WDV MailChimp Ajax Security & Risk Analysis

wordpress.org/plugins/wdv-mailchimp-ajax

With this plugin you can add 'WDV MailChimp Ajax' widget with subscribe form by MailChimp to your theme. You can change the design of the wi …

30 active installs v2.1.0 PHP 5.7+ WP 5.0.0+ Updated Jan 4, 2025
formmailchimpnewslettersign-upsubscribe
92
A · Safe
CVEs total0
Unpatched0
Last CVENever
Safety Verdict

Is WDV MailChimp Ajax Safe to Use in 2026?

Generally Safe

Score 92/100

WDV MailChimp Ajax has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.

No known CVEs Updated 1yr ago
Risk Assessment

The 'wdv-mailchimp-ajax' plugin exhibits a concerning security posture primarily due to a significant number of unprotected AJAX endpoints. While the plugin demonstrates good practices in other areas, such as using prepared statements for all SQL queries and having a clean vulnerability history, the lack of authentication on its AJAX handlers presents a substantial attack surface. The static analysis reveals 4 AJAX handlers, all of which lack authorization checks. This means any authenticated user, potentially with low privileges, could trigger these actions. The absence of taint analysis results and known vulnerabilities might suggest a lack of complex attack vectors or prior discovery, but it does not negate the inherent risk introduced by the unprotected entry points. Overall, while the plugin avoids common pitfalls like raw SQL queries and unescaped output, the unprotected AJAX handlers are a critical weakness that requires immediate attention to mitigate potential exploits.

Key Concerns

  • AJAX handlers without authentication
  • No nonce checks on AJAX handlers
  • Low percentage of properly escaped output
Vulnerabilities
None known

WDV MailChimp Ajax Security Vulnerabilities

No known vulnerabilities — this is a good sign.
Code Analysis
Analyzed Mar 16, 2026

WDV MailChimp Ajax Code Analysis

Dangerous Functions
0
Raw SQL Queries
0
0 prepared
Unescaped Output
22
150 escaped
Nonce Checks
0
Capability Checks
0
File Operations
0
External Requests
1
Bundled Libraries
0

Output Escaping

87% escaped172 total outputs
Attack Surface
4 unprotected

WDV MailChimp Ajax Attack Surface

Entry Points4
Unprotected4

AJAX Handlers 4

authwp_ajax_wp_ajax_nopriv_wdv_mailchimp_ajaxcallincludes\class-wdv-mailchimp-ajax.php:165
authwp_ajax_wp_ajax_wdv_mailchimp_ajaxcallincludes\class-wdv-mailchimp-ajax.php:166
noprivwp_ajax_wdv_mailchimp_ajaxcallincludes\class-wdv-mailchimp-ajax.php:188
authwp_ajax_wdv_mailchimp_ajaxcallincludes\class-wdv-mailchimp-ajax.php:189
WordPress Hooks 6
actionplugins_loadedincludes\class-wdv-mailchimp-ajax.php:145
actionadmin_enqueue_scriptsincludes\class-wdv-mailchimp-ajax.php:160
actionadmin_enqueue_scriptsincludes\class-wdv-mailchimp-ajax.php:161
actionwidgets_initincludes\class-wdv-mailchimp-ajax.php:170
actionwp_enqueue_scriptsincludes\class-wdv-mailchimp-ajax.php:184
actionwp_enqueue_scriptsincludes\class-wdv-mailchimp-ajax.php:185
Maintenance & Trust

WDV MailChimp Ajax Maintenance & Trust

Maintenance Signals

WordPress version tested6.7.5
Last updatedJan 4, 2025
PHP min version5.7
Downloads5K

Community Trust

Rating46/100
Number of ratings3
Active installs30
Developer Profile

WDV MailChimp Ajax Developer Profile

vrpr

6 plugins · 1K total installs

88
trust score
Avg Security Score
91/100
Avg Patch Time
30 days
View full developer profile
Detection Fingerprints

How We Detect WDV MailChimp Ajax

Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.

Asset Fingerprints

Asset Paths
/wp-content/plugins/wdv-mailchimp-ajax/admin/css/wdv-mailchimp-ajax-admin.css/wp-content/plugins/wdv-mailchimp-ajax/admin/js/wdv-mailchimp-ajax-admin.js
Script Paths
/wp-content/plugins/wdv-mailchimp-ajax/admin/js/wdv-mailchimp-ajax-admin.js
Version Parameters
wdv-mailchimp-ajax-admin.css?ver=wdv-mailchimp-ajax-admin.js?ver=

HTML / DOM Fingerprints

CSS Classes
wdv-mailchimp-ajax
Data Attributes
wdv_mailchimp_ajax_nonce
JS Globals
wdv_mailchimp_ajax_object
FAQ

Frequently Asked Questions about WDV MailChimp Ajax