AffiliateWP MailChimp Add-On Security & Risk Analysis

wordpress.org/plugins/affiliatewp-mailchimp-add-on

AffiliateWP MailChimp Add-on adds a newsletter signup checkbox to your AffiliateWP affiliates sign up page.

30 active installs v1.2.0 PHP + WP 4.4+ Updated Oct 31, 2018
affiliate-wpaffiliatewpmailchimpnigeriatubiz-plugins
85
A · Safe
CVEs total0
Unpatched0
Last CVENever
Safety Verdict

Is AffiliateWP MailChimp Add-On Safe to Use in 2026?

Generally Safe

Score 85/100

AffiliateWP MailChimp Add-On has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.

No known CVEs Updated 7yr ago
Risk Assessment

The affiliatewp-mailchimp-add-on v1.2.0 plugin exhibits a generally good security posture based on the provided static analysis. The absence of identified dangerous functions, raw SQL queries, file operations, and taint analysis findings suggests careful coding practices regarding core security vulnerabilities. Furthermore, the plugin has no recorded vulnerability history, indicating a lack of past exploitation or discovery of significant flaws. The plugin also demonstrates an absence of direct entry points like AJAX handlers, REST API routes, or shortcodes that are often targeted by attackers. However, there are areas for concern that prevent an entirely clean bill of health. The low percentage of properly escaped output (44%) is a significant weakness, potentially exposing the plugin to cross-site scripting (XSS) vulnerabilities if user-supplied data is not handled securely before being displayed. The lack of nonce checks and capability checks on any identified (though absent in this analysis) potential entry points is also a concern, as these are fundamental WordPress security mechanisms.

Key Concerns

  • Low percentage of properly escaped output
  • No nonce checks implemented
  • No capability checks implemented
Vulnerabilities
None known

AffiliateWP MailChimp Add-On Security Vulnerabilities

No known vulnerabilities — this is a good sign.
Version History

AffiliateWP MailChimp Add-On Release Timeline

v1.2.0Current
v1.1.0
v1.0.6
v1.0.5
v1.0.4
v1.0.3
v1.0.2
v1.0.1
v1.0.0
Code Analysis
Analyzed Apr 16, 2026

AffiliateWP MailChimp Add-On Code Analysis

Dangerous Functions
0
Raw SQL Queries
0
0 prepared
Unescaped Output
5
4 escaped
Nonce Checks
0
Capability Checks
0
File Operations
0
External Requests
1
Bundled Libraries
0

Output Escaping

44% escaped9 total outputs
Attack Surface

AffiliateWP MailChimp Add-On Attack Surface

Entry Points0
Unprotected0
WordPress Hooks 10
actionadmin_initaffiliatewp-mailchimp-addon.php:31
filteraffwp_settings_integrationsaffiliatewp-mailchimp-addon.php:32
actionaffwp_register_useraffiliatewp-mailchimp-addon.php:33
actionaffwp_new_affiliate_endaffiliatewp-mailchimp-addon.php:37
actionaffwp_insert_affiliateaffiliatewp-mailchimp-addon.php:38
actionaffwp_register_fields_before_tosaffiliatewp-mailchimp-addon.php:42
actionaffwp_affiliate_dashboard_before_submitaffiliatewp-mailchimp-addon.php:43
actionaffwp_update_affiliate_profile_settingsaffiliatewp-mailchimp-addon.php:44
actionadmin_noticesaffiliatewp-mailchimp-addon.php:56
actionplugins_loadedaffiliatewp-mailchimp-addon.php:529
Maintenance & Trust

AffiliateWP MailChimp Add-On Maintenance & Trust

Maintenance Signals

WordPress version tested4.9.29
Last updatedOct 31, 2018
PHP min version
Downloads7K

Community Trust

Rating100/100
Number of ratings2
Active installs30
Developer Profile

AffiliateWP MailChimp Add-On Developer Profile

Tunbosun Ayinla

11 plugins · 33K total installs

87
trust score
Avg Security Score
90/100
Avg Patch Time
30 days
View full developer profile
Detection Fingerprints

How We Detect AffiliateWP MailChimp Add-On

Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.

Asset Fingerprints

Asset Paths
/wp-content/plugins/affiliatewp-mailchimp-add-on/css/admin.css/wp-content/plugins/affiliatewp-mailchimp-add-on/js/admin.js
Version Parameters
/wp-content/plugins/affiliatewp-mailchimp-add-on/css/admin.css?ver=/wp-content/plugins/affiliatewp-mailchimp-add-on/js/admin.js?ver=

HTML / DOM Fingerprints

Data Attributes
name="affwp_mailchimp_subscribe"id="affwp_mailchimp_subscribe"name="affwp_mailchimp_api_key"id="affwp_mailchimp_api_key"
FAQ

Frequently Asked Questions about AffiliateWP MailChimp Add-On