Admin Zendesk Help Widget Security & Risk Analysis

wordpress.org/plugins/admin-zendesk-help-widget

Integrates the Zendesk Web Widget into the WordPress Admin.

10 active installs v1.0 PHP + WP 3.9+ Updated Apr 21, 2015
helpdeskzendesk
85
A · Safe
CVEs total0
Unpatched0
Last CVENever
Safety Verdict

Is Admin Zendesk Help Widget Safe to Use in 2026?

Generally Safe

Score 85/100

Admin Zendesk Help Widget has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.

No known CVEs Updated 11yr ago
Risk Assessment

The `admin-zendesk-help-widget` plugin, version 1.0, exhibits a strong security posture based on the provided static analysis. The absence of identified AJAX handlers, REST API routes, shortcodes, and cron events suggests a very limited attack surface. Furthermore, the code analysis shows no dangerous functions, no raw SQL queries (all prepared statements), and no file operations or external HTTP requests, all of which are positive indicators of secure coding practices. The lack of any recorded vulnerabilities or CVEs further reinforces this positive outlook.

However, a significant concern is the very low percentage of properly escaped output (29%). This indicates that a substantial portion of data displayed to users might not be adequately sanitized, potentially leading to cross-site scripting (XSS) vulnerabilities if user-supplied data is directly rendered without proper escaping. The complete absence of nonce checks and capability checks, while not immediately exploitable due to the limited attack surface, represents a missed opportunity to reinforce security on potential future entry points.

In conclusion, the plugin has a generally good security foundation with a minimal attack surface and good practices in areas like SQL query handling. The primary weakness lies in the inadequate output escaping, which introduces a notable risk of XSS. The lack of any historical vulnerabilities is positive but doesn't negate the current code-level risks.

Key Concerns

  • Low percentage of properly escaped output
  • Missing nonce checks
  • Missing capability checks
Vulnerabilities
None known

Admin Zendesk Help Widget Security Vulnerabilities

No known vulnerabilities — this is a good sign.
Version History

Admin Zendesk Help Widget Release Timeline

No version history available.
Code Analysis
Analyzed Apr 16, 2026

Admin Zendesk Help Widget Code Analysis

Dangerous Functions
0
Raw SQL Queries
0
0 prepared
Unescaped Output
5
2 escaped
Nonce Checks
0
Capability Checks
0
File Operations
0
External Requests
0
Bundled Libraries
0

Output Escaping

29% escaped7 total outputs
Attack Surface

Admin Zendesk Help Widget Attack Surface

Entry Points0
Unprotected0
WordPress Hooks 3
actionadmin_initwordpress-zendesk-admin.php:34
actionadmin_footerwordpress-zendesk-admin.php:35
actionadmin_menuwordpress-zendesk-admin.php:36
Maintenance & Trust

Admin Zendesk Help Widget Maintenance & Trust

Maintenance Signals

WordPress version tested4.1.42
Last updatedApr 21, 2015
PHP min version
Downloads2K

Community Trust

Rating0/100
Number of ratings0
Active installs10
Developer Profile

Admin Zendesk Help Widget Developer Profile

Andy Brudtkuhl

5 plugins · 740 total installs

84
trust score
Avg Security Score
85/100
Avg Patch Time
30 days
View full developer profile
Detection Fingerprints

How We Detect Admin Zendesk Help Widget

Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.

Asset Fingerprints

Asset Paths
/wp-content/plugins/admin-zendesk-help-widget/admin-zendesk-help-widget.php
Script Paths
//assets.zendesk.com/embeddable_framework/main.js

HTML / DOM Fingerprints

HTML Comments
<!-- Start of Zendesk Widget script --><!-- End of Zendesk Widget script -->
JS Globals
zEmbedzE
FAQ

Frequently Asked Questions about Admin Zendesk Help Widget