eewee sellsy Security & Risk Analysis

wordpress.org/plugins/eewee-sellsy

Generate ticket support form et simple form

10 active installs v1.14 PHP + WP 3.1+ Updated Unknown
apicrm
100
A · Safe
CVEs total0
Unpatched0
Last CVENever
Safety Verdict

Is eewee sellsy Safe to Use in 2026?

Generally Safe

Score 100/100

eewee sellsy has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.

No known CVEs
Risk Assessment

The 'eewee-sellsy' v1.14 plugin exhibits a mixed security posture. While it avoids dangerous functions and primarily uses prepared statements for SQL queries, a significant concern arises from its attack surface. Three out of five identified entry points, specifically AJAX handlers, lack authentication checks. This creates a direct pathway for unauthenticated users to interact with potentially sensitive plugin functionalities.

The taint analysis reveals six flows with unsanitized paths, although none are classified as critical or high severity. This suggests potential vulnerabilities related to input handling, where data might not be adequately cleaned before being used, even if it doesn't immediately lead to severe exploitation based on the static analysis alone. The low percentage of properly escaped output (21%) is another significant weakness, increasing the risk of cross-site scripting (XSS) vulnerabilities.

Notably, the plugin has no recorded vulnerability history (CVEs), which is a positive indicator of its past security performance. However, the current static analysis findings, particularly the unprotected AJAX handlers and the high rate of unescaped output, indicate areas that require immediate attention to maintain a secure state. The absence of capability checks further exacerbates the risk associated with the unprotected entry points.

Key Concerns

  • Unprotected AJAX handlers
  • Low percentage of properly escaped output
  • Unsanitized paths in taint flows
  • Lack of capability checks
Vulnerabilities
None known

eewee sellsy Security Vulnerabilities

No known vulnerabilities — this is a good sign.
Code Analysis
Analyzed Mar 16, 2026

eewee sellsy Code Analysis

Dangerous Functions
0
Raw SQL Queries
1
18 prepared
Unescaped Output
74
20 escaped
Nonce Checks
6
Capability Checks
0
File Operations
2
External Requests
0
Bundled Libraries
0

SQL Query Safety

95% prepared19 total queries

Output Escaping

21% escaped94 total outputs
Data Flows
6 unsanitized

Data Flow Analysis

6 flows6 with unsanitized paths
<contactFormEdit> (view\contactFormEdit.php:0)
Source (user input) Sink (dangerous op) Sanitizer Transform Unsanitized Sanitized
Attack Surface
3 unprotected

eewee sellsy Attack Surface

Entry Points5
Unprotected3

AJAX Handlers 3

authwp_ajax_eewee_my_frontend_actioncontrollers\AjaxController.php:25
noprivwp_ajax_eewee_my_frontend_actioncontrollers\AjaxController.php:26
authwp_ajax_eewee_my_backend_actioncontrollers\AjaxController.php:27

Shortcodes 2

[ticketSellsy] controllers\ShortcodeController.php:17
[contactSellsy] controllers\ShortcodeController.php:18
WordPress Hooks 3
actionadmin_initcontrollers\AdminController.php:62
actioninitindex.php:69
actionadmin_menuindex.php:154
Maintenance & Trust

eewee sellsy Maintenance & Trust

Maintenance Signals

WordPress version tested4.9.29
Last updatedUnknown
PHP min version
Downloads2K

Community Trust

Rating100/100
Number of ratings2
Active installs10
Developer Profile

eewee sellsy Developer Profile

eewee

5 plugins · 50 total installs

88
trust score
Avg Security Score
91/100
Avg Patch Time
30 days
View full developer profile
Detection Fingerprints

How We Detect eewee sellsy

Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.

Asset Fingerprints

Asset Paths
/wp-content/plugins/eewee-sellsy/css/style.css
Script Paths
https://www.google.com/recaptcha/api.js/wp-content/plugins/eewee-sellsy/js/main.js/wp-content/plugins/eewee-sellsy/js/front.js
Version Parameters
eewee-sellsy/style.css?ver=

HTML / DOM Fingerprints

CSS Classes
error-msgticket-form-submitcontact-form-submitrecaptcha-area
Data Attributes
data-formid
JS Globals
ajax_object
Shortcode Output
[ticketSellsy][contactSellsy]
FAQ

Frequently Asked Questions about eewee sellsy