Skip to content
Updated today

← Can you vibe-code it?

Can You Vibe-Code Download Monitor?

Kinda Low confidence

Real-world usage 79.7K+ live sites #43 by usage View plugin details →
from $69/yr What it costs
A weekend To get an MVP working
~8 h/yr To keep it alive, forever
60% Of it is just code

What you’re actually buying

60% code you could commission 40% somebody running something

You could build: Files behind a post type, download counting, versioned files and a shortcode. Genuinely straightforward, and the free plugin already does it.

What you’d still be missing: The paid half is gating and abuse: email-gated downloads wired to your mailing list, bot and hotlink defence that does not also block real users, and per-user access rules. Useful, but a smaller gap than most of this index.

Maintenance Support Integrations

Is it worth building?

About 6 hours to get a working version (a weekend), then roughly 8 hours a year keeping it alive. So year one is about 14 hours of your time — both figures assume you’re using an agent for the maintenance too, not just the build.

Against $69 a year for the licence. At $50/hour that’s $700 of your time in year one — so it pays off once you run it on about 11 sites, because the licence is per site and your build isn’t.

11 sites — break even +$818/yr $0 -$631/yr 1 11 22 sites you'd run it on (maintenance at $50/hr)
If your time is worth Year one Each year after Sites to break even
$25/hr $350 $200 6
$50/hr $700 $400 11
$100/hr $1,400 $800 21
$150/hr $2,100 $1,200 31

Year one only, and it assumes the 40% above is worth nothing to you. That is the assumption most likely to be wrong — read the “still missing” line again before you decide.

The prompt

A starting point, not a magic spell. Expect to iterate — and to be told what it skipped.

Starter prompt
Build a self-contained WordPress plugin that covers the core of Download Monitor. I want a working first version I can install and test, not a scaffold.

Requirements:
- Download post type with versioning and access logging
- Gated downloads collecting an email into your mailing list
- Bot, hotlink and abuse protection on the download endpoint
- Per-role or per-member access restriction
- Reporting on downloads over time

Constraints:
- Plain PHP against the WordPress APIs. No build step, no framework, no Composer runtime dependencies.
- Follow WordPress coding standards. Prefix every global function, class and option.
- Escape on output, sanitise on input, nonce + capability check every write. Prepare every SQL query.
- Translation-ready with a single text domain.
- Uninstall routine that removes options and tables it created.
- Target the current WordPress and PHP 8.1+.

Deliver: the plugin files, a short README covering setup and limitations, and an explicit list of what you did NOT implement.

Context for scope: the paid product is from $69/yr. Do not try to match it feature for feature — build the part I would actually use, and tell me where the gap is.

Don’t feel like building it?

Free or open-source, finished, and already doing the job.

0 people say they built this instead

Self-reported and unverified — one tap per person, roughly. Treat it as a mood ring, not a statistic.

Why this list exists

“Can I just vibe-code this?” has become a reasonable question to ask before renewing a licence. For most SaaS the answer is a straight yes or no. For WordPress plugins it usually isn’t, because a premium licence is rarely paying for source code alone.

Ask an agent for a security plugin and you’ll get a firewall and a file scanner in an afternoon. What you won’t get is the rule that shipped this morning for the vulnerability disclosed last night — that’s a research team, and it’s the entire reason the product works. Ask for a caching plugin and you’ll get page caching, minification and lazy-loading. What you won’t get is the eight years of exclusion rules that stop it breaking somebody’s checkout.

So instead of a verdict, every plugin above is split in two: the share an agent could plausibly build for you, and the share that only exists because a vendor is running something on an ongoing basis — a live data feed, servers doing the work, a legal review, or an integration matrix kept alive against other companies’ breaking changes.

How to read the score

The percentage is the answer to one question: what would you still be missing the day after the agent finished? A low score means the product really is mostly code, and building it yourself is a fair trade. A high score means you’d finish the build and still need to buy the thing that made it useful.

The baseline is one competent developer with a good agent and a couple of weekends — not a team, and not a year. Scores are editorial judgement rather than measurement, and they’re deliberately arguable. If you think a call is wrong, that’s the interesting conversation.

Ranking, prices and live-site counts come from the same daily data as the rest of the site — see the premium plugin ranking for how those are gathered.