Integrations for mautic Security & Risk Analysis

wordpress.org/plugins/integrations-for-mautic

Integrates WordPress with Mautic, allowing you to send leads from Elementor forms, WooCommerce, and more to your Mautic instance.

10 active installs v2.0.7 PHP 8.0+ WP 5.5+ Updated Jan 29, 2026
crmelementorintegrationmauticwoocommerce
100
A · Safe
CVEs total0
Unpatched0
Last CVENever
Safety Verdict

Is Integrations for mautic Safe to Use in 2026?

Generally Safe

Score 100/100

Integrations for mautic has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.

No known CVEs Updated 2mo ago
Risk Assessment

The 'integrations-for-mautic' plugin version 2.0.7 demonstrates a generally strong security posture based on the provided static analysis. The plugin has no known vulnerabilities (CVEs) and a clean vulnerability history, which is a significant positive indicator. The code adheres to good security practices by utilizing prepared statements for all SQL queries and implements a reasonable number of nonce and capability checks, particularly considering its limited entry points. The absence of critical or high-severity taint flows and unsanitized paths further reinforces this positive assessment.

However, there are a few areas that warrant attention. The 16% of output that is not properly escaped, while not immediately indicative of a critical flaw, represents a potential for cross-site scripting (XSS) vulnerabilities if user-controlled data is involved in those unescaped outputs. Furthermore, while the attack surface is small with no unprotected entry points, the presence of external HTTP requests (10) should be monitored for any potential vulnerabilities related to the endpoints they communicate with, as these are external dependencies. The single cron event, while not inherently risky, should be reviewed to ensure it doesn't introduce any exploitable logic.

In conclusion, the plugin is relatively secure with a strong track record. The primary areas for improvement and monitoring are the unescaped output, the security of external HTTP request destinations, and ensuring the cron event is robust. The lack of known vulnerabilities and a clean history suggest diligent development, but ongoing vigilance and code review for the identified minor concerns are recommended.

Key Concerns

  • Unescaped output found
  • External HTTP requests present
Vulnerabilities
None known

Integrations for mautic Security Vulnerabilities

No known vulnerabilities — this is a good sign.
Code Analysis
Analyzed Mar 17, 2026

Integrations for mautic Code Analysis

Dangerous Functions
0
Raw SQL Queries
0
0 prepared
Unescaped Output
16
85 escaped
Nonce Checks
5
Capability Checks
3
File Operations
0
External Requests
10
Bundled Libraries
0

Output Escaping

84% escaped101 total outputs
Data Flows
All sanitized

Data Flow Analysis

3 flows
intmau_save_mautic_settings (admin\mautic-settings.php:275)
Source (user input) Sink (dangerous op) Sanitizer Transform Unsanitized Sanitized
Attack Surface

Integrations for mautic Attack Surface

Entry Points2
Unprotected0

AJAX Handlers 2

authwp_ajax_intmau_generate_mautic_auth_urladmin\mautic-settings.php:229
noprivwp_ajax_intmau_generate_mautic_auth_urladmin\mautic-settings.php:230
WordPress Hooks 30
actionadmin_post_intmau_save_modulesadmin\class-intmau-modules-manager.php:14
actionadmin_noticesadmin\class-intmau-modules-manager.php:59
actionelementor/initadmin\class-intmau-modules-manager.php:81
actionwoocommerce_initadmin\class-intmau-modules-manager.php:100
actionadmin_initadmin\mautic-settings.php:10
actionadmin_enqueue_scriptsadmin\mautic-settings.php:11
actionadmin_post_intmau_generate_mautic_auth_urladmin\mautic-settings.php:271
actionadmin_post_intmau_save_mautic_settingsadmin\mautic-settings.php:347
actionadmin_menuadmin\menu.php:10
actionadmin_menuadmin\menu.php:68
actionadmin_enqueue_scriptsadmin\menu.php:121
actionadmin_menucore\mautic-auth.php:25
actionadmin_initcore\mautic-auth.php:26
actionwp_enqueue_scriptscore\mautic-tracking-code.php:32
actionadmin_noticesintegrations-for-mautic.php:40
actionplugins_loadedintegrations-for-mautic.php:77
actionintmau_refresh_mautic_tokenintegrations-for-mautic.php:79
actionadmin_noticesintegrations-for-mautic.php:135
actionelementor/initmodules\elementor\elementor-loader.php:45
actionelementor_pro/initmodules\elementor\elementor.php:10
actionwoocommerce_review_order_before_submitmodules\woocommerce\class-mautic-woocommerce.php:18
actionwp_loginmodules\woocommerce\class-mautic-woocommerce.php:21
actionwoocommerce_checkout_processmodules\woocommerce\class-mautic-woocommerce.php:24
actionwoocommerce_checkout_update_order_metamodules\woocommerce\class-mautic-woocommerce.php:25
actioninitmodules\woocommerce\class-mautic-woocommerce.php:28
filterwoocommerce_account_menu_itemsmodules\woocommerce\class-mautic-woocommerce.php:32
actionwoocommerce_account_intmau-newsletter_endpointmodules\woocommerce\class-mautic-woocommerce.php:33
actiontemplate_redirectmodules\woocommerce\class-mautic-woocommerce.php:34
actionwoocommerce_initmodules\woocommerce\woocommerce-loader.php:36
actionwoocommerce_initmodules\woocommerce\woocommerce.php:15

Scheduled Events 1

intmau_refresh_mautic_token
Maintenance & Trust

Integrations for mautic Maintenance & Trust

Maintenance Signals

WordPress version tested6.9.4
Last updatedJan 29, 2026
PHP min version8.0
Downloads416

Community Trust

Rating100/100
Number of ratings4
Active installs10
Developer Profile

Integrations for mautic Developer Profile

indedmedia

1 plugin · 10 total installs

94
trust score
Avg Security Score
100/100
Avg Patch Time
30 days
View full developer profile
Detection Fingerprints

How We Detect Integrations for mautic

Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.

Asset Fingerprints

Asset Paths
/wp-content/plugins/integrations-for-mautic/assets/css/admin-styles.css/wp-content/plugins/integrations-for-mautic/assets/js/admin-scripts.js
Script Paths
/wp-content/plugins/integrations-for-mautic/assets/js/admin-scripts.js
Version Parameters
integrations-for-mautic/assets/css/admin-styles.css?ver=integrations-for-mautic/assets/js/admin-scripts.js?ver=

HTML / DOM Fingerprints

CSS Classes
notice-warningis-dismissible
Data Attributes
data-mautic-base-urldata-mautic-client-iddata-mautic-client-secret
JS Globals
intmau_auth_dataINTMAU_Mautic_APIINTMAU_Modules_Manager
FAQ

Frequently Asked Questions about Integrations for mautic