AcyMailing integration for Business Directory Security & Risk Analysis

wordpress.org/plugins/acymailing-integration-for-business-directory

Add listings from Business Directory to your emails.

0 active installs v3.3 PHP + WP + Updated Feb 26, 2026
acymailingbusinessintegrationnewsletter
100
A · Safe
CVEs total0
Unpatched0
Last CVENever
Download
Safety Verdict

Is AcyMailing integration for Business Directory Safe to Use in 2026?

Generally Safe

Score 100/100

AcyMailing integration for Business Directory has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.

No known CVEs Updated 1mo ago
Risk Assessment

The "acymailing-integration-for-business-directory" plugin v3.3 exhibits a strong security posture in several key areas. The static analysis reveals no exposed AJAX handlers, REST API routes, shortcodes, or cron events without proper authentication or permission checks, indicating a well-secured attack surface. Furthermore, all SQL queries are properly prepared, and all output is correctly escaped, mitigating common injection and XSS vulnerabilities. The absence of file operations and external HTTP requests also limits potential attack vectors.

However, a significant concern arises from the presence of the `unserialize` function without any apparent sanitization or context provided in the static analysis. This is a well-known risk for remote code execution (RCE) if the serialized data originates from an untrusted source. The lack of nonce checks and capability checks on entry points, while the attack surface is reported as zero without auth, is a minor concern as it suggests these checks might be handled by the core integration or a hypothetical later stage not reflected in this snapshot. The plugin's vulnerability history is clean, with no recorded CVEs, which is a positive sign of its stability and security over time. This suggests the developers have a good track record, but the identified `unserialize` risk remains a critical potential weakness that needs immediate attention.

In conclusion, while the plugin demonstrates excellent practices in preventing common web vulnerabilities and maintains a clean history, the sole identified dangerous function, `unserialize`, represents a notable security risk. Addressing this specific function with proper input validation and sanitization is paramount to ensuring the plugin's overall security. The strengths in attack surface management and SQL/output escaping are commendable, but this single critical flaw demands a focused remediation effort.

Key Concerns

  • Dangerous function 'unserialize' used
  • Missing nonce checks
  • Missing capability checks
Vulnerabilities
None known

AcyMailing integration for Business Directory Security Vulnerabilities

No known vulnerabilities — this is a good sign.
Code Analysis
Analyzed Mar 17, 2026

AcyMailing integration for Business Directory Code Analysis

Dangerous Functions
1
Raw SQL Queries
0
0 prepared
Unescaped Output
0
11 escaped
Nonce Checks
0
Capability Checks
0
File Operations
0
External Requests
0
Bundled Libraries
0

Dangerous Functions Found

unserialize$this->wpbdpFields[$key]->field_data = unserialize($oneField->field_data);BusinessDirectoryInsertion.php:224

Output Escaping

100% escaped11 total outputs
Attack Surface

AcyMailing integration for Business Directory Attack Surface

Entry Points0
Unprotected0
WordPress Hooks 1
actionacym_load_installed_integrationsacymailing-businessdirectory.php:26
Maintenance & Trust

AcyMailing integration for Business Directory Maintenance & Trust

Maintenance Signals

WordPress version tested6.9.4
Last updatedFeb 26, 2026
PHP min version
Downloads3K

Community Trust

Rating0/100
Number of ratings0
Active installs0
Developer Profile

AcyMailing integration for Business Directory Developer Profile

AcyMailing Newsletter Team

20 plugins · 8K total installs

79
trust score
Avg Security Score
100/100
Avg Patch Time
298 days
View full developer profile
Detection Fingerprints

How We Detect AcyMailing integration for Business Directory

Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.

Asset Fingerprints

Asset Paths
/wp-content/plugins/acymailing-integration-for-business-directory/assets/css/acymailing-business-directory.css/wp-content/plugins/acymailing-integration-for-business-directory/assets/js/acymailing-business-directory.js
Script Paths
/wp-content/plugins/acymailing-integration-for-business-directory/assets/js/acymailing-business-directory.js
Version Parameters
acymailing-integration-for-business-directory/assets/css/acymailing-business-directory.css?ver=acymailing-integration-for-business-directory/assets/js/acymailing-business-directory.js?ver=

HTML / DOM Fingerprints

CSS Classes
acymailing_content
Data Attributes
data-acymailing-namedata-acymailing-type
JS Globals
window.pluginHelper
Shortcode Output
[acy_business_directory_listing][acy_business_directory_item]
FAQ

Frequently Asked Questions about AcyMailing integration for Business Directory