Purchase Tagger – Product-Based Mailchimp Tags Security & Risk Analysis

wordpress.org/plugins/purchase-tagger-for-mailchimp

Assign Mailchimp tags to contacts based on WooCommerce purchases.

0 active installs v1.1.0 PHP 7.4+ WP 6.0+ Updated Jan 19, 2026
automationemail-marketingmailchimptagswoocommerce
100
A · Safe
CVEs total0
Unpatched0
Last CVENever
Download
Safety Verdict

Is Purchase Tagger – Product-Based Mailchimp Tags Safe to Use in 2026?

Generally Safe

Score 100/100

Purchase Tagger – Product-Based Mailchimp Tags has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.

No known CVEs Updated 2mo ago
Risk Assessment

The "purchase-tagger-for-mailchimp" v1.1.0 plugin exhibits a strong security posture based on the provided static analysis. All identified entry points, including AJAX handlers and cron events, are protected with nonce and capability checks, indicating a proactive approach to securing user interactions. The absence of dangerous functions, raw SQL queries, file operations, and external HTTP requests further strengthens its security. Moreover, the code demonstrates excellent output escaping practices and utilizes prepared statements for all SQL queries, mitigating common web vulnerabilities. The plugin's clean vulnerability history with zero recorded CVEs, across all severity levels, suggests a commitment to security or a history of robust development.

While the static analysis reveals no immediate critical or high-severity risks, the analysis of taint flows was reported as zero, which is an unusual finding and could indicate limited test coverage or a very simple plugin architecture. Nonetheless, the comprehensive application of security best practices in the areas of authentication, authorization, and data handling is commendable. The plugin's strengths lie in its robust access control and data sanitization. Its primary weakness, if any, would be the lack of detailed taint analysis results, which might mask potential subtle vulnerabilities if the plugin were to evolve or have more complex data interactions.

In conclusion, the "purchase-tagger-for-mailchimp" v1.1.0 plugin appears to be a secure choice. The developer has implemented key security measures effectively. The absence of known vulnerabilities and the positive static analysis results provide a high level of confidence in its current security state. Further investigation into the reasons for zero taint flows might be beneficial for a complete understanding, but based on the presented data, the plugin is well-defended against common threats.

Vulnerabilities
None known

Purchase Tagger – Product-Based Mailchimp Tags Security Vulnerabilities

No known vulnerabilities — this is a good sign.
Code Analysis
Analyzed Mar 17, 2026

Purchase Tagger – Product-Based Mailchimp Tags Code Analysis

Dangerous Functions
0
Raw SQL Queries
0
0 prepared
Unescaped Output
0
40 escaped
Nonce Checks
3
Capability Checks
6
File Operations
0
External Requests
0
Bundled Libraries
0

Output Escaping

100% escaped40 total outputs
Attack Surface

Purchase Tagger – Product-Based Mailchimp Tags Attack Surface

Entry Points2
Unprotected0

AJAX Handlers 2

authwp_ajax_mctwc_get_mailchimp_listsclass-mctwc-mailchimp-tags-integration.php:289
authwp_ajax_mctwc_dismiss_noticemctwc-tags-for-mailchimp.php:411
WordPress Hooks 14
filterwoocommerce_integrationsclass-mctwc-mailchimp-tags-integration.php:23
actionadmin_enqueue_scriptsclass-mctwc-mailchimp-tags-integration.php:62
actionplugins_loadedclass-mctwc-mailchimp-tags-integration.php:229
actionbefore_woocommerce_initmctwc-tags-for-mailchimp.php:41
actionadmin_noticesmctwc-tags-for-mailchimp.php:49
actionwoocommerce_order_status_changedmctwc-tags-for-mailchimp.php:128
actionplugins_loadedmctwc-tags-for-mailchimp.php:150
actionmctwc_daily_health_checkmctwc-tags-for-mailchimp.php:225
actionadmin_noticesmctwc-tags-for-mailchimp.php:346
actionadmin_enqueue_scriptsmctwc-tags-for-mailchimp.php:373
actionwoocommerce_product_after_variable_attributesmctwc-tags-for-mailchimp.php:620
actionwoocommerce_save_product_variationmctwc-tags-for-mailchimp.php:644
actionwoocommerce_product_options_general_product_datamctwc-tags-for-mailchimp.php:670
actionwoocommerce_process_product_metamctwc-tags-for-mailchimp.php:696

Scheduled Events 3

mctwc_daily_health_check
mctwc_daily_health_check
mctwc_daily_health_check
Maintenance & Trust

Purchase Tagger – Product-Based Mailchimp Tags Maintenance & Trust

Maintenance Signals

WordPress version tested6.9.4
Last updatedJan 19, 2026
PHP min version7.4
Downloads163

Community Trust

Rating0/100
Number of ratings0
Active installs0
Developer Profile

Purchase Tagger – Product-Based Mailchimp Tags Developer Profile

jessaumick

1 plugin · 0 total installs

94
trust score
Avg Security Score
100/100
Avg Patch Time
30 days
View full developer profile
Detection Fingerprints

How We Detect Purchase Tagger – Product-Based Mailchimp Tags

Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.

Asset Fingerprints

Asset Paths
/wp-content/plugins/purchase-tagger-for-mailchimp/assets/css/styles.css
Script Paths
/wp-content/plugins/purchase-tagger-for-mailchimp/assets/js/admin-settings.js/wp-content/plugins/purchase-tagger-for-mailchimp/assets/js/mailchimp-integration.js
Version Parameters
purchase-tagger-for-mailchimp/assets/css/styles.css?ver=purchase-tagger-for-mailchimp/assets/js/admin-settings.js?ver=purchase-tagger-for-mailchimp/assets/js/mailchimp-integration.js?ver=

HTML / DOM Fingerprints

FAQ

Frequently Asked Questions about Purchase Tagger – Product-Based Mailchimp Tags