Maui Marketing Scripts, Tags & CSS Manager Security & Risk Analysis

wordpress.org/plugins/maui-marketing-script-manager

This plugin allows you to add custom scripts, css and tags to header, footer and body.

30 active installs v2.3.0 PHP + WP 3.0.1+ Updated Jan 31, 2017
cssjavascriptjsmanagerpages
85
A · Safe
CVEs total0
Unpatched0
Last CVENever
Safety Verdict

Is Maui Marketing Scripts, Tags & CSS Manager Safe to Use in 2026?

Generally Safe

Score 85/100

Maui Marketing Scripts, Tags & CSS Manager has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.

No known CVEs Updated 9yr ago
Risk Assessment

The "maui-marketing-script-manager" v2.3.0 plugin presents a concerning security posture due to significant vulnerabilities identified in its static analysis. A primary concern is the presence of two AJAX handlers that lack authentication checks, creating an open attack surface for malicious actors. Additionally, the use of the `unserialize` function is a known risk, especially if the data being unserialized originates from user input, as it can lead to remote code execution vulnerabilities. The taint analysis, while limited in scope, did identify a flow with an unsanitized path, indicating a potential for input to be processed in an unsafe manner. The plugin's vulnerability history is clean, with no recorded CVEs, which is a positive indicator. However, this lack of history combined with the identified code signals does not negate the current risks. The plugin demonstrates some good practices, such as using prepared statements for all SQL queries and having a relatively small attack surface in terms of entry points (excluding AJAX). Nonetheless, the unprotected AJAX endpoints and the use of `unserialize` are critical weaknesses that require immediate attention. The low percentage of properly escaped outputs is also a weakness, though not as severe as the unprotected entry points or unserialization vulnerability.

Key Concerns

  • AJAX handlers without authentication
  • Dangerous function: unserialize used
  • Flow with unsanitized path
  • Low percentage of properly escaped outputs
  • No nonce checks on AJAX
Vulnerabilities
None known

Maui Marketing Scripts, Tags & CSS Manager Security Vulnerabilities

No known vulnerabilities — this is a good sign.
Code Analysis
Analyzed Mar 16, 2026

Maui Marketing Scripts, Tags & CSS Manager Code Analysis

Dangerous Functions
6
Raw SQL Queries
0
0 prepared
Unescaped Output
133
4 escaped
Nonce Checks
0
Capability Checks
1
File Operations
22
External Requests
0
Bundled Libraries
0

Dangerous Functions Found

unserialize$list_item = unserialize(get_option('mm_custom_save_script'));mm-script-manager-admin.php:233
unserialize$list_item = unserialize(get_option('mm_custom_save_script'));mm-script-manager-admin.php:243
unserialize$list_item = unserialize(get_option('mm_custom_save_script'));mm-script-manager-admin.php:496
unserialize$list_item = unserialize(get_option('mm_custom_save_script'));mm-script-manager-admin.php:638
unserialize$list_item = unserialize(get_option('mm_custom_save_script'));mm-script-manager-admin.php:780
unserialize$list_item = unserialize(get_option('mm_custom_save_script'));mm-script-manager-admin.php:922

Output Escaping

3% escaped137 total outputs
Data Flows
1 unsanitized

Data Flow Analysis

2 flows1 with unsanitized paths
mm_script_manager_add_new_repeater_item (mm-script-manager-admin.php:33)
Source (user input) Sink (dangerous op) Sanitizer Transform Unsanitized Sanitized
Attack Surface
2 unprotected

Maui Marketing Scripts, Tags & CSS Manager Attack Surface

Entry Points2
Unprotected2

AJAX Handlers 2

authwp_ajax_mm_script_add_new_repeater_itemmm-script-manager-admin.php:13
noprivwp_ajax_mm_script_add_new_repeater_itemmm-script-manager-admin.php:14
WordPress Hooks 9
actionadmin_enqueue_scriptsmm-script-manager-admin.php:7
actionadmin_menumm-script-manager-admin.php:8
actionwp_headmm-script-manager-admin.php:9
actionwp_footermm-script-manager-admin.php:10
actionwp_mm_body_after_open_hookmm-script-manager-admin.php:11
actionwp_mm_body_prior_close_hookmm-script-manager-admin.php:12
actionadmin_noticesmm-script-manager.php:24
actionplugins_loadedmm-script-manager.php:25
actionafter_switch_thememm-script-manager.php:26
Maintenance & Trust

Maui Marketing Scripts, Tags & CSS Manager Maintenance & Trust

Maintenance Signals

WordPress version tested4.3.34
Last updatedJan 31, 2017
PHP min version
Downloads3K

Community Trust

Rating100/100
Number of ratings1
Active installs30
Developer Profile

Maui Marketing Scripts, Tags & CSS Manager Developer Profile

mauimarketing

2 plugins · 40 total installs

89
trust score
Avg Security Score
93/100
Avg Patch Time
30 days
View full developer profile
Detection Fingerprints

How We Detect Maui Marketing Scripts, Tags & CSS Manager

Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.

Asset Fingerprints

Asset Paths
/wp-content/plugins/maui-marketing-script-manager/js/mm-script-manager-admin.js/wp-content/plugins/maui-marketing-script-manager/css/mm-script-manager-admin.css
Script Paths
/wp-content/plugins/maui-marketing-script-manager/js/mm-script-manager-admin.js
Version Parameters
maui-marketing-script-manager/js/mm-script-manager-admin.js?ver=maui-marketing-script-manager/css/mm-script-manager-admin.css?ver=

HTML / DOM Fingerprints

FAQ

Frequently Asked Questions about Maui Marketing Scripts, Tags & CSS Manager