Logicrays WP Mailchimp Signup form with popup Security & Risk Analysis

wordpress.org/plugins/logicrays-wp-mailchimp-signup-form-with-popup

A full-featured WordPress Mailchimp Subscriber form with modal popup which fulfils all subscribers, emails and get more subscribres easily.

0 active installs v1.1 PHP + WP 4.5+ Updated Feb 2, 2021
emailmailchimpmarketingmc4wpnewsletter
85
A · Safe
CVEs total0
Unpatched0
Last CVENever
Safety Verdict

Is Logicrays WP Mailchimp Signup form with popup Safe to Use in 2026?

Generally Safe

Score 85/100

Logicrays WP Mailchimp Signup form with popup has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.

No known CVEs Updated 5yr ago
Risk Assessment

The "logicrays-wp-mailchimp-signup-form-with-popup" plugin v1.1 exhibits a mixed security posture. On the positive side, the static analysis reveals no dangerous functions, all SQL queries are properly prepared, and there are no known past vulnerabilities. This suggests a development team that is aware of and implementing some fundamental security practices. However, there are notable concerns, particularly regarding the handling of external HTTP requests and a lack of comprehensive input validation. The taint analysis indicates flows with unsanitized paths, which is a red flag even without critical or high-severity findings. This suggests potential avenues for attackers to manipulate plugin behavior through untrusted input. Furthermore, the absence of nonce checks and capability checks on entry points is a significant weakness that could allow for unauthorized actions or privilege escalation if the plugin's functionality were to be exploited. The 84% output escaping is good but leaves room for improvement, as a small percentage of unescaped output can still lead to cross-site scripting (XSS) vulnerabilities.

Despite the positive aspects like the absence of SQL injection risks and a clean vulnerability history, the identified weaknesses in input sanitization and the lack of robust access control mechanisms present tangible risks. The presence of external HTTP requests without explicit validation of their source or content further compounds these concerns. While the plugin does not currently have any known critical vulnerabilities, these structural weaknesses could facilitate future exploits. A balanced conclusion would highlight the developer's effort in avoiding common pitfalls like raw SQL, but strongly caution against the potential for XSS and unauthorized actions due to the identified input handling and authorization gaps.

Key Concerns

  • Taint flows with unsanitized paths
  • External HTTP requests without clear validation
  • Missing nonce checks
  • Missing capability checks
  • Some unescaped output
Vulnerabilities
None known

Logicrays WP Mailchimp Signup form with popup Security Vulnerabilities

No known vulnerabilities — this is a good sign.
Code Analysis
Analyzed Mar 17, 2026

Logicrays WP Mailchimp Signup form with popup Code Analysis

Dangerous Functions
0
Raw SQL Queries
0
0 prepared
Unescaped Output
3
16 escaped
Nonce Checks
0
Capability Checks
0
File Operations
0
External Requests
2
Bundled Libraries
0

Output Escaping

84% escaped19 total outputs
Data Flows
2 unsanitized

Data Flow Analysis

2 flows2 with unsanitized paths
lrM_shortcode (lrm-wp-mailchimp-shortcode.php:4)
Source (user input) Sink (dangerous op) Sanitizer Transform Unsanitized Sanitized
Attack Surface

Logicrays WP Mailchimp Signup form with popup Attack Surface

Entry Points1
Unprotected0

Shortcodes 1

[LRM_WP_MAILCHIMP] lrm-wp-mailchimp-shortcode.php:3
WordPress Hooks 3
actionadmin_menulrm-wp-mailchimp.php:11
actionadmin_initlrm-wp-mailchimp.php:62
actionwp_headlrm-wp-mailchimp.php:63
Maintenance & Trust

Logicrays WP Mailchimp Signup form with popup Maintenance & Trust

Maintenance Signals

WordPress version tested5.6.17
Last updatedFeb 2, 2021
PHP min version
Downloads1K

Community Trust

Rating100/100
Number of ratings1
Active installs0
Developer Profile

Logicrays WP Mailchimp Signup form with popup Developer Profile

LogicRays Technologies

15 plugins · 290 total installs

87
trust score
Avg Security Score
90/100
Avg Patch Time
30 days
View full developer profile
Detection Fingerprints

How We Detect Logicrays WP Mailchimp Signup form with popup

Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.

Asset Fingerprints

Asset Paths
/wp-content/plugins/logicrays-wp-mailchimp-signup-form-with-popup/css/mailchimp-style.css/wp-content/plugins/logicrays-wp-mailchimp-signup-form-with-popup/js/mailchimp-custom.js
Script Paths
/wp-content/plugins/logicrays-wp-mailchimp-signup-form-with-popup/js/mailchimp-custom.js

HTML / DOM Fingerprints

CSS Classes
lrm_wp_shortcodebox-item
Shortcode Output
[LRM_WP_MAILCHIMP]
FAQ

Frequently Asked Questions about Logicrays WP Mailchimp Signup form with popup