guessing. The install base is a real asset to an acquirer, just not one public data lets us price. A declining trend compresses what a buyer would pay.
Details
Recent review vibe
read from the latest 12 reviews to 2026-07-13Reviewers keep praising the support team by name and say the plugin covers what they need, with one asking for a translation module and flagging the new Glassmorphism Card theme for slowing page loads.
Recent reviews
All reviews on wp.org ↗- ★★★★★ promise5211mo ago
For a few days now, I have been dealing with Tahasin, due to problems on my site. This brother has been great. Keep it up brother. I wish I could rate your service 10 stars. thanks again Download Manager. You are a great company to work with.
Read on wp.org ↗ - ★★★★★ gorkova3mo ago
Very kind and hardworking people, and the helpful support is excellent and very efficient.
Read on wp.org ↗ - ★★★★★ Fred4mo ago
Great plugin and excellent support!
Read on wp.org ↗ - ★★★★★ purepixels4mo ago
This plugin is perfect. It improved a lot over the last few years. We use it already for almost 10 years and we’ve seen the whole product and interface improve over the years. Everything you might need from a download manager is in there. And, if you ever run into issues or you have questions, the support (via chat and email) is very quick to help you out. We love this plugin. The Pro version is highly recommended !
Read on wp.org ↗ - ★★★★★ jds2mpo5mo ago
Great Support on a few occasions
Read on wp.org ↗ - ★★★★★ Furkan Özden5mo ago
Eklenti harika. Çeviri kısmının incelenmesi gerek. Örneğin page-template-default.php içinde [txt=Download][download_count]yer alan kısımda hata var. [txt=Download] yazması lazım. Kendi Türkçe çevirinizi yapabiliyorsunuz. Keşke sisteme yükleyip kullanıcılarla ilerleyen bir çeviri modülü olsa. Bu şekiled her güncelleme sonrası yedek aldığım çeviri dosyasını yüklemem gerekiyor. Son güncelleme ile eklenen Glassmorphism Card teması sayfa yükleme hızını büyük ölçüde yavaşlatıyor. Bulunan temalar yeterliydi.
Read on wp.org ↗ - ★★★★★ cesare13605mo ago
RISOLTO…Uaoooo….!!!Innanzitutto complimenti perché siete velocissimi a rispondere.Vi ringrazio vivamente per avermi illuminato sull’errore che stavo facendo e quindi di configurare bene le chiavi. Io mi sono perso sulle varie soluzioni che ti propone la console di google mentre era tutto molto più semplice.Siete unici! Siete avanti!!!
Read on wp.org ↗ - ★★★★★ vickyh6mo ago
I’m using the free version of the plugin and have had a couple of issues recently. I posted my question on their forum and on both occasions they came back really quickly with answers and solutions. Very impressed with this level of support, especially as I’m only using the free version.
Read on wp.org ↗
Latest updates
via wp.org changelogRecent releases and news for this plugin
- — Version 3.3.66 Security: Author+ Stored Cross-Site Scripting via Package Title – the title was run through stripcslashes() when rendered, which decoded C-style escape sequences back into active markup after save-time sanitization had a 3.3.66
- — Version 3.3.65 Fixed: The [wpdm_changelog] shortcode rendered unstyled, because its markup was emitted without the wrapper element that the front-end stylesheet scopes every changelog rule to 3.3.65
- — Version 3.3.64 Fixed: The [changelog] template tag rendered unstyled, because the front-end stylesheet still targeted an older markup structure – entry content was hidden outright, the timeline had no layout and the icons rendered at t 3.3.64
- — Version 3.3.63 New: Activity Reports – scheduled weekly or monthly summary emails covering downloads, top packages, trending items, user activity, category breakdown and storage usage, with configurable sections, recipients, schedule a 3.3.63
- — Version 3.3.62 Improved: Expirable download link handling Improved: Emailed and shareable download links are now kept in a durable, indexed store instead of post meta, so they survive cache clears and no longer bloat package meta Impro 3.3.62
- — Version 3.3.61 Fixed: Authenticated (Contributor+) Stored Cross-Site Scripting via the no_data_msg attribute of the wpdm_all_packages shortcode ( Reported by Wordfence ) 3.3.61
Known vulnerabilities
via Wordfence Intelligence83 disclosed vulnerabilities on record for this plugin, all fixed in the current version. Sites on older versions stay exposed until they update.
- 2026-08-05 CVE-2026-14292 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') Affects < 3.3.66 Patched in 3.3.66
- 2026-07-31 CVE-2026-16685 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') Affects <= 3.3.66 Patched in 3.3.67
- 2026-07-08 CVE-2026-14343 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') Affects <= 3.3.61 Patched in 3.3.62
- 2026-06-30 CVE-2026-13733 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') Affects <= 3.3.60 Patched in 3.3.61
- Medium · 6.4 Download Manager <= 3.3.52 - Authenticated (Contributor+) Stored Cross-Site Scripting via Shortcode Attributes ↗2026-04-08 CVE-2026-5357 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') Affects <= 3.3.52 Patched in 3.3.53
- 2026-03-18 CVE-2026-2571 Exposure of Sensitive Information to an Unauthorized Actor Affects <= 3.3.49 Patched in 3.3.50
- Medium · 5.3 Download Manager <= 3.3.52 - Missing Authorization ↗
- Medium · 6.1 Download Manager <= 3.3.46 - Reflected Cross-Site Scripting via 'redirect_to' Parameter ↗2026-02-17 CVE-2026-1666 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') Affects <= 3.3.46 Patched in 3.3.47
- 2026-02-10 CVE-2026-39615 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') Affects <= 3.3.53 Patched in 3.3.54
- 2025-09-30 CVE-2025-63070 Exposure of Sensitive Information to an Unauthorized Actor Affects <= 3.3.32 Patched in 3.3.33
- 2025-09-26 CVE-2025-60092 Exposure of Sensitive Information to an Unauthorized Actor Affects <= 3.3.25 Patched in 3.3.26
- 2025-09-18 CVE-2025-10146 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') Affects <= 3.3.23 Patched in 3.3.24
- Medium · 6.4 Download Manager <= 3.3.18 - Authenticated (Author+) Stored Cross-site Scripting via wpdm_user_dashboard Shortcode ↗2025-06-18 CVE-2025-4367 Improper Neutralization of Script-Related HTML Tags in a Web Page (Basic XSS) Affects <= 3.3.18 Patched in 3.3.19
- 2025-04-18 CVE-2025-3404 Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') Affects <= 3.3.12 Patched in 3.3.13
- Medium · 5.4 Download Manager <= 3.3.12 - Authenticated (Author+) Stored Cross-Site Scripting via SVG File Upload ↗2025-04-17 CVE-2025-3056 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') Affects <= 3.3.12 Patched in 3.3.13
- Medium · 5.4 Download Manager <= 3.3.08 - Authenticated (Author+) Path Traversal to Limited File Overwrite ↗2025-03-12 CVE-2025-1785 Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') Affects <= 3.3.08 Patched in 3.3.09
- Medium · 5.3 Download Manager <= 3.3.06 - Unauthenticated Information Disclosure via Unprotected Directory ↗2025-01-17 CVE-2024-13126 Files or Directories Accessible to External Parties Affects <= 3.3.06 Patched in 3.3.07
- Medium · 4.3 Download Manager <= 3.3.03 - Missing Authorization ↗
- 2024-12-18 CVE-2024-11740 Improper Control of Generation of Code ('Code Injection') Affects <= 3.3.03 Patched in 3.3.04
- 2024-11-29 CVE-2024-10706 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') Affects <= 3.3.02 Patched in 3.3.03
- Medium · 6.4 Download Manager <= 3.2.99 - Authenticated (Contributor+) Stored Cross-Site Scripting ↗2024-10-09 CVE-2024-8444 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') Affects <= 3.2.99 Patched in 3.3.00
- 2024-09-23 CVE-2024-8284 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') Affects <= 3.2.98 Patched in 3.2.99
- Medium · 6.4 Download Manager <= 3.2.97 - Authenticated (Contributor+) Stored Cross-Site Scripting via Shortcode ↗2024-07-30 CVE-2024-6208 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') Affects <= 3.2.97 Patched in 3.2.98
- 2024-06-12 CVE-2024-2098 Authentication Bypass by Alternate Name Affects <= 3.2.89 Patched in 3.2.90
- Medium · 6.4 Download Manager <= 3.2.92 - Authenticated (Author+) Stored Cross-Site Scripting via Multiple Shortcodes ↗2024-06-11 CVE-2024-5266 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') Affects <= 3.2.92 Patched in 3.2.94
- Medium · 4.4 Download Manager <= 3.2.86 - Authenticated (Subscriber+) Stored Self-Based Cross-Site Scripting ↗2024-06-11 CVE-2024-1766 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') Affects <= 3.2.86 Patched in 3.2.87
- 2024-06-04 CVE-2024-4001 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') Affects <= 3.2.93 Patched in 3.2.94
- 2024-05-30 CVE-2024-4160 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') Affects <= 3.2.90 Patched in 3.2.91
- Medium · 6.4 Download Manager <= 3.2.84 - Authenticated (Contributor+) Stored Cross-Site Scripting ↗2024-03-16 CVE-2024-29114 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') Affects <= 3.2.84 Patched in 3.2.85
- Medium · 6.4 Download Manager <= 3.2.85 - Authenticated (Contributor+) Stored Cross-Site Scripting via Shortcode ↗2024-02-28 CVE-2023-6954 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') Affects <= 3.2.85 Patched in 3.2.86
- Medium · 5.3 Download Manager <= 3.2.84 - Missing Authorization ↗
- Medium · 6.4 Download Manager <= 3.2.70 - Authenticated (Contributor+) Stored Cross-Site Scripting via Shortcode ↗2023-05-12 CVE-2023-2305 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') Affects <= 3.2.70 Patched in 3.2.71
- 2023-04-10 CVE-2023-1809 Exposure of Sensitive Information to an Unauthorized Actor Affects 4.0 - 6.3.0 Patched in 6.3.0
- Medium · 6.4 Download Manager <= 3.2.61 - Authenticated (Contributor+) Stored Cross-Site Scripting ↗2022-12-20 CVE-2022-4476 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') Affects <= 3.2.61 Patched in 3.2.62
- 2022-11-29 CVE-2022-45836 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') Affects <= 3.2.59 Patched in 3.2.60
- 2022-09-05 CVE-2022-2926 Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') Affects < 3.2.55 Patched in 3.2.55
- 2022-08-04 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') Affects <= 3.2.53 Patched in 3.2.54
- Medium · 5.3 Download Manager <= 3.2.49 - IP Blocking Bypass ↗
- 2022-07-27 CVE-2022-2431 Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') Affects <= 3.2.50 Patched in 3.2.51
- Medium · 5.4 Download Manager <= 3.2.48 - Authenticated (Contributor+) Stored Cross-Site Scripting ↗2022-07-06 CVE-2022-34658 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') Affects <= 3.2.48 Patched in 3.2.49
- 2022-06-27 CVE-2022-2168 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') Affects <= 3.2.43 Patched in 3.2.44
- 2022-06-23 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') Affects <= 3.2.43 Patched in 3.2.44
- 2022-06-21 CVE-2022-2101 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') Affects <= 3.2.46 Patched in 3.2.47
- 2022-06-02 CVE-2022-1985 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') Affects <= 3.2.42 Patched in 3.2.43
- 2022-01-20 CVE-2021-25069 Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') Affects < 3.2.34 Patched in 3.2.34
- 2021-11-29 CVE-2021-24969 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') Affects < 3.2.22 Patched in 3.2.22
- 2021-09-29 CVE-2021-24773 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') Affects < 3.2.16 Patched in 3.2.16
- 2021-08-09 Cross-Site Request Forgery (CSRF) Affects < 3.2.13 Patched in 3.2.13
- 2021-07-29 CVE-2021-34639 Unrestricted Upload of File with Dangerous Type Affects <= 3.1.24 Patched in 3.1.25
- 2021-07-29 CVE-2021-34638 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') Affects <= 3.1.24 Patched in 3.1.25
- 2021-04-30 Cross-Site Request Forgery (CSRF) Affects < 3.1.22 Patched in 3.1.22
- 2021-04-30 Missing Authorization Affects < 3.1.23 Patched in 3.1.23
- 2021-04-30 Unrestricted Upload of File with Dangerous Type Affects < 3.1.19 Patched in 3.1.19
- Medium · 5.3 Download Manager <= 3.1.17 - Missing Authorization ↗2021-04-16 Missing Authorization Affects < 3.1.18 Patched in 3.1.18
- 2019-06-16 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') Affects < 2.9.97 Patched in 2.9.97
- 2019-04-13 CVE-2019-15889 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') Affects < 2.9.94 Patched in 2.9.94
- 2018-01-09 Cross-Site Request Forgery (CSRF) Affects <= 2.9.6 Patched in 2.9.61
- 2017-07-13 CVE-2017-2217 URL Redirection to Untrusted Site ('Open Redirect') Affects < 2.9.51 Patched in 2.9.51
- 2017-06-16 CVE-2017-18032 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') Affects <= 2.9.51 Patched in 2.9.52
- 2017-06-13 CVE-2017-2216 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') Affects < 2.9.50 Patched in 2.9.50
- 2017-03-01 Cross-Site Request Forgery (CSRF) Affects <= 2.9.45 Patched in 2.9.46
- 2016-01-19 Exposure of Sensitive Information to an Unauthorized Actor Affects < 2.8.8 Patched in 2.8.8
- Medium · 6.5 Download Manager <= 2.8.7 - Privilege Escalation ↗2016-01-19 Improper Privilege Management Affects < 2.8.8 Patched in 2.8.8
- Critical · 9.1 Download Manager <= 2.8.7 - Missing Authorization ↗2016-01-19 Missing Authorization Affects < 2.8.8 Patched in 2.8.8
- 2015-07-16 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') Affects <= 2.7.94 Patched in 2.7.95
- 2014-12-15 Improper Control of Generation of Code ('Code Injection') Affects < 2.7.5 Patched in 2.7.5
- Medium · 6.1 Download Manager <= 2.2.2 - Cross-Site Scripting ↗2014-08-01 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') Affects <= 2.2.2 Patched in 2.2.3
- 2013-12-08 CVE-2013-7319 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') Affects <= 2.5.8 Patched in 2.5.9
- Medium · 5.3 Download Manager <= 2.5.8 - Cross-Site Scripting ↗2013-12-07 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') Affects <= 2.5.8 Patched in 2.5.9
Vulnerability records provided by Wordfence Intelligence. Copyright 2012-2026 Defiant Inc. License and terms.
CVE records: Copyright 1999-2026 The MITRE Corporation. CVE terms of use.
Behavioral tests
via WP HiveAutomated install-time checks, tested on PHP 8.1.12 · WP 7.0.1
Languages
via translate.wordpress.orgTranslated into 39 languages, 3 at 90% or more
Plus 15 more locales with partial translations.
Growth timeline
Install-tier crossings we have observed, and how long each tier took to outgrow
No tier crossings observed yet.
Competes with
The plugins that solve the same job, ranked by shared tags then reach, closest match first. The letter on the right is each plugin's health grade (A best, F worst).
-
Download Monitor 80K+ installs · 4.5★ · 4 shared tags A -
Download Manager Addons for Elementor 6K+ installs · 3.4★ · 4 shared tags B -
Document Library Lite 4K+ installs · 3.9★ · 3 shared tags B -
Advanced File Manager – Ultimate File Manager for WordPress And Document Library Solution 100K+ installs · 4.8★ · 2 shared tags A -
Easy Digital Downloads – eCommerce Payments and Subscriptions made easy 40K+ installs · 4.7★ · 2 shared tags A
-
Shared Files – File Upload & Download Manager 4K+ installs · 4.3★ · 2 shared tags A
Embed this report card
Drop a live Pulse card for Download Manager into a readme, a review or a deck. It updates itself.
<iframe src="https://plugins.wpmayor.com/embed/download-manager" width="480" height="300" style="border:0" loading="lazy" title="Download Manager — Plugin Pulse"></iframe> Download Manager: 100K+ active installs, 4.1★ (1,006 reviews). Plugin Pulse (WP Mayor), as of 2026-08-25. https://plugins.wpmayor.com/plugin/download-manager