Affiliates Manager MailChimp Integration Security & Risk Analysis

wordpress.org/plugins/affiliates-manager-mailchimp-integration

An addon for the Affiliates Manager plugin to signup the affiliates to your MailChimp list

100 active installs v1.0.1 PHP 5.3+ WP 3.8+ Updated Jan 21, 2025
autoresponderemailmailchimpoptinsignup
92
A · Safe
CVEs total0
Unpatched0
Last CVENever
Safety Verdict

Is Affiliates Manager MailChimp Integration Safe to Use in 2026?

Generally Safe

Score 92/100

Affiliates Manager MailChimp Integration has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.

No known CVEs Updated 1yr ago
Risk Assessment

The "affiliates-manager-mailchimp-integration" v1.0.1 plugin exhibits a generally good security posture based on the provided static analysis, with no known CVEs and a minimal attack surface. The absence of AJAX handlers, REST API routes, shortcodes, and cron events with missing authentication checks is a significant strength. The plugin also avoids dangerous functions and file operations, and does not make external HTTP requests, further limiting potential attack vectors. All SQL queries are reported as using prepared statements, which is excellent practice.

However, a critical concern arises from the taint analysis, which indicates two flows with unsanitized paths. This suggests that data processed by the plugin might not be properly validated or cleaned before being used, potentially leading to vulnerabilities like cross-site scripting (XSS) or other injection attacks, even if the specific impact is not classified as critical or high in this analysis. The most significant weakness lies in the complete lack of output escaping. With two outputs analyzed and 0% properly escaped, there is a high probability of reflected or stored XSS vulnerabilities being present. The absence of nonce and capability checks on any potential entry points, while the attack surface is currently reported as zero, leaves the plugin vulnerable if new entry points are introduced in the future without these security measures.

Given the lack of historical vulnerabilities, the plugin has likely been maintained with security in mind. However, the identified taint flows and the absolute absence of output escaping are significant red flags. The plugin's strengths in minimizing attack surface and using prepared statements are commendable, but these are overshadowed by the immediate risks of unsanitized data and unescaped output. A cautious approach is recommended when using this plugin until these issues are addressed.

Key Concerns

  • Unsanitized paths in taint analysis
  • Output escaping: 0% properly escaped
  • No nonce checks
  • No capability checks
Vulnerabilities
None known

Affiliates Manager MailChimp Integration Security Vulnerabilities

No known vulnerabilities — this is a good sign.
Code Analysis
Analyzed Mar 16, 2026

Affiliates Manager MailChimp Integration Code Analysis

Dangerous Functions
0
Raw SQL Queries
0
0 prepared
Unescaped Output
2
0 escaped
Nonce Checks
0
Capability Checks
0
File Operations
0
External Requests
0
Bundled Libraries
0

Output Escaping

0% escaped2 total outputs
Data Flows
2 unsanitized

Data Flow Analysis

2 flows2 with unsanitized paths
wpam_mc_admin_interface (affmgr-mailchimp-admin-menu.php:9)
Source (user input) Sink (dangerous op) Sanitizer Transform Unsanitized Sanitized
Attack Surface

Affiliates Manager MailChimp Integration Attack Surface

Entry Points0
Unprotected0
WordPress Hooks 2
actionwpam_front_end_registration_form_submittedaffmgr-mailchimp-action.php:5
actionwpam_after_main_admin_menuaffmgr-mailchimp-admin-menu.php:3
Maintenance & Trust

Affiliates Manager MailChimp Integration Maintenance & Trust

Maintenance Signals

WordPress version tested6.7.5
Last updatedJan 21, 2025
PHP min version5.3
Downloads7K

Community Trust

Rating80/100
Number of ratings1
Active installs100
Developer Profile

Affiliates Manager MailChimp Integration Developer Profile

wp.insider

14 plugins · 76K total installs

76
trust score
Avg Security Score
95/100
Avg Patch Time
556 days
View full developer profile
Detection Fingerprints

How We Detect Affiliates Manager MailChimp Integration

Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.

Asset Fingerprints

Asset Paths
/wp-content/plugins/affiliates-manager-mailchimp-integration/affmgr-mailchimp-admin-menu.php/wp-content/plugins/affiliates-manager-mailchimp-integration/affmgr-mailchimp-action.php
Version Parameters
affiliates-manager-mailchimp-integration/affmgr-mailchimp-admin-menu.php?ver=1.0.1affiliates-manager-mailchimp-integration/affmgr-mailchimp-action.php?ver=1.0.1

HTML / DOM Fingerprints

FAQ

Frequently Asked Questions about Affiliates Manager MailChimp Integration