# ultimate-post-kit/4.5.6/modules/newsletter/module.php

Ultimate Post Kit – Elementor Post Grid, Post Carousel, Post Slider &amp; Blog Layout Widgets, version 4.5.6. 120 lines.

- Page: https://pluginprobe.com/plugins/ultimate-post-kit/4.5.6/code/modules/newsletter/module.php
- Raw: https://pluginprobe.com/plugins/ultimate-post-kit/4.5.6/raw/modules/newsletter/module.php
- Modified: 2026-10-06T08:37:16+00:00

Line numbers below start at 1. Link to a line or a range by appending a fragment to the
page URL, for example `https://pluginprobe.com/plugins/ultimate-post-kit/4.5.6/code/modules/newsletter/module.php#L10-L20`.

```php
<?php

namespace UltimatePostKit\Modules\Newsletter;

use UltimatePostKit\Base\Ultimate_Post_Kit_Module_Base;

if (!defined('ABSPATH')) exit; // Exit if accessed directly

class Module extends Ultimate_Post_Kit_Module_Base
{

    public function __construct()
    {
        parent::__construct();

        add_action('wp_ajax_ultimate_post_kit_mailchimp_subscribe', [$this, 'mailchimp_subscribe']);
        add_action('wp_ajax_nopriv_ultimate_post_kit_mailchimp_subscribe', [$this, 'mailchimp_subscribe']);
    }

    public function get_name()
    {
        return 'newsletter';
    }

    public function get_widgets()
    {

        $widgets = ['Newsletter'];

        return $widgets;
    }

    /**
     * subscribe mailchimp with api key
     * @param  string $email        any valid email
     * @param  string $status       subscribe or unsubscribe
     * @param  array  $merge_fields First name and last name of subscriber
     * @return [type]               [description]
     */
    public function mailchimp_subscriber_status($email, $status, $merge_fields = array('FNAME' => '', 'LNAME' => ''))
    {

        $options = get_option('ultimate_post_kit_api_settings');

        $list_id = (!empty($options['mailchimp_list_id'])) ? $options['mailchimp_list_id'] : ''; // Your list is here
        $api_key = (!empty($options['mailchimp_api_key'])) ? $options['mailchimp_api_key'] : ''; // Your mailchimp api key here

        // This endpoint is registered on wp_ajax_nopriv_, so it is reachable before the
        // site owner has configured Mailchimp at all. Without credentials the request
        // below would be built against an unresolvable host and fail.
        if (empty($api_key) || empty($list_id) || false === strpos($api_key, '-')) {
            return null;
        }

        $args = array(
            'method' => 'PUT',
            'headers' => array(
                'Authorization' => 'Basic ' . base64_encode('user:' . $api_key)
            ),
            'body' => json_encode(array(
                'email_address' => $email,
                'status'        => $status,
                'merge_fields'  => $merge_fields
            ))
        );
        $response = wp_remote_post('https://' . substr($api_key, strpos($api_key, '-') + 1) . '.api.mailchimp.com/3.0/lists/' . $list_id . '/members/' . md5(strtolower($email)), $args);

        // A transport failure returns WP_Error, which is an object: indexing it as an
        // array is a fatal. The caller already handles a null/!is_object result.
        if (is_wp_error($response)) {
            return null;
        }

        $body = json_decode(wp_remote_retrieve_body($response));

		return $body;
    }


    public function mailchimp_subscribe()
    {

        // phpcs:ignore WordPress.Security.NonceVerification.Missing, WordPress.Security.NonceVerification.Recommended -- unauthenticated public newsletter subscribe form; input is sanitized and the e-mail validated before use, no nonce is expected from anonymous visitors.
        $fname = (isset($_POST['fname']) && !empty($_POST['fname'])) ? sanitize_text_field(wp_unslash($_POST['fname'])) : '';

        // Validate the address before hitting the Mailchimp API. This endpoint is
        // unauthenticated, so reject anything that is not a real e-mail rather
        // than forwarding arbitrary input to the list.
        // phpcs:ignore WordPress.Security.NonceVerification.Missing, WordPress.Security.NonceVerification.Recommended -- unauthenticated public newsletter subscribe form; input is sanitized and the e-mail validated before use, no nonce is expected from anonymous visitors.
        $email = isset($_POST['email']) ? sanitize_email(wp_unslash($_POST['email'])) : '';

        if (empty($email) || ! is_email($email)) {
            echo '<div class="upk-text-warning">' . esc_html_x('Please enter a valid email address.', 'Mailchimp String', 'ultimate-post-kit') . '</div>';
            die;
        }

        $result  = $this->mailchimp_subscriber_status($email, 'subscribed', ['FNAME' => $fname, 'LNAME' => '']);

        if (! is_object($result) || ! isset($result->status)) {
            echo '<div class="upk-text-danger">' . esc_html_x('An unexpected internal error has occurred. Please contact Support for more information.', 'Mailchimp String', 'ultimate-post-kit') . '</div>';
            die;
        }

        if ($result->status == 400) {
            if (isset($result->detail) && !empty($result->detail)) {
				echo '<div class="upk-text-warning">' . esc_html($result->detail) . '</div>';
			} else {
				echo '<div class="upk-text-warning">' . esc_html_x('Your request could not be processed', 'Mailchimp String', 'ultimate-post-kit') . '</div>';
			}
        } elseif ($result->status == 401) {
            echo '<div class="upk-text-warning">' . esc_html_x('Error: You did not set the API keys or List ID in admin settings!', 'Mailchimp String', 'ultimate-post-kit') . '</div>';
        } elseif ($result->status == 200 || $result->status == 'subscribed') {
            echo '<div class="upk-text-success"><span class="upk-success-icon"></span> ' . esc_html_x('Thank you, You have subscribed successfully.', 'Mailchimp String', 'ultimate-post-kit') . '</div>';
        } else {
            echo '<div class="upk-text-danger">' . esc_html_x('An unexpected internal error has occurred. Please contact Support for more information.', 'Mailchimp String', 'ultimate-post-kit') . '</div>';
        }
        die;
    }
}

```
