Acumbamail Security & Risk Analysis

wordpress.org/plugins/acumbamail-signup-forms

Show your Acumbamail signup forms easily in your Wordpress pages through a widget.

1K active installs v2.0.26 PHP 7.4+ WP 4.7+ Updated Dec 1, 2025
acumbamailemail-marketingmailing
99
A · Safe
CVEs total1
Unpatched0
Last CVEApr 30, 2014
Safety Verdict

Is Acumbamail Safe to Use in 2026?

Generally Safe

Score 99/100

Acumbamail has a strong security track record. Known vulnerabilities have been patched promptly.

1 known CVELast CVE: Apr 30, 2014Updated 4mo ago
Risk Assessment

The acumbamail-signup-forms plugin v2.0.26 exhibits a generally good security posture with several positive indicators. The static analysis reveals a very small attack surface with only one AJAX handler, and importantly, this handler appears to be protected by authentication checks. The plugin demonstrates strong SQL hygiene, with all queries utilizing prepared statements, and a high percentage of output is properly escaped, which helps mitigate cross-site scripting (XSS) vulnerabilities. The absence of critical or high-severity taint flows further supports a robust security design in this version.

However, the plugin's history includes one high-severity "Exposure of Sensitive Information to an Unauthorized Actor" vulnerability, albeit from a very old date (2014). While there are currently no unpatched vulnerabilities, this past incident warrants consideration. The presence of an external HTTP request, while not inherently a vulnerability, could be a potential vector if the external service were compromised or if the request itself handled data insecurely. The limited number of nonce and capability checks, while functional for the identified entry points, could suggest a less comprehensive security implementation in areas not directly covered by static analysis.

In conclusion, acumbamail-signup-forms v2.0.26 appears to be a secure plugin in its current state, with strong adherence to fundamental WordPress security practices. The small attack surface, proper SQL usage, and output escaping are significant strengths. The past high-severity vulnerability, though old, serves as a reminder for continued vigilance. Future development should maintain these good practices and consider expanding security checks if the plugin's functionality grows to expose more potential attack vectors.

Key Concerns

  • Past high severity vulnerability
  • External HTTP request present
  • Limited nonce/capability checks
Vulnerabilities
1

Acumbamail Security Vulnerabilities

CVEs by Year

1 CVE in 2014
2014
Patched Has unpatched

Severity Breakdown

High
1

1 total CVE

WF-e8efc5cf-3497-4426-a8a5-740783a7c2c9-acumbamail-signup-formshigh · 7.5Exposure of Sensitive Information to an Unauthorized Actor

Acumbamail < 1.0.4.1 - Sensitive Information Disclosure

Apr 30, 2014 Patched in 1.0.4.1 (3555d)
Code Analysis
Analyzed Mar 16, 2026

Acumbamail Code Analysis

Dangerous Functions
0
Raw SQL Queries
0
0 prepared
Unescaped Output
9
69 escaped
Nonce Checks
2
Capability Checks
1
File Operations
0
External Requests
1
Bundled Libraries
0

Output Escaping

88% escaped78 total outputs
Attack Surface

Acumbamail Attack Surface

Entry Points1
Unprotected0

AJAX Handlers 1

authwp_ajax_action_update_state_cartacumbamail.php:60
WordPress Hooks 20
actioninitacumbamail.php:28
actionadmin_menuacumbamail.php:29
actionadmin_initacumbamail.php:30
actionwidgets_initacumbamail.php:31
actionbefore_woocommerce_initacumbamail.php:33
actionwoocommerce_initacumbamail.php:39
filterwoocommerce_checkout_fieldsacumbamail.php:41
actionwoocommerce_checkout_update_order_metaacumbamail.php:42
actionwoocommerce_order_status_processingacumbamail.php:43
actionwoocommerce_store_api_checkout_update_order_from_requestacumbamail.php:46
actionwoocommerce_add_to_cartacumbamail.php:49
actionwoocommerce_cart_item_removedacumbamail.php:50
actionwoocommerce_cart_item_set_quantityacumbamail.php:51
actionwoocommerce_new_orderacumbamail.php:52
actionwoocommerce_payment_completeacumbamail.php:53
actionwp_loginacumbamail.php:55
actiontemplate_redirectacumbamail.php:56
actionwoocommerce_thankyouacumbamail.php:57
actionadmin_noticesacumbamail.php:312
actionadmin_noticesacumbamail.php:444
Maintenance & Trust

Acumbamail Maintenance & Trust

Maintenance Signals

WordPress version tested6.8.5
Last updatedDec 1, 2025
PHP min version7.4
Downloads28K

Community Trust

Rating100/100
Number of ratings1
Active installs1K
Developer Profile

Acumbamail Developer Profile

Acumbamail

1 plugin · 1K total installs

78
trust score
Avg Security Score
99/100
Avg Patch Time
3555 days
View full developer profile
Detection Fingerprints

How We Detect Acumbamail

Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.

Asset Fingerprints

Asset Paths
/wp-content/plugins/acumbamail-signup-forms/css/acumbamail.css/wp-content/plugins/acumbamail-signup-forms/js/acumbamail.js
Script Paths
/wp-content/plugins/acumbamail-signup-forms/js/acumbamail.js
Version Parameters
acumbamail-signup-forms/css/acumbamail.css?ver=acumbamail-signup-forms/js/acumbamail.js?ver=

HTML / DOM Fingerprints

CSS Classes
acumbamail-signup-form
Data Attributes
data-acumbamail-form-iddata-acumbamail-form-hash
JS Globals
acumbamail_form_data
REST Endpoints
/wp-json/acumbamail/v1/forms
Shortcode Output
[acumbamail-form]
FAQ

Frequently Asked Questions about Acumbamail