
Maui Marketing Scripts, Tags & CSS Manager Security & Risk Analysis
wordpress.org/plugins/maui-marketing-script-managerThis plugin allows you to add custom scripts, css and tags to header, footer and body.
Is Maui Marketing Scripts, Tags & CSS Manager Safe to Use in 2026?
Generally Safe
Score 85/100Maui Marketing Scripts, Tags & CSS Manager has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.
The "maui-marketing-script-manager" v2.3.0 plugin presents a concerning security posture due to significant vulnerabilities identified in its static analysis. A primary concern is the presence of two AJAX handlers that lack authentication checks, creating an open attack surface for malicious actors. Additionally, the use of the `unserialize` function is a known risk, especially if the data being unserialized originates from user input, as it can lead to remote code execution vulnerabilities. The taint analysis, while limited in scope, did identify a flow with an unsanitized path, indicating a potential for input to be processed in an unsafe manner. The plugin's vulnerability history is clean, with no recorded CVEs, which is a positive indicator. However, this lack of history combined with the identified code signals does not negate the current risks. The plugin demonstrates some good practices, such as using prepared statements for all SQL queries and having a relatively small attack surface in terms of entry points (excluding AJAX). Nonetheless, the unprotected AJAX endpoints and the use of `unserialize` are critical weaknesses that require immediate attention. The low percentage of properly escaped outputs is also a weakness, though not as severe as the unprotected entry points or unserialization vulnerability.
Key Concerns
- AJAX handlers without authentication
- Dangerous function: unserialize used
- Flow with unsanitized path
- Low percentage of properly escaped outputs
- No nonce checks on AJAX
Maui Marketing Scripts, Tags & CSS Manager Security Vulnerabilities
Maui Marketing Scripts, Tags & CSS Manager Code Analysis
Dangerous Functions Found
Output Escaping
Data Flow Analysis
Maui Marketing Scripts, Tags & CSS Manager Attack Surface
AJAX Handlers 2
WordPress Hooks 9
Maintenance & Trust
Maui Marketing Scripts, Tags & CSS Manager Maintenance & Trust
Maintenance Signals
Community Trust
Maui Marketing Scripts, Tags & CSS Manager Alternatives
Better WordPress Minify
bwp-minify
Allows you to combine and minify your CSS and JS files to improve page load time.
CSS JS Manager, Async JavaScript, Defer Render Blocking CSS
css-js-manager
CSS JS Manager, Async JavaScript, Defer Render Blocking CSS, Remove javascript, Remove CSS, Defer Render Blocking CSS, Both CSS and JS can be loaded A …
WP Minify Fix
wp-minify-fix
[Fixed] This plugin uses the Minify engine to combine and compress JS and CSS files to improve page load time.
Insert Code by Angie Makes
wpc-insert-code
Easily insert HTML, Javascript, CSS, into the head and footer areas of your site.
Custom CSS/JS
wp-custom-cssjs
WP Custom CSS JS plugin allows you to add any HTML, CSS, Javascript, jQuery or Tracking Pixel easily on your wordpress site right from your dashboard.
Maui Marketing Scripts, Tags & CSS Manager Developer Profile
2 plugins · 40 total installs
How We Detect Maui Marketing Scripts, Tags & CSS Manager
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/maui-marketing-script-manager/js/mm-script-manager-admin.js/wp-content/plugins/maui-marketing-script-manager/css/mm-script-manager-admin.css/wp-content/plugins/maui-marketing-script-manager/js/mm-script-manager-admin.jsmaui-marketing-script-manager/js/mm-script-manager-admin.js?ver=maui-marketing-script-manager/css/mm-script-manager-admin.css?ver=