
Event Tickets with Ticket Scanner Security & Risk Analysis
wordpress.org/plugins/event-tickets-with-ticket-scannerSell event tickets with WooCommerce. Design seating plans, generate PDF tickets with QR codes, and scan them at the door. No per-ticket fees.
Is Event Tickets with Ticket Scanner Safe to Use in 2026?
Generally Safe
Score 86/100Event Tickets with Ticket Scanner has a strong security track record. Known vulnerabilities have been patched promptly.
The 'event-tickets-with-ticket-scanner' plugin v2.9.8 presents a mixed security posture. While it demonstrates some good practices, such as a high percentage of prepared SQL statements and a significant portion of properly escaped output, there are notable areas of concern. The presence of the `unserialize` function without explicit sanitization is a significant risk, especially given the plugin's vulnerability history which includes code injection and CSRF, often exploitable through deserialization vulnerabilities. The taint analysis revealing flows with unsanitized paths, including one of high severity, directly points to potential vulnerabilities that could be leveraged by attackers. Furthermore, the plugin has a history of 7 known CVEs, with past critical and high-severity issues, suggesting a recurring pattern of security weaknesses that may not be fully addressed by current versions, despite the absence of currently unpatched CVEs.
While the static analysis shows a low attack surface in terms of entry points like AJAX, REST API, and shortcodes, this can be misleading if the existing code paths are not thoroughly secured. The bundled libraries, DataTables v1.10.21 and TCPDF v1.0.004, are outdated and could harbor known vulnerabilities. The plugin's past vulnerability types (Code Injection, CSRF, XSS) are classic indicators of potential weaknesses in input handling and state management, which are often exacerbated by insecure deserialization. In conclusion, while efforts have been made to secure SQL queries and output, the presence of dangerous functions, concerning taint flows, outdated bundled libraries, and a history of severe vulnerabilities necessitate caution.
Key Concerns
- Dangerous function unserialize found
- Taint flow: High severity
- Taint flow with unsanitized path (x2)
- Outdated bundled library: DataTables v1.10.21
- Outdated bundled library: TCPDF v1.0.004
- History of 1 critical CVE (potentially unaddressed)
- History of 1 high CVE (potentially unaddressed)
- History of 5 medium CVEs (potentially unaddressed)
Event Tickets with Ticket Scanner Security Vulnerabilities
CVEs by Year
Severity Breakdown
7 total CVEs
Event Tickets with Ticket Scanner <= 2.8.5 - Unauthenticated Remote Code Execution
Event Tickets with Ticket Scanner <= 2.5.3 - Cross-Site Request Forgery to Arbitrary Ticket Deletion
Event Tickets with Ticket Scanner <= 2.4.4 - Missing Authorization to Authenticated (Subscriber+) Stored Cross-Site Scripting
Event Tickets with Ticket Scanner <= 2.3.11 - Authenticated (Author+) Remote Code Execution
Event Tickets with Ticket Scanner <= 2.3.7 - Authenticated (Admin+) Stored Cross-Site Scripting
Event Tickets with Ticket Scanner <= 2.3.1 - Reflected Cross-Site Scripting
Event Tickets with Ticket Scanner <= 1.5.4 - Authenticated (Subscriber+) Stored Cross-Site Scripting
Event Tickets with Ticket Scanner Code Analysis
Dangerous Functions Found
Bundled Libraries
SQL Query Safety
Output Escaping
Data Flow Analysis
Event Tickets with Ticket Scanner Attack Surface
WordPress Hooks 69
Scheduled Events 1
Maintenance & Trust
Event Tickets with Ticket Scanner Maintenance & Trust
Maintenance Signals
Community Trust
Event Tickets with Ticket Scanner Alternatives
Sugar Calendar – Events Calendar, Event Tickets, and Events Management Platform
sugar-calendar-lite
Easily manage events and sell tickets on your WordPress site. Sugar Calendar is easy-to-use, reliable, and exceptionally powerful. See for yourself.
Eventin – Events Calendar, Event Booking, Ticket & Registration (AI Powered)
wp-event-solution
Create and manage events with a flexible WordPress events calendar plugin. Add recurring events, RSVP, ticket booking, and WooCommerce ticket selling …
My Tickets – Accessible Event Ticketing
my-tickets
My Tickets is a simple, flexible platform for selling event tickets with WordPress.
Easy Custom Event Tickets
custom-event-tickets
Dupliquez vos événements et affichez la liste des participants pour The Events Calendar et Event Tickets.
Event RSVP and Simple Event Management Plugin
wp-easy-events
Event management, RSVP and event tickets system with event calendar, event venues with maps and event organizers.
Event Tickets with Ticket Scanner Developer Profile
2 plugins · 2K total installs
How We Detect Event Tickets with Ticket Scanner
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/event-tickets-with-ticket-scanner/css/frontend.css/wp-content/plugins/event-tickets-with-ticket-scanner/css/admin.css/wp-content/plugins/event-tickets-with-ticket-scanner/js/frontend.js/wp-content/plugins/event-tickets-with-ticket-scanner/js/backend.js/wp-content/plugins/event-tickets-with-ticket-scanner/js/saso-eventtickets-validator.js/wp-content/plugins/event-tickets-with-ticket-scanner/js/frontend.js/wp-content/plugins/event-tickets-with-ticket-scanner/js/backend.js/wp-content/plugins/event-tickets-with-ticket-scanner/js/saso-eventtickets-validator.jsevent-tickets-with-ticket-scanner/css/frontend.css?ver=event-tickets-with-ticket-scanner/css/admin.css?ver=event-tickets-with-ticket-scanner/js/frontend.js?ver=event-tickets-with-ticket-scanner/js/backend.js?ver=event-tickets-with-ticket-scanner/js/saso-eventtickets-validator.js?ver=HTML / DOM Fingerprints
sasoEventticketssasoEventtickets_admin<!-- Start sasoEventtickets --><!-- End sasoEventtickets -->data-saso-eventtickets-noncedata-saso-eventtickets-actionsasoEventticketssasoEventtickets_frontend_jssasoEventtickets_backend_jssasoEventtickets_validator_js/wp-json/sasoEventtickets/v1/executeFrontend/wp-json/sasoEventtickets/v1/executeWCBackend/wp-json/sasoEventtickets/v1/downloadMyCodesAsPDF[sasoEventTicketsValidator][sasoEventTicketsValidator_code][sasoEventTicketsValidator_eventsview][sasoEventTicketsValidator_ticket_scanner]