Responsive Contact Form Mailchimp Extension Security & Risk Analysis

wordpress.org/plugins/responsive-contact-form-mailchimp-extension

It is extension of Responsive Contact Form to integrate leads to your mailchimp account.

10 active installs v1.2 PHP + WP 3.6+ Updated Jul 20, 2020
contactcontact-formformresponsive-contact-formtext
85
A · Safe
CVEs total0
Unpatched0
Last CVENever
Safety Verdict

Is Responsive Contact Form Mailchimp Extension Safe to Use in 2026?

Generally Safe

Score 85/100

Responsive Contact Form Mailchimp Extension has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.

No known CVEs Updated 5yr ago
Risk Assessment

The "responsive-contact-form-mailchimp-extension" v1.2 plugin exhibits a generally strong security posture based on the provided static analysis. The absence of any known CVEs, critical or high severity taint flows, and SQL queries not using prepared statements are positive indicators. Furthermore, the plugin demonstrates good practices by avoiding dangerous functions and file operations, and it does not bundle any external libraries, which could introduce outdated components. The limited attack surface, with zero entry points identified, is a significant strength.

However, there are notable areas of concern. The analysis reveals that 100% of flows with unsanitized paths are present, although they are not classified as critical or high severity. More importantly, the plugin entirely lacks nonce checks and capability checks across its code. This absence of authorization and integrity checks on any potential (though currently unexposed) entry points represents a significant security weakness. The external HTTP request also warrants scrutiny, as its purpose and the data it handles are not detailed, potentially posing a risk if not handled securely.

In conclusion, while the plugin benefits from a clean vulnerability history and a well-defined, minimal attack surface, the complete lack of nonce and capability checks is a substantial flaw. This omission could be exploited if new entry points are introduced or if existing, unanalyzed code paths are discovered. The presence of unsanitized paths, even without critical severity, suggests a need for more robust input validation and sanitization.

Key Concerns

  • No Nonce Checks Found
  • No Capability Checks Found
  • Unsanitized Paths Found (2 flows)
  • Output escaping is not 100% effective (75%)
  • One External HTTP Request Present
Vulnerabilities
None known

Responsive Contact Form Mailchimp Extension Security Vulnerabilities

No known vulnerabilities — this is a good sign.
Code Analysis
Analyzed Mar 17, 2026

Responsive Contact Form Mailchimp Extension Code Analysis

Dangerous Functions
0
Raw SQL Queries
0
1 prepared
Unescaped Output
2
6 escaped
Nonce Checks
0
Capability Checks
0
File Operations
0
External Requests
1
Bundled Libraries
0

SQL Query Safety

100% prepared1 total queries

Output Escaping

75% escaped8 total outputs
Data Flows
2 unsanitized

Data Flow Analysis

2 flows2 with unsanitized paths
ai_plugin_admin_notices (ai-responsive-contact-form-mailchimp-extension.php:48)
Source (user input) Sink (dangerous op) Sanitizer Transform Unsanitized Sanitized
Attack Surface

Responsive Contact Form Mailchimp Extension Attack Surface

Entry Points0
Unprotected0
WordPress Hooks 7
actionadmin_menuadmin\class-ai-mailchimp-admin.php:14
actionadmin_initadmin\class-ai-mailchimp-admin.php:20
actionplugins_loadedai-responsive-contact-form-mailchimp-extension.php:34
actionplugins_loadedai-responsive-contact-form-mailchimp-extension.php:39
actionadmin_noticesai-responsive-contact-form-mailchimp-extension.php:45
actioninitpublic\class-ai-mailchimp.php:13
actionwpmu_new_blogpublic\class-ai-mailchimp.php:16
Maintenance & Trust

Responsive Contact Form Mailchimp Extension Maintenance & Trust

Maintenance Signals

WordPress version tested5.4.19
Last updatedJul 20, 2020
PHP min version
Downloads4K

Community Trust

Rating100/100
Number of ratings1
Active installs10
Developer Profile

Responsive Contact Form Mailchimp Extension Developer Profile

August Infotech

4 plugins · 50 total installs

86
trust score
Avg Security Score
89/100
Avg Patch Time
30 days
View full developer profile
Detection Fingerprints

How We Detect Responsive Contact Form Mailchimp Extension

Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.

Asset Fingerprints

Asset Paths
/wp-content/plugins/responsive-contact-form-mailchimp-extension/assets/css/admin.css/wp-content/plugins/responsive-contact-form-mailchimp-extension/assets/js/admin.js
Version Parameters
responsive-contact-form-mailchimp-extension/assets/css/admin.css?ver=responsive-contact-form-mailchimp-extension/assets/js/admin.js?ver=

HTML / DOM Fingerprints

FAQ

Frequently Asked Questions about Responsive Contact Form Mailchimp Extension