Plugin Pulse
← Pulse

Download Monitor

by WP Chill · eCommerce

Also makes 27 other plugins · 405.8K+ installs across the portfolio →

Powerful Download Manager Plugin for WordPress

How scoring works →
94 Health · A
Maintenance 100/100
Rating quality 89/100
Support 92/100

94 health vs 68 average across 5,561 eCommerce plugins

Directory ranking optimization

How it's scored →

How well this listing is tuned to rank in WordPress.org search, on the factors an owner controls. Not popularity, optimization.

96 / 100

Excellent listing optimization

Well tuned across the board

Update recency 100/100
WP compatibility 100/100
Rating quality 89/100
Listing tuning 100/100
Support resolution 88/100

Daily downloads

Since 2022-10-05 · 1,421 days · wp.org + Plugin Pulse archive

-40% vs prior 30d
0Downloads · Aug 26

30-day downloads

Rolling 30-day volume · peaks are release surges

82.4K

now · peak 208.8K

82.8K30d downloads · Aug 26

Directory rank vs rivals

wp.org popularity rank over time · higher is better · when a rival's line climbs above yours, they've overtaken you

Download Monitor · #512 you Download Manager · #458 Download Manager Add · #2821 Easy Digital Downloa · #852

Rating trend

Star average over time · dips mark rough releases

4.5Stars · Aug 26

Update activity

How busy the existing users are, measured as downloads in the last 30 days for every 1,000 active sites. A spike means a new release everyone's pulling; a long, slow decline means an aging user base that updates less.

1Kper 1k installs · Aug 26

Release cadence

Actively maintained
from wp.org release tags

How often this plugin actually ships. A steady rhythm is the maintenance signal a single "last updated" date can't show.

23

releases in the last 12 months

1mo ago

latest release · v5.2.5

197

tagged releases on record

Recent releases

5.2.5 · 1mo ago5.2.4 · 1mo ago5.2.3 · 1mo ago5.2.2 · 2mo ago5.2.1 · 2mo ago5.2.0 · 2mo ago5.1.16 · 3mo ago5.1.15 · 3mo ago5.1.14 · 4mo ago5.1.13 · 4mo ago5.1.12 · 5mo ago5.1.11 · 5mo ago5.1.10 · 6mo ago5.1.9 · 6mo ago

What its installed base runs

via wordpress.org

Share of active installs on each version of this plugin · 42% run the current release. Green is the current release; a big slice on older versions is a user base that has stopped updating.

v5.2 42%
v5.1 25%
v5.0 10%
v4.4 7.3%
Older / other versions 15%

Estimated active installs

The public count shows “80K+”. Our estimate pins where the real number sits.

tracked estimate
80K–90K ≈87K

Refined from the date this plugin crossed into its current band.

Install history · since 2015-03-10 · 1,491 observations

80KInstalls · Aug 26

Estimated value

What this plugin might earn a year, and what it might sell for. Modeled from public signals; we don't see anyone's books.

Est. annual revenue

N/A

Est. acquisition value

N/A

No paid tier is visible, so we don't put a figure on revenue or sale value: that would be guessing. The install base is a real asset to an acquirer, just not one public data lets us price. A declining trend compresses what a buyer would pay.

Details

Version
5.2.7
Last updated
11d ago
Added
2008-03-12 · 18 yrs old
Requires WP
6.4
Tested up to
7.0.4
Requires PHP
7.4

Latest updates

via wp.org changelog

Recent releases and news for this plugin

  1. Version 5.2.5 Fixed: Download loading indicator styling. Added: The download_data shortcode now supports custom meta fields. 5.2.5
  2. Version 5.2.4 Fixed: Frontend CSS is now always loaded on frontend pages. 5.2.4
  3. Version 5.2.3 Fixed: Default download template link rendering inside lists. 5.2.3
  4. Version 5.2.2 Changed: Title and Filename download templates restored to default link styling. Fixed: Terms & Conditions download behavior and admin list quick edit checkbox. 5.2.2
  5. Version 5.2.1 Improved: File browser modal updated. Fixed: Downloads widget chart on the dashboard showing incorrect data. Fixed: Download title sometimes displayed incorrectly on the Reports page. Fixed: PHP notice shown on some admi 5.2.1
  6. Version 5.2.0 Changed: Improved frontend CSS class naming to avoid conflicts with other plugins. Added: Filter to show extra version fields in the download editor. Fixed: PHP warning related to session handling on hosts with open_base 5.2.0

Known vulnerabilities

via Wordfence Intelligence

30 disclosed vulnerabilities on record for this plugin, all fixed in the current version. Sites on older versions stay exposed until they update.

  1. 2026-08-03 CVE-2026-16608 Missing Authorization Affects <= 5.2.5 Patched in 5.2.6
  2. 2026-04-20 CVE-2026-39489 Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') Affects <= 5.1.9 Patched in 5.1.10
  3. 2026-04-07 CVE-2026-4401 Cross-Site Request Forgery (CSRF) Affects <= 5.1.10 Patched in 5.1.11
  4. 2026-03-29 CVE-2026-3124 Authorization Bypass Through User-Controlled Key Affects <= 5.1.7 Patched in 5.1.8
  5. 2026-03-25 CVE-2026-39486 Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') Affects <= 5.1.8 Patched in 5.1.9
  6. 2025-05-07 CVE-2025-47439 Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') Affects <= 5.0.22 Patched in 5.0.23
  7. 2024-10-29 CVE-2024-10399 Missing Authorization Affects <= 5.0.13 Patched in 5.0.14
  8. 2024-10-25 CVE-2024-10092 Missing Authorization Affects <= 5.0.12 Patched in 5.0.13
  9. 2024-09-25 CVE-2024-8552 Missing Authorization Affects <= 5.0.9 Patched in 5.0.10
  10. 2024-05-29 CVE-2024-3269 Improper Authorization Affects <= 4.9.13 Patched in 4.9.14
  11. 2024-01-08 CVE-2024-30501 Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') Affects < 4.9.5 Patched in 4.9.5
  12. 2023-06-07 CVE-2023-34007 Unrestricted Upload of File with Dangerous Type Affects < 4.8.4 Patched in 4.8.4
  13. 2023-05-30 CVE-2023-31219 Server-Side Request Forgery (SSRF) Affects <= 4.8.1 Patched in 4.8.2
  14. 2023-05-10 CVE-2022-45354 Missing Authorization Affects <= 4.7.60 Patched in 4.7.70
  15. 2022-11-26 CVE-2022-4972 Missing Authorization Affects <= 4.7.51 Patched in 4.7.52
  16. 2022-11-01 Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') Affects <= 4.7.2 Patched in 4.7.3
  17. 2022-09-19 CVE-2022-2981 Files or Directories Accessible to External Parties Affects <= 4.5.97 Patched in 4.5.98
  18. 2022-06-27 CVE-2022-2222 Files or Directories Accessible to External Parties Affects <= 4.5.9 Patched in 4.5.91
  19. 2021-10-29 CVE-2021-36920 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') Affects <= 4.4.6 Patched in 4.4.7
  20. 2021-10-29 CVE-2021-31567 Files or Directories Accessible to External Parties Affects <= 4.4.6 Patched in 4.4.7
  21. 2021-10-29 CVE-2021-23174 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') Affects <= 4.4.6 Patched in 4.4.7
  22. 2021-10-20 CVE-2021-24786 Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') Affects < 4.4.5 Patched in 4.4.5
  23. 2017-05-05 Missing Authorization Affects <= 1.9.6 Patched in 1.9.7
  24. 2015-04-20 CVE-2015-9296 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') Affects < 1.7.1 Patched in 1.7.1
  25. 2015-04-20 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') Affects < 1.6.5 Patched in 1.6.5
  26. 2015-03-08 Exposure of Sensitive Information to an Unauthorized Actor Affects <= 1.6.3 Patched in 1.6.4
  27. 2013-07-23 CVE-2013-5098 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') Affects < 3.3.6.2 Patched in 3.3.6.2
  28. 2013-07-22 CVE-2013-3262 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') Affects < 3.3.6.2 Patched in 3.3.6.2
  29. 2012-09-06 CVE-2012-4768 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') Affects <= 3.3.5.8 Patched in 3.3.5.9
  30. 2008-04-28 CVE-2008-2034 Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') Affects <= 2.0.6 Patched in 2.0.9

Vulnerability records provided by Wordfence Intelligence. Copyright 2012-2026 Defiant Inc. License and terms.

CVE records: Copyright 1999-2026 The MITRE Corporation. CVE terms of use.

Behavioral tests

via WP Hive

Automated install-time checks, tested on PHP 8.1.12 · WP 7.0.1

Low memory footprint
Low page-speed impact
Runs on latest PHP + WP
No PHP errors
No JS errors
Activates cleanly
No resource errors
No external HTTP errors
Optimized database use
Frequently updated

Languages

via translate.wordpress.org

Translated into 57 languages, 4 at 90% or more

Polish 98%
Dutch 95%
Dutch (Formal) 94%
Croatian 90%
Spanish (Chile) 89%
Russian 87%
Spanish (Spain) 79%
French (France) 71%
Swedish 71%
Romanian 61%
Japanese 60%
Danish 56%
Chinese (China) 55%
German 55%
Afrikaans 52%
Ukrainian 52%
Persian 50%
German (Formal) 18%
Hungarian 17%
Italian 16%
Finnish 14%
Portuguese (Brazil) 14%
Portuguese (Portugal) 14%
Czech 13%

Plus 33 more locales with partial translations.

Growth timeline

Install-tier crossings we have observed, and how long each tier took to outgrow

  1. 2026-05-08 90K+ → 80K+ down after 663 days in tier
  2. 2024-07-14 100K+ → 90K+ down

Competes with

The plugins that solve the same job, ranked by shared tags then reach, closest match first. The letter on the right is each plugin's health grade (A best, F worst).

Compare head to head →

Embed this report card

Drop a live Pulse card for Download Monitor into a readme, a review or a deck. It updates itself.

<iframe src="https://plugins.wpmayor.com/embed/download-monitor" width="480" height="300" style="border:0" loading="lazy" title="Download Monitor — Plugin Pulse"></iframe>
Preview card ↗

Download Monitor: 80K+ active installs, 4.5★ (524 reviews). Plugin Pulse (WP Mayor), as of 2026-08-25. https://plugins.wpmayor.com/plugin/download-monitor