ACF: MadMimi Audience List Security & Risk Analysis

wordpress.org/plugins/acf-madmimi-audience-list

A field for Advanced Custom Fields which allows you to select one or more of your MadMimi audience lists

10 active installs v1.0.2 PHP + WP 3.4+ Updated Jan 11, 2016
acfcustom-fields
85
A · Safe
CVEs total0
Unpatched0
Last CVENever
Safety Verdict

Is ACF: MadMimi Audience List Safe to Use in 2026?

Generally Safe

Score 85/100

ACF: MadMimi Audience List has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.

No known CVEs Updated 10yr ago
Risk Assessment

The "acf-madmimi-audience-list" plugin v1.0.2 exhibits a generally good security posture with no known vulnerabilities and a limited attack surface. The static analysis reveals a complete absence of dangerous functions, external HTTP requests, file operations, and SQL queries that aren't using prepared statements. This indicates a solid foundation in secure coding practices regarding these critical areas. However, a significant concern arises from the output escaping, where only 47% of outputs are properly escaped. This leaves a notable portion of data potentially vulnerable to cross-site scripting (XSS) attacks if user-supplied data is rendered directly without sufficient sanitization. Additionally, the taint analysis identified two flows with unsanitized paths. While these did not result in critical or high severity findings, they represent potential weaknesses where malicious input could traverse through the code without proper sanitization, possibly leading to unexpected behavior or further vulnerabilities if combined with other factors.

Despite the absence of past CVEs, which is a positive indicator of historical security, the current static analysis highlights areas requiring attention. The lack of nonce checks and capability checks on all entry points, though there are currently zero unprotected entry points, means that if new entry points were introduced in future versions without proper security controls, the plugin could become vulnerable. The limited attack surface is a strength, but the identified issues with output escaping and taint flows suggest that a deeper review and remediation are necessary to ensure a truly robust security profile.

Key Concerns

  • Low output escaping percentage
  • Taint flow with unsanitized path (x2)
  • No nonce checks on entry points
  • No capability checks on entry points
Vulnerabilities
None known

ACF: MadMimi Audience List Security Vulnerabilities

No known vulnerabilities — this is a good sign.
Code Analysis
Analyzed Mar 17, 2026

ACF: MadMimi Audience List Code Analysis

Dangerous Functions
0
Raw SQL Queries
0
0 prepared
Unescaped Output
9
8 escaped
Nonce Checks
0
Capability Checks
0
File Operations
0
External Requests
0
Bundled Libraries
0

Output Escaping

47% escaped17 total outputs
Data Flows
2 unsanitized

Data Flow Analysis

2 flows2 with unsanitized paths
mal_settings_page_content (acf-madmimi_audience_list.php:110)
Source (user input) Sink (dangerous op) Sanitizer Transform Unsanitized Sanitized
Attack Surface

ACF: MadMimi Audience List Attack Surface

Entry Points0
Unprotected0
WordPress Hooks 4
actionadmin_menuacf-madmimi_audience_list.php:64
actionadmin_initacf-madmimi_audience_list.php:80
actionacf/include_field_typesacf-madmimi_audience_list.php:174
actionacf/register_fieldsacf-madmimi_audience_list.php:186
Maintenance & Trust

ACF: MadMimi Audience List Maintenance & Trust

Maintenance Signals

WordPress version tested4.3.34
Last updatedJan 11, 2016
PHP min version
Downloads2K

Community Trust

Rating0/100
Number of ratings0
Active installs10
Developer Profile

ACF: MadMimi Audience List Developer Profile

danielpataki

12 plugins · 7K total installs

83
trust score
Avg Security Score
84/100
Avg Patch Time
30 days
View full developer profile
Detection Fingerprints

How We Detect ACF: MadMimi Audience List

Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.

Asset Fingerprints

Asset Paths
/wp-content/plugins/acf-madmimi-audience-list/acf-madmimi_audience_list-v5.php/wp-content/plugins/acf-madmimi-audience-list/acf-madmimi_audience_list-v4.php/wp-content/plugins/acf-madmimi-audience-list/lang/

HTML / DOM Fingerprints

FAQ

Frequently Asked Questions about ACF: MadMimi Audience List