Download Monitor
by WP Chill · eCommerce
Also makes 27 other plugins · 405.8K+ installs across the portfolio →
Powerful Download Manager Plugin for WordPress
94 health vs 68 average across 5,561 eCommerce plugins
Directory ranking optimization
How it's scored →How well this listing is tuned to rank in WordPress.org search, on the factors an owner controls. Not popularity, optimization.
Excellent listing optimization
Well tuned across the board
Daily downloads
Since 2022-10-05 · 1,421 days · wp.org + Plugin Pulse archive
30-day downloads
Rolling 30-day volume · peaks are release surges
82.4K
now · peak 208.8K
Directory rank vs rivals
wp.org popularity rank over time · higher is better · when a rival's line climbs above yours, they've overtaken you
Rating trend
Star average over time · dips mark rough releases
Update activity
How busy the existing users are, measured as downloads in the last 30 days for every 1,000 active sites. A spike means a new release everyone's pulling; a long, slow decline means an aging user base that updates less.
Release cadence
Actively maintainedHow often this plugin actually ships. A steady rhythm is the maintenance signal a single "last updated" date can't show.
23
releases in the last 12 months
1mo ago
latest release · v5.2.5
197
tagged releases on record
Recent releases
What its installed base runs
via wordpress.orgShare of active installs on each version of this plugin · 42% run the current release. Green is the current release; a big slice on older versions is a user base that has stopped updating.
Estimated active installs
The public count shows “80K+”. Our estimate pins where the real number sits.
Refined from the date this plugin crossed into its current band.
Install history · since 2015-03-10 · 1,491 observations
Estimated value
What this plugin might earn a year, and what it might sell for. Modeled from public signals; we don't see anyone's books.
Est. annual revenue
Est. acquisition value
No paid tier is visible, so we don't put a figure on revenue or sale value: that would be guessing. The install base is a real asset to an acquirer, just not one public data lets us price. A declining trend compresses what a buyer would pay.
Details
Latest updates
via wp.org changelogRecent releases and news for this plugin
- — Version 5.2.5 Fixed: Download loading indicator styling. Added: The download_data shortcode now supports custom meta fields. 5.2.5
- — Version 5.2.4 Fixed: Frontend CSS is now always loaded on frontend pages. 5.2.4
- — Version 5.2.3 Fixed: Default download template link rendering inside lists. 5.2.3
- — Version 5.2.2 Changed: Title and Filename download templates restored to default link styling. Fixed: Terms & Conditions download behavior and admin list quick edit checkbox. 5.2.2
- — Version 5.2.1 Improved: File browser modal updated. Fixed: Downloads widget chart on the dashboard showing incorrect data. Fixed: Download title sometimes displayed incorrectly on the Reports page. Fixed: PHP notice shown on some admi 5.2.1
- — Version 5.2.0 Changed: Improved frontend CSS class naming to avoid conflicts with other plugins. Added: Filter to show extra version fields in the download editor. Fixed: PHP warning related to session handling on hosts with open_base 5.2.0
Known vulnerabilities
via Wordfence Intelligence30 disclosed vulnerabilities on record for this plugin, all fixed in the current version. Sites on older versions stay exposed until they update.
- Medium · 5.3 Download Monitor <= 5.2.5 - Missing Authorization ↗
- 2026-04-20 CVE-2026-39489 Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') Affects <= 5.1.9 Patched in 5.1.10
- 2026-03-29 CVE-2026-3124 Authorization Bypass Through User-Controlled Key Affects <= 5.1.7 Patched in 5.1.8
- 2026-03-25 CVE-2026-39486 Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') Affects <= 5.1.8 Patched in 5.1.9
- 2025-05-07 CVE-2025-47439 Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') Affects <= 5.0.22 Patched in 5.0.23
- Medium · 5.4 Download Monitor <= 4.9.13 - Missing Authorization ↗
- 2024-01-08 CVE-2024-30501 Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') Affects < 4.9.5 Patched in 4.9.5
- High · 8.8 Download Monitor <= 4.8.3 - Authenticated(Subscriber+) Arbitrary File Upload via upload_file ↗2023-06-07 CVE-2023-34007 Unrestricted Upload of File with Dangerous Type Affects < 4.8.4 Patched in 4.8.4
- Medium · 4.9 Download Monitor <= 4.7.2 - Authenticated Directory Traversal to Sensitive Information Exposure ↗2022-11-01 Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') Affects <= 4.7.2 Patched in 4.7.3
- 2022-09-19 CVE-2022-2981 Files or Directories Accessible to External Parties Affects <= 4.5.97 Patched in 4.5.98
- 2022-06-27 CVE-2022-2222 Files or Directories Accessible to External Parties Affects <= 4.5.9 Patched in 4.5.91
- 2021-10-29 CVE-2021-36920 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') Affects <= 4.4.6 Patched in 4.4.7
- 2021-10-29 CVE-2021-31567 Files or Directories Accessible to External Parties Affects <= 4.4.6 Patched in 4.4.7
- 2021-10-29 CVE-2021-23174 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') Affects <= 4.4.6 Patched in 4.4.7
- 2021-10-20 CVE-2021-24786 Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') Affects < 4.4.5 Patched in 4.4.5
- Medium · 6.5 Download Monitor <= 1.9.6 - Missing Authorization ↗2017-05-05 Missing Authorization Affects <= 1.9.6 Patched in 1.9.7
- 2015-04-20 CVE-2015-9296 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') Affects < 1.7.1 Patched in 1.7.1
- 2015-04-20 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') Affects < 1.6.5 Patched in 1.6.5
- 2015-03-08 Exposure of Sensitive Information to an Unauthorized Actor Affects <= 1.6.3 Patched in 1.6.4
- 2013-07-23 CVE-2013-5098 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') Affects < 3.3.6.2 Patched in 3.3.6.2
- 2013-07-22 CVE-2013-3262 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') Affects < 3.3.6.2 Patched in 3.3.6.2
- 2012-09-06 CVE-2012-4768 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') Affects <= 3.3.5.8 Patched in 3.3.5.9
- Critical · 9.8 Download Monitor <= 2.0.6 - Unauthenticated SQL Injection ↗2008-04-28 CVE-2008-2034 Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') Affects <= 2.0.6 Patched in 2.0.9
Vulnerability records provided by Wordfence Intelligence. Copyright 2012-2026 Defiant Inc. License and terms.
CVE records: Copyright 1999-2026 The MITRE Corporation. CVE terms of use.
Behavioral tests
via WP HiveAutomated install-time checks, tested on PHP 8.1.12 · WP 7.0.1
Languages
via translate.wordpress.orgTranslated into 57 languages, 4 at 90% or more
Plus 33 more locales with partial translations.
Growth timeline
Install-tier crossings we have observed, and how long each tier took to outgrow
- 2026-05-08 90K+ → 80K+ down after 663 days in tier
- 2024-07-14 100K+ → 90K+ down
Competes with
The plugins that solve the same job, ranked by shared tags then reach, closest match first. The letter on the right is each plugin's health grade (A best, F worst).
-
Download Manager 100K+ installs · 4.1★ · 4 shared tags A -
Download Manager Addons for Elementor 6K+ installs · 3.4★ · 3 shared tags B -
Easy Digital Downloads – eCommerce Payments and Subscriptions made easy 40K+ installs · 4.7★ · 2 shared tags A
-
Document Library Lite 4K+ installs · 3.9★ · 2 shared tags B -
Shared Files – File Upload & Download Manager 4K+ installs · 4.3★ · 2 shared tags A
-
Lana Downloads Manager 3K+ installs · 4.5★ · 2 shared tags B
Embed this report card
Drop a live Pulse card for Download Monitor into a readme, a review or a deck. It updates itself.
<iframe src="https://plugins.wpmayor.com/embed/download-monitor" width="480" height="300" style="border:0" loading="lazy" title="Download Monitor — Plugin Pulse"></iframe> Download Monitor: 80K+ active installs, 4.5★ (524 reviews). Plugin Pulse (WP Mayor), as of 2026-08-25. https://plugins.wpmayor.com/plugin/download-monitor