Plugin Pulse
← Pulse

Hide Real Download Path

by Deepak S · Uncategorized

Also makes 1 other plugin · 120+ installs across the portfolio →

This plugin help to hide real download path of your files on server and allow file downloading using a common URL. Also maintain log of your downloads …

⚠ Stale⚠ Likely abandoned
How scoring works →
43 Health · D
Maintenance 3/100
Rating quality 70/100
Support 70/100

43 health vs 56 average across 16,377 Uncategorized plugins

High removal-risk signals

63/100

Maintenance and integrity signals that tend to precede a WordPress.org removal. Not an official status, a heads-up to act.

  • Long abandoned. No update in 11+ years — the top precursor to removal once a vulnerability is found.
  • Compatibility drift. Tested only up to WordPress 4.0.38, well behind 6.8.

Directory ranking optimization

How it's scored →

How well this listing is tuned to rank in WordPress.org search, on the factors an owner controls. Not popularity, optimization.

40 / 100

Under-optimized

Biggest win: Update recency

Update recency 0/100
WP compatibility 3/100
Rating quality 66/100
Listing tuning 100/100

To rank higher: Last updated 4333 days ago — ship an update; wp.org decays a listing's search weight after ~180 days.

Get the full rank-higher report →

Daily downloads

Since 2022-10-05 · 1,426 days · wp.org + Plugin Pulse archive

+17% vs prior 30d
1Downloads · Aug 26

30-day downloads

Rolling 30-day volume · peaks are release surges

75

now · peak 149

7530d downloads · Aug 26

Directory rank

wp.org popularity rank over time · lower is better

16.7KRank · Jul 26

Update activity

How busy the existing users are, measured as downloads in the last 30 days for every 1,000 active sites. A spike means a new release everyone's pulling; a long, slow decline means an aging user base that updates less.

833per 1k installs · Aug 26

What its installed base runs

via wordpress.org

Share of active installs on each version of this plugin · 100% run the current release. Green is the current release; a big slice on older versions is a user base that has stopped updating.

v1.6 100%

Estimated active installs

The public count shows “90+”. Our estimate pins where the real number sits.

modeled estimate
90–100 ≈97

Modeled within the band wp.org reports; tightens as we track daily.

Install history · since 2022-10-04 · 1,385 observations

90Installs · Aug 26

Estimated value

What this plugin might earn a year, and what it might sell for. Modeled from public signals; we don't see anyone's books.

Est. annual revenue

N/A

Est. acquisition value

N/A

No paid tier is visible, so we don't put a figure on revenue or sale value: that would be guessing. The install base is a real asset to an acquirer, just not one public data lets us price. A small install base leaves thin data to model from.

Details

Version
1.6
Last updated
11.9y ago
Added
2013-01-15 · 13 yrs old
Requires WP
3.5
Tested up to
4.0.38
Requires PHP

Recent reviews

All reviews on wp.org ↗
  1. priljayme
    9.2y ago

    Yes, this plugin is still working on version 4.8 (though it lacks clear usage instructions). Thanks! I created a topic on the support regarding the step-by-step guide https://wordpress.org/support/topic/step-by-step-guide-4/ This topic was modified 9 years ago by priljayme.

    Read on wp.org ↗
  2. priljayme
    9.2y ago

    Yes, still working on version 4.8 Although it lacks clear usage, but since the author did put effort so I’ll offer my own step-by-step version so that others can appreciate it as well (after activating plugin): 1. Create ANY folder on your hosting server using FTP or cpanel File Manager (I created mine inside /wp-content/uploads/ folder). e.g. “downloads” 2. After activating plugin, go to Settings > Hide Download Link 3. Copy the directory highlighted on the “Root path on your server is” e.g. /home/server/public_html/ 4. Paste it on the “Base Dir:” text box then add the directory where you created your folder. Now, my full “Base Dir:” is: /home/server/public_html/wp-content/uploads/downloads/ 5. Keep “Log Downloads” checked 6. Click to Save Settings (Nevermind any error) 7. Upload your downloadable file on your “Base Dir” (or on your created folder) Let’s say my file is “plugin-download.zip” The REAL full url of my file is /home/server/public_html/wp-content/uploads/downloads/plugin-download.zip 8. Create new post/page for your “plugin-download.zip” Download Page Let’s say I named it “Download Page of Plugin” with slug “download-page-plugin” 9. On that page, you don’t have to write anything EXCEPT for the shortcode [download_page] 10. Save & Publish that Page Now, the url of that page will be: http://website.com/download-page-plugin/ 11. Create ANOTHER new post/page. This time, I created my Thank You Page. I named it “Thank You Plugin Download” with slug “thank-you-page-plugin” 12. On the content, I included a thank you message plus the PLUGIN-SECURED download link. e.g. Thank you for downloading my plugin. Click HERE to download the plugin NOTE: “http://website.com/download-page-plugin/” is the URL of the first created page; “?f=” is the required query for the URL; and lastly “plugin-download.zip” is the file name of the uploaded file. 13. Save & Publish that Page Now, the url of that page will be: http://website.com/thank-you-page-plugin/ 14. To test if everything is working, go to the recently created page; “http://website.com/thank-you-page-plugin/” and check the download link. Once you click the link, the downloadable file should now be accessible.

    Read on wp.org ↗
  3. BiomeDigital
    10.4y ago

    not clear instructions. I had to search for the short code then it didn’t work.

    Read on wp.org ↗
  4. lalejon
    10.5y ago

    It works smoothly and integrated within any external player or audio tag. The real path of mp3 file is coded, although external or browser audio players works fine. Nice work Deepak!

    Read on wp.org ↗
  5. Abhi
    10.5y ago

    This plugin works beautifully. I’d like to thank Deepak for making this plugin. There are however a few directions that you should follow. Don’t forget to create a page titled “download” & put this shortcode there ‘[download_page]’ Most of the bad reviews I read are by people who have no idea what they’re doing. A little bit of WP knowledge & access from server side (since you need to create a folder in wp-content as well) this plugin works like a charm. Thanks again to the developer.

    Read on wp.org ↗
  6. Andrea
    10.8y ago

    …but remember to set your “real download path” every (!) time, the plugin is updated or re-activated. So it´s still working under WP 4.9.x Alternative for some bucks (and more complicated): https://codecanyon.net/item/wp-one-time-file-download-unique-link-generator-wordpress-plugin/21871469 This topic was modified 9 years, 8 months ago by Andrea. This topic was modified 8 years, 1 month ago by Andrea. This topic was modified 8 years, 1 month ago by Andrea. This topic was modified 8 years, 1 month ago by Andrea. This topic was modified 8 years, 1 month ago by Andrea.

    Read on wp.org ↗
  7. yorcht
    11.3y ago

    poor support

    Read on wp.org ↗
  8. Social Chic
    11.9y ago

    Hide Real Download Path is lightweight, doesn’t slow the site down, and does a PERFECT job of redirects. Efficient, and makes a wysiwig out of adding code to htaccess. Love it — solved everything. And the developer support is second to none — Deepak solved the issues I had w/in 7 hours! Best plugin of its kind.

    Read on wp.org ↗

Known vulnerabilities

via Wordfence Intelligence

1 disclosed vulnerability on record for this plugin, 1 still affects the current version.

  1. 2025-09-05 CVE-2025-58849 Cross-Site Request Forgery (CSRF) Affects <= 1.6 No patch available

Vulnerability records provided by Wordfence Intelligence. Copyright 2012-2026 Defiant Inc. License and terms.

CVE records: Copyright 1999-2026 The MITRE Corporation. CVE terms of use.

Behavioral tests

via WP Hive

Automated install-time checks, tested on PHP 7.2.16 · WP 5.2.4

Low memory footprint
Low page-speed impact
Runs on latest PHP + WP
No PHP errors
No JS errors
Activates cleanly
No resource errors
No external HTTP errors
Optimized database use
Frequently updated

Growth timeline

Install-tier crossings we have observed, and how long each tier took to outgrow

  1. 2026-08-31 100+ → 90+ down after 1213 days in tier
  2. 2023-05-06 200+ → 100+ down

Embed this report card

Drop a live Pulse card for Hide Real Download Path into a readme, a review or a deck. It updates itself.

<iframe src="https://plugins.wpmayor.com/embed/hide-real-download-path" width="480" height="300" style="border:0" loading="lazy" title="Hide Real Download Path — Plugin Pulse"></iframe>
Preview card ↗

Hide Real Download Path: 90+ active installs, 3.8★ (14 reviews). Plugin Pulse (WP Mayor), as of 2026-08-31. https://plugins.wpmayor.com/plugin/hide-real-download-path