GRT Ticket Security & Risk Analysis

wordpress.org/plugins/grt-ticket

A support ticket system with real-time chat, email piping, custom fields, and Webhook integrations (Slack/Discord/Zapier).

0 active installs v1.2.4 PHP + WP 5.0+ Updated Mar 12, 2026
chathelpdesksupportticketwebhooks
100
A · Safe
CVEs total0
Unpatched0
Last CVENever
Safety Verdict

Is GRT Ticket Safe to Use in 2026?

Generally Safe

Score 100/100

GRT Ticket has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.

No known CVEs Updated 5mo ago
Risk Assessment

The grt-ticket plugin v1.2.4 exhibits a mixed security posture. On the positive side, it demonstrates strong adherence to secure coding practices in several key areas. The plugin has no recorded vulnerabilities or CVEs, indicating a potentially stable security history. Furthermore, the code shows excellent output escaping (98%), a low incidence of dangerous functions, and robust use of prepared statements for SQL queries (58%). The absence of critical or high severity taint analysis flows is also a very positive sign.

However, a significant concern lies in its attack surface. A substantial portion of its entry points, specifically 20 out of 21 total, lack authentication checks. This is primarily driven by a large number of AJAX handlers (20) that do not implement proper authorization. While there are 20 nonce checks present, their effectiveness is diminished if not properly implemented in conjunction with capability checks for all AJAX endpoints. The presence of file operations and external HTTP requests, though not inherently insecure, warrants careful scrutiny in conjunction with the lack of authentication on these entry points.

In conclusion, while grt-ticket v1.2.4 shows good internal coding hygiene regarding output escaping and SQL preparation, the overwhelming lack of authentication on its AJAX handlers presents a critical security risk. This vast unprotected attack surface significantly outweighs the positive aspects and makes the plugin vulnerable to unauthorized actions if not immediately addressed by adding proper authentication and authorization checks to all its AJAX endpoints.

Key Concerns

  • Large attack surface without auth checks (AJAX)
  • High number of AJAX handlers without auth checks
  • File operations present
  • External HTTP requests present
Vulnerabilities
None known

GRT Ticket Security Vulnerabilities

No known vulnerabilities — this is a good sign.
Version History

GRT Ticket Release Timeline

v1.2.4Current
v1.1.4
Code Analysis
Analyzed Mar 17, 2026

GRT Ticket Code Analysis

Dangerous Functions
0
Raw SQL Queries
19
26 prepared
Unescaped Output
8
358 escaped
Nonce Checks
20
Capability Checks
18
File Operations
1
External Requests
8
Bundled Libraries
0

SQL Query Safety

58% prepared45 total queries

Output Escaping

98% escaped366 total outputs
Data Flows · Security
All sanitized

Data Flow Analysis

4 flows
<settings-page> (admin\partials\settings-page.php:0)
Source (user input) Sink (dangerous op) Sanitizer Transform Unsanitized Sanitized
Attack Surface
20 unprotected

GRT Ticket Attack Surface

Entry Points21
Unprotected20

AJAX Handlers 20

authwp_ajax_grt_ticket_submitincludes\class-grt-ticket.php:197
noprivwp_ajax_grt_ticket_submitincludes\class-grt-ticket.php:198
authwp_ajax_grt_ticket_send_messageincludes\class-grt-ticket.php:200
noprivwp_ajax_grt_ticket_send_messageincludes\class-grt-ticket.php:201
authwp_ajax_grt_ticket_get_messagesincludes\class-grt-ticket.php:203
noprivwp_ajax_grt_ticket_get_messagesincludes\class-grt-ticket.php:204
authwp_ajax_grt_ticket_get_ticketsincludes\class-grt-ticket.php:206
noprivwp_ajax_grt_ticket_get_ticketsincludes\class-grt-ticket.php:207
authwp_ajax_grt_ticket_submit_ratingincludes\class-grt-ticket.php:209
noprivwp_ajax_grt_ticket_submit_ratingincludes\class-grt-ticket.php:210
authwp_ajax_grt_upload_profile_imageincludes\class-grt-ticket.php:213
authwp_ajax_grt_ticket_update_typing_statusincludes\class-grt-ticket.php:216
noprivwp_ajax_grt_ticket_update_typing_statusincludes\class-grt-ticket.php:217
authwp_ajax_grt_ticket_mark_solvedincludes\class-grt-ticket.php:220
authwp_ajax_grt_ticket_deleteincludes\class-grt-ticket.php:221
authwp_ajax_grt_bulk_actionincludes\class-grt-ticket.php:222
authwp_ajax_grt_ticket_assign_agentincludes\class-grt-ticket.php:223
authwp_ajax_grt_save_form_builderincludes\class-grt-ticket.php:224
authwp_ajax_grt_test_supabase_connectionincludes\class-grt-ticket.php:225
authwp_ajax_grt_test_supabase_pushincludes\class-grt-ticket.php:226

Shortcodes 1

[grt_ticket] public\class-grt-ticket-public.php:247
WordPress Hooks 15
actionplugins_loadedincludes\class-grt-ticket.php:115
actionadmin_enqueue_scriptsincludes\class-grt-ticket.php:128
actionadmin_enqueue_scriptsincludes\class-grt-ticket.php:129
actionadmin_menuincludes\class-grt-ticket.php:130
actionadmin_initincludes\class-grt-ticket.php:131
actioninitincludes\class-grt-ticket.php:160
actionwp_enqueue_scriptsincludes\class-grt-ticket.php:161
actionwp_enqueue_scriptsincludes\class-grt-ticket.php:162
actioninitincludes\class-grt-ticket.php:163
actiongrt_ticket_check_emails_cronincludes\class-grt-ticket.php:176
filtercron_schedulesincludes\class-grt-ticket.php:177
actiongrt_ticket_auto_close_cronincludes\class-grt-ticket.php:184
filterquery_varspublic\class-grt-ticket-public.php:51
filterrequestpublic\class-grt-ticket-public.php:58
actionshutdownpublic\class-grt-ticket-public.php:254

Scheduled Events 2

grt_ticket_check_emails_cron
grt_ticket_auto_close_cron
Maintenance & Trust

GRT Ticket Maintenance & Trust

Maintenance Signals

WordPress version tested6.9.5
Last updatedMar 12, 2026
PHP min version
Downloads490

Community Trust

Rating100/100
Number of ratings1
Active installs0
Developer Profile

GRT Ticket Developer Profile

Ridhwan Ahsan

6 plugins · 10 total installs

94
trust score
Avg Security Score
100/100
Avg Patch Time
30 days
View full developer profile
Detection Fingerprints

How We Detect GRT Ticket

Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.

Asset Fingerprints

Asset Paths
/wp-content/plugins/grt-ticket/assets/grt-ticket.css/wp-content/plugins/grt-ticket/assets/grt-ticket.js/wp-content/plugins/grt-ticket/admin/build/assets/index-*.js/wp-content/plugins/grt-ticket/admin/build/assets/index-*.css
Script Paths
/wp-content/plugins/grt-ticket/assets/grt-ticket.js
Version Parameters
grt-ticket/assets/grt-ticket.css?ver=grt-ticket/assets/grt-ticket.js?ver=grt-ticket/admin/build/assets/index.js?ver=grt-ticket/admin/build/assets/index.css?ver=

HTML / DOM Fingerprints

CSS Classes
grt-ticket-chat-containergrt-ticket-chat-messagegrt-ticket-chat-inputgrt-ticket-admin-ticket-listgrt-ticket-settings-section
HTML Comments
<!-- GRT Ticket Admin UI -->
Data Attributes
data-grt-ticket-chatdata-grt-ticket-ticket-iddata-grt-ticket-user-id
JS Globals
grtTicketDatagrtTicketAdmin
REST Endpoints
/wp-json/grt-ticket/v1/tickets/wp-json/grt-ticket/v1/chat
Shortcode Output
[grt_ticket_chat][grt_ticket_support]
FAQ

Frequently Asked Questions about GRT Ticket