
Subscribe Mailchimp for EDD Security & Risk Analysis
wordpress.org/plugins/edd-mailchimp-subscribeSubscribe Mailchimp for EDD WordPress plugin displays a newsletter signup checkbox on checkout for Easy Digital Downloads integrated with MailChimp
Is Subscribe Mailchimp for EDD Safe to Use in 2026?
Generally Safe
Score 100/100Subscribe Mailchimp for EDD has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.
The overall security posture of the edd-mailchimp-subscribe plugin v1.4 appears to be a mixed bag. On the positive side, the plugin has no known CVEs, a clean vulnerability history, and all SQL queries utilize prepared statements, indicating good practices in database interaction. The lack of file operations and external HTTP requests also reduces potential attack vectors. However, significant concerns arise from the code analysis. The presence of the `unserialize` function without any apparent sanitization or checks presents a high risk of remote code execution if it processes untrusted input. Furthermore, the fact that 100% of outputs are not properly escaped is a serious security flaw that could lead to cross-site scripting (XSS) vulnerabilities. The absence of any nonce or capability checks across all entry points means that any user, regardless of their permissions, could potentially trigger actions within the plugin.
Key Concerns
- Dangerous function 'unserialize' used without context
- 100% of outputs are not properly escaped (XSS risk)
- No nonce checks across all entry points
- No capability checks across all entry points
Subscribe Mailchimp for EDD Security Vulnerabilities
Subscribe Mailchimp for EDD Code Analysis
Dangerous Functions Found
Output Escaping
Subscribe Mailchimp for EDD Attack Surface
WordPress Hooks 5
Maintenance & Trust
Subscribe Mailchimp for EDD Maintenance & Trust
Maintenance Signals
Community Trust
Subscribe Mailchimp for EDD Alternatives
Connect Contact Form 7 and Mailchimp
contact-form-7-mailchimp-extension
Connect Contact Form 7 to Mailchimp. Automatically sync form submissions to your Mailchimp audiences with merge field mapping, double opt-in, and opt- …
Integration for WooCommerce and MailChimp
woo-mailchimp-crm-perks
WooCommerce MailChimp Plugin allows you to quickly integrate WooCommerce with MailChimp lists and eCommerce features.
ChimpBridge – Create and Send Mailchimp Campaigns in WordPress
chimpbridge
Create and send Mailchimp Campaigns right inside of the WordPress admin.
Flirty Leads
flirty-leads
Flirty Leads lets your site visitors respond your site images. Generate client lists, gain leads using your post/pages images.
Subscriber Discounts for Easy Digital Downloads
subscriber-discounts-for-easy-digital-downloads
Easily send mailing list subscribers a discount code for joining your list.
Subscribe Mailchimp for EDD Developer Profile
11 plugins · 8K total installs
How We Detect Subscribe Mailchimp for EDD
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/edd-mailchimp-subscribe/style.cssHTML / DOM Fingerprints
edd-mailchimp-subscribeeddms_labeledds-gedds-ustat-blocksecondary-stat-blockrounded Inject fields into Easy Digital Downloads Extension Tab Display Newsletter Checkbox on Checkout Subscribe User to MailChimp Get List from MailChimp+1 moreid="eddms_susbscribe"name="eddms_susbscribe"/wp-json/edd-mailchimp-subscribe<div class="form-row edd-mailchimp-subscribe">
<input type="checkbox" class="input-checkbox" name="eddms_susbscribe" id="eddms_susbscribe" value="1" checked="checked">
<span class="eddms_label">