Post to Mailchimp Security & Risk Analysis

wordpress.org/plugins/post-to-mailchimp

Need a way to use posts as content for mailchimp?

0 active installs v1.0 PHP + WP 4.0+ Updated Nov 13, 2018
mailchimpnewsletter
85
A · Safe
CVEs total0
Unpatched0
Last CVENever
Safety Verdict

Is Post to Mailchimp Safe to Use in 2026?

Generally Safe

Score 85/100

Post to Mailchimp has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.

No known CVEs Updated 7yr ago
Risk Assessment

The "post-to-mailchimp" v1.0 plugin exhibits a generally good security posture based on the provided static analysis. The absence of any recorded CVEs, including critical or high severity vulnerabilities, and the complete lack of raw SQL queries or dangerous function usage are positive indicators. Furthermore, the plugin demonstrates a commitment to security by performing capability checks on four separate occasions. The attack surface is also commendably small, with no exposed AJAX handlers, REST API routes, shortcodes, or cron events without proper authentication or permission checks, and no file operations or external HTTP requests were detected.

However, a significant concern arises from the output escaping, with only 29% of the 17 total outputs being properly escaped. This indicates a potential for cross-site scripting (XSS) vulnerabilities, where malicious code could be injected into the site's output and executed in users' browsers. While the taint analysis reports no critical or high severity flows, the lack of proper output escaping presents a tangible risk that could be exploited if an attacker can influence the data being outputted.

In conclusion, the plugin's foundation is solid, with robust defenses against common server-side and database-level attacks. The lack of past vulnerabilities further supports this. The primary weakness lies in the insufficient output escaping, which represents a moderate security risk. Addressing this specific area should be the priority for improving the plugin's overall security.

Key Concerns

  • Insufficient output escaping
Vulnerabilities
None known

Post to Mailchimp Security Vulnerabilities

No known vulnerabilities — this is a good sign.
Code Analysis
Analyzed Mar 17, 2026

Post to Mailchimp Code Analysis

Dangerous Functions
0
Raw SQL Queries
0
0 prepared
Unescaped Output
12
5 escaped
Nonce Checks
0
Capability Checks
4
File Operations
0
External Requests
0
Bundled Libraries
0

Output Escaping

29% escaped17 total outputs
Attack Surface

Post to Mailchimp Attack Surface

Entry Points0
Unprotected0
WordPress Hooks 4
actionadd_meta_boxesclasses\meta-box.php:31
actionsave_postclasses\meta-box.php:32
actionadmin_initclasses\settings.php:27
actionadmin_menuclasses\settings.php:28
Maintenance & Trust

Post to Mailchimp Maintenance & Trust

Maintenance Signals

WordPress version tested4.9.29
Last updatedNov 13, 2018
PHP min version
Downloads2K

Community Trust

Rating0/100
Number of ratings0
Active installs0
Developer Profile

Post to Mailchimp Developer Profile

EdwardBock

22 plugins · 2K total installs

72
trust score
Avg Security Score
90/100
Avg Patch Time
107 days
View full developer profile
Detection Fingerprints

How We Detect Post to Mailchimp

Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.

Asset Fingerprints

Asset Paths
/wp-content/plugins/post-to-mailchimp/css/meta-box.css/wp-content/plugins/post-to-mailchimp/js/api.js/wp-content/plugins/post-to-mailchimp/js/meta-box.js
Script Paths
/wp-content/plugins/post-to-mailchimp/js/api.js/wp-content/plugins/post-to-mailchimp/js/meta-box.js
Version Parameters
/wp-content/plugins/post-to-mailchimp/js/api.js?ver=/wp-content/plugins/post-to-mailchimp/css/meta-box.css?ver=/wp-content/plugins/post-to-mailchimp/js/meta-box.js?ver=

HTML / DOM Fingerprints

CSS Classes
post_to_mailchimp__lists-list
Data Attributes
id="post_to_mailchimp__app"name="post_to_mailchimp_list_id"class="post_to_mailchimp__lists-list"
JS Globals
PostToMailchimpAPIPostToMailchimpMetaBox
FAQ

Frequently Asked Questions about Post to Mailchimp