ChimpBridge – Create and Send Mailchimp Campaigns in WordPress Security & Risk Analysis

wordpress.org/plugins/chimpbridge

Create and send Mailchimp Campaigns right inside of the WordPress admin.

40 active installs v1.2.5 PHP 7.4+ WP 4.1+ Updated Feb 26, 2026
campaignmailchimpmailchimp-integrationmailchimp-sendingnewsletter
100
A · Safe
CVEs total0
Unpatched0
Last CVENever
Safety Verdict

Is ChimpBridge – Create and Send Mailchimp Campaigns in WordPress Safe to Use in 2026?

Generally Safe

Score 100/100

ChimpBridge – Create and Send Mailchimp Campaigns in WordPress has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.

No known CVEs Updated 1mo ago
Risk Assessment

The ChimpBridge plugin v1.2.5 exhibits a mixed security posture. On the positive side, it has a clean vulnerability history with no recorded CVEs, and its database interactions are secured using prepared statements. The absence of dangerous functions and file operations is also commendable. However, there are notable concerns regarding its attack surface. With five identified AJAX handlers, three of which lack authentication checks, a significant risk of unauthorized access and execution of plugin functions is present. While the output escaping is reasonably good (75% proper), the remaining unescaped outputs could potentially lead to cross-site scripting (XSS) vulnerabilities, especially when combined with unprotected AJAX endpoints. The taint analysis shows no detected flows, which is a good sign for the current version, but it does not fully mitigate the risks posed by the exposed AJAX handlers and partially unescaped outputs.

In conclusion, while the plugin benefits from a lack of past vulnerabilities and secure database practices, the significant number of unprotected AJAX endpoints represents a critical weakness. This, coupled with the potential for XSS from unescaped outputs, elevates the overall risk. Developers should prioritize implementing proper authentication and capability checks for all AJAX handlers and ensure all output is thoroughly escaped to improve the plugin's security. The lack of taint analysis findings is positive, but the static analysis clearly highlights areas needing immediate attention.

Key Concerns

  • AJAX handlers without authentication checks
  • Unescaped output (potential XSS)
Vulnerabilities
None known

ChimpBridge – Create and Send Mailchimp Campaigns in WordPress Security Vulnerabilities

No known vulnerabilities — this is a good sign.
Code Analysis
Analyzed Mar 16, 2026

ChimpBridge – Create and Send Mailchimp Campaigns in WordPress Code Analysis

Dangerous Functions
0
Raw SQL Queries
0
0 prepared
Unescaped Output
18
54 escaped
Nonce Checks
2
Capability Checks
3
File Operations
0
External Requests
1
Bundled Libraries
0

Output Escaping

75% escaped72 total outputs
Attack Surface
3 unprotected

ChimpBridge – Create and Send Mailchimp Campaigns in WordPress Attack Surface

Entry Points5
Unprotected3

AJAX Handlers 5

authwp_ajax_get_mailchimp_listschimpbridge.php:148
authwp_ajax_get_mailchimp_segmentschimpbridge.php:149
authwp_ajax_refresh_mailchimp_listschimpbridge.php:150
authwp_ajax_refresh_mailchimp_segmentschimpbridge.php:151
authwp_ajax_chimpbridge_send_testchimpbridge.php:152
WordPress Hooks 29
actioninitchimpbridge.php:62
actioninitchimpbridge.php:63
actionadmin_enqueue_scriptschimpbridge.php:114
actionadmin_menuchimpbridge.php:115
actionadmin_noticeschimpbridge.php:116
actionplugins_loadedchimpbridge.php:118
actionadd_meta_boxeschimpbridge.php:121
actionadd_meta_boxeschimpbridge.php:122
filtertiny_mce_before_initchimpbridge.php:123
filtergettextchimpbridge.php:124
filterpost_submitbox_misc_actionschimpbridge.php:125
actionin_admin_footerchimpbridge.php:126
actiondefault_hidden_meta_boxeschimpbridge.php:127
actionsave_post_chimpbridgechimpbridge.php:131
actionuntrashed_postchimpbridge.php:132
actiontrashed_postchimpbridge.php:135
actionbefore_delete_postchimpbridge.php:136
actionadmin_noticeschimpbridge.php:139
actionnew_to_publishchimpbridge.php:140
actiondraft_to_publishchimpbridge.php:141
actionpending_to_publishchimpbridge.php:142
actionadmin_initchimpbridge.php:145
actionadmin_headchimpbridge.php:155
actionadmin_headchimpbridge.php:156
filterpost_updated_messageschimpbridge.php:157
filterpost_updated_messageschimpbridge.php:158
filterredirect_post_locationchimpbridge.php:782
actionshutdownchimpbridge.php:1016
actionadmin_noticeschimpbridge.php:1216
Maintenance & Trust

ChimpBridge – Create and Send Mailchimp Campaigns in WordPress Maintenance & Trust

Maintenance Signals

WordPress version tested6.9.4
Last updatedFeb 26, 2026
PHP min version7.4
Downloads5K

Community Trust

Rating100/100
Number of ratings1
Active installs40
Developer Profile

ChimpBridge – Create and Send Mailchimp Campaigns in WordPress Developer Profile

Link Software LLC

4 plugins · 23K total installs

77
trust score
Avg Security Score
97/100
Avg Patch Time
94 days
View full developer profile
Detection Fingerprints

How We Detect ChimpBridge – Create and Send Mailchimp Campaigns in WordPress

Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.

Asset Fingerprints

Asset Paths
/wp-content/plugins/chimpbridge/assets/stylesheets/global.css/wp-content/plugins/chimpbridge/assets/stylesheets/chimpbridge.css/wp-content/plugins/chimpbridge/assets/javascripts/chimpbridge.js/wp-content/plugins/chimpbridge/assets/javascripts/chimpbridge-ajax.js/wp-content/plugins/chimpbridge/assets/javascripts/chimpbridge-settings.js/wp-content/plugins/chimpbridge/assets/javascripts/chimpbridge-campaign.js
Version Parameters
?ver=1.2.5&ver=1.2.5

HTML / DOM Fingerprints

CSS Classes
chimpbridge_settings_formcb-campaign-previewcb-campaign-settingscb-campaign-editorchimpbridge-admin-settingschimpbridge-campaign-settingschimpbridge-editor-wrap
HTML Comments
<!-- ChimpBridge API Key Settings --><!-- ChimpBridge Settings Form --><!-- Mailchimp List Selection --><!-- Mailchimp Segment Selection -->+1 more
Data Attributes
data-chimpbridge-campaign-iddata-chimpbridge-nonce
JS Globals
window.chimpbridge_ajax_object
REST Endpoints
/wp-json/chimpbridge/v1/lists/wp-json/chimpbridge/v1/segments/wp-json/chimpbridge/v1/refresh_lists/wp-json/chimpbridge/v1/refresh_segments/wp-json/chimpbridge/v1/send_test
FAQ

Frequently Asked Questions about ChimpBridge – Create and Send Mailchimp Campaigns in WordPress