Mailchimp Widget by ProteusThemes Security & Risk Analysis

wordpress.org/plugins/proteusthemes-mailchimp-widget

Capture your visitor's email address and subscribe them to your newsletter campaign with this simple Mailchimp widget plugin!

1K active installs v1.0.5 PHP + WP 4.6+ Updated May 31, 2020
emailformmailchimpnewsletterwidget
85
A · Safe
CVEs total0
Unpatched0
Last CVENever
Safety Verdict

Is Mailchimp Widget by ProteusThemes Safe to Use in 2026?

Generally Safe

Score 85/100

Mailchimp Widget by ProteusThemes has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.

No known CVEs Updated 5yr ago
Risk Assessment

The proteusthemes-mailchimp-widget plugin v1.0.5 exhibits a generally strong security posture, largely due to the absence of known vulnerabilities and a good approach to database interactions. The code analysis indicates no dangerous functions or direct SQL queries without prepared statements, which are positive signs. File operations and external HTTP requests are also limited, reducing potential attack vectors.

However, there are areas for concern. The plugin has a single AJAX handler that lacks explicit capability checks, meaning its functionality could potentially be accessed by unauthenticated or less privileged users if not properly secured by WordPress's core AJAX handling mechanisms. Furthermore, the taint analysis reveals two flows with unsanitized paths, though currently assessed as not critical or high severity. The mixed rate of output escaping (66% properly escaped) suggests that some output may be vulnerable to cross-site scripting (XSS) if the data originates from untrusted sources.

With no recorded vulnerabilities in its history, the plugin appears to have been developed with security in mind. The lack of past issues is a significant strength. However, the presence of unsanitized paths in taint analysis and the less than perfect output escaping are weaknesses that warrant attention. Overall, while the plugin is currently free of known severe flaws, proactive measures to address potential XSS and ensure robust authorization for AJAX endpoints would further enhance its security.

Key Concerns

  • AJAX handler without capability checks
  • Unsanitized paths in taint analysis
  • Output escaping at 66%
Vulnerabilities
None known

Mailchimp Widget by ProteusThemes Security Vulnerabilities

No known vulnerabilities — this is a good sign.
Code Analysis
Analyzed Mar 16, 2026

Mailchimp Widget by ProteusThemes Code Analysis

Dangerous Functions
0
Raw SQL Queries
0
0 prepared
Unescaped Output
12
23 escaped
Nonce Checks
1
Capability Checks
0
File Operations
0
External Requests
2
Bundled Libraries
0

Output Escaping

66% escaped35 total outputs
Data Flows
2 unsanitized

Data Flow Analysis

2 flows2 with unsanitized paths
mailchimp_get_lists (inc\widget-mailchimp-subscribe.php:146)
Source (user input) Sink (dangerous op) Sanitizer Transform Unsanitized Sanitized
Attack Surface

Mailchimp Widget by ProteusThemes Attack Surface

Entry Points1
Unprotected0

AJAX Handlers 1

authwp_ajax_pt_mailchimp_subscribe_get_listsinc\widget-mailchimp-subscribe.php:28
WordPress Hooks 4
actionplugins_loadedproteusthemes-mailchimp-widget.php:29
actionwidgets_initproteusthemes-mailchimp-widget.php:32
actionadmin_enqueue_scriptsproteusthemes-mailchimp-widget.php:35
actionwp_enqueue_scriptsproteusthemes-mailchimp-widget.php:38
Maintenance & Trust

Mailchimp Widget by ProteusThemes Maintenance & Trust

Maintenance Signals

WordPress version tested5.4.19
Last updatedMay 31, 2020
PHP min version
Downloads52K

Community Trust

Rating100/100
Number of ratings2
Active installs1K
Developer Profile

Mailchimp Widget by ProteusThemes Developer Profile

ProteusThemes

3 plugins · 5K total installs

79
trust score
Avg Security Score
78/100
Avg Patch Time
30 days
View full developer profile
Detection Fingerprints

How We Detect Mailchimp Widget by ProteusThemes

Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.

Asset Fingerprints

Asset Paths
/wp-content/plugins/proteusthemes-mailchimp-widget/assets/css/main.css/wp-content/plugins/proteusthemes-mailchimp-widget/assets/js/admin.js
Script Paths
/wp-content/plugins/proteusthemes-mailchimp-widget/assets/js/admin.js
Version Parameters
/wp-content/plugins/proteusthemes-mailchimp-widget/assets/css/main.css?ver=/wp-content/plugins/proteusthemes-mailchimp-widget/assets/js/admin.js?ver=

HTML / DOM Fingerprints

JS Globals
PTMCWAdminVars
FAQ

Frequently Asked Questions about Mailchimp Widget by ProteusThemes