
eewee sellsy Security & Risk Analysis
wordpress.org/plugins/eewee-sellsyGenerate ticket support form et simple form
Is eewee sellsy Safe to Use in 2026?
Generally Safe
Score 100/100eewee sellsy has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.
The 'eewee-sellsy' v1.14 plugin exhibits a mixed security posture. While it avoids dangerous functions and primarily uses prepared statements for SQL queries, a significant concern arises from its attack surface. Three out of five identified entry points, specifically AJAX handlers, lack authentication checks. This creates a direct pathway for unauthenticated users to interact with potentially sensitive plugin functionalities.
The taint analysis reveals six flows with unsanitized paths, although none are classified as critical or high severity. This suggests potential vulnerabilities related to input handling, where data might not be adequately cleaned before being used, even if it doesn't immediately lead to severe exploitation based on the static analysis alone. The low percentage of properly escaped output (21%) is another significant weakness, increasing the risk of cross-site scripting (XSS) vulnerabilities.
Notably, the plugin has no recorded vulnerability history (CVEs), which is a positive indicator of its past security performance. However, the current static analysis findings, particularly the unprotected AJAX handlers and the high rate of unescaped output, indicate areas that require immediate attention to maintain a secure state. The absence of capability checks further exacerbates the risk associated with the unprotected entry points.
Key Concerns
- Unprotected AJAX handlers
- Low percentage of properly escaped output
- Unsanitized paths in taint flows
- Lack of capability checks
eewee sellsy Security Vulnerabilities
eewee sellsy Code Analysis
SQL Query Safety
Output Escaping
Data Flow Analysis
eewee sellsy Attack Surface
AJAX Handlers 3
Shortcodes 2
WordPress Hooks 3
Maintenance & Trust
eewee sellsy Maintenance & Trust
Maintenance Signals
Community Trust
eewee sellsy Alternatives
Contact Form to Any API
contact-form-to-any-api
Send Contact Form 7 submissions to any API, Webhook or CRM - quick setup, flexible payloads, endpoints and authentication.
Connector to CiviCRM with CiviMcRestFace
connector-civicrm-mcrestface
Provides an API connector to a local or remote CiviCRM installation. This connector could be used by other plugins. Funded by Artfulrobot, CiviCoop, c …
Connect WPForm to Any API
connect-wpform-to-any-api
WPForm to Any API is most powerful plugin to send WPForm data to any third party services. It can be use to send data to CRM or any REST API.
Forms Bridge – Infinite integrations
forms-bridge
Seamlessly connect WordPress forms to CRMs, ERPs, and APIs — no coding required. Automate data flow with field mappers, custom fields, and workflows.
Data source CiviCRM api for wpDataTable
data-source-civicrm-api-for-wpdatatable
Provides a CiviCRM api data source for wpDataTable plugin.
eewee sellsy Developer Profile
5 plugins · 50 total installs
How We Detect eewee sellsy
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/eewee-sellsy/css/style.csshttps://www.google.com/recaptcha/api.js/wp-content/plugins/eewee-sellsy/js/main.js/wp-content/plugins/eewee-sellsy/js/front.jseewee-sellsy/style.css?ver=HTML / DOM Fingerprints
error-msgticket-form-submitcontact-form-submitrecaptcha-areadata-formidajax_object[ticketSellsy][contactSellsy]