BBA Secure File Downloads

Changelog

1.0.7

  • Security: Validate the download nonce before touching any other request input.
  • Security: Add clear permission hooks for download authorization.
  • Compliance: Document raw/binary output in the download endpoint for scanners.

1.0.2

  • Fix: Plugin Check compliance (admin enqueue without direct $_GET access, readme headers).

1.0.1

  • Fix: add nonce to download links and validate in handler.
  • Fix: use WP_Filesystem for file reads (Plugin Check compliance).
  • Fix: wp_unslash() before sanitization for request values.
  • Fix: translators comment for placeholder strings.
  • Meta: bump Tested up to.

1.0.0

  • Initial release: Files UI, Settings, How to Use, Help/About, shortcode, and secure download endpoint.

Plugin Website
Visit website

Version:
1.0.7
Last Updated
March 8, 2026
Requires
WordPress 5.8
Tested Up To
WordPress 6.9.1
Requires PHP
7.0

Share Post

Join our newsletter.

Get insights into what’s happening at ChangelogWP right in your inbox. We don’t believe in spam.