
Majestic Support – The Leading-Edge Help Desk & Customer Support Plugin Security & Risk Analysis
wordpress.org/plugins/majestic-supportMajestic Support for WordPress is a top-tier ticket system that can significantly enhance your customers' support experience.
Is Majestic Support – The Leading-Edge Help Desk & Customer Support Plugin Safe to Use in 2026?
Use With Caution
Score 58/100Majestic Support – The Leading-Edge Help Desk & Customer Support Plugin has 1 unpatched vulnerability. Evaluate alternatives or apply available mitigations.
The 'majestic-support' plugin version 1.1.2 presents a concerning security posture. While it demonstrates good practices in output escaping and a high rate of prepared SQL statements, significant weaknesses are present. The static analysis reveals a total of 6 entry points, with 2 of them lacking proper authentication checks. Furthermore, the presence of the `unserialize` function, a known vector for serious vulnerabilities, is a critical concern. The taint analysis identified 7 high-severity flows with unsanitized paths, indicating potential for data manipulation or code execution if not handled with extreme care.
The plugin's vulnerability history is particularly alarming, with a total of 7 known CVEs, including 1 critical and 3 high-severity issues. The fact that 1 CVE remains unpatched is a direct and immediate threat. The common vulnerability types listed, such as Missing Authorization, SQL Injection, PHP Remote File Inclusion, and Authorization Bypass, strongly suggest recurring and fundamental security flaws in the plugin's design and implementation. The recurrence of these types of vulnerabilities indicates a systemic issue that needs to be addressed comprehensively.
In conclusion, despite some positive code signals, the 'majestic-support' plugin has significant security deficiencies. The combination of unprotected entry points, dangerous function usage, high-severity taint flows, and a history of critical and unpatched vulnerabilities makes this plugin a high-risk component for any WordPress installation. Organizations should exercise extreme caution and consider disabling or replacing this plugin until all identified security issues are resolved and verified.
Key Concerns
- Unpatched CVE present
- Critical severity vulnerability history (1)
- High severity vulnerability history (3)
- High severity taint flows (7)
- Dangerous function: unserialize
- Unprotected AJAX handlers (2)
- Authorization bypass vulnerability history
- PHP Remote File Inclusion vulnerability history
- SQL Injection vulnerability history
- Missing Authorization vulnerability history
- Exposure of Sensitive Information vulnerability history
Majestic Support – The Leading-Edge Help Desk & Customer Support Plugin Security Vulnerabilities
CVEs by Year
Severity Breakdown
7 total CVEs
Majestic Support <= 1.1.0 - Missing Authorization
Majestic Support <= 1.1.0 - Unauthenticated SQL Injection
Majestic Support <= 1.1.0 - Missing Authorization
Majestic Support <= 1.1.1 - Authenticated (Contributor+) Local File Inclusion
Majestic Support <= 1.0.6 - Unauthenticated Local File Inclusion
Majestic Support – The Leading-Edge Help Desk & Customer Support Plugin <= 1.0.5 - Unauthenticated Sensitive Information Exposure Through Unprotected Directory
Majestic Support – The Leading-Edge Help Desk & Customer Support Plugin <= 1.0.5 - Authenticated (Subscriber+) Insecure Direct Object Reference
Majestic Support – The Leading-Edge Help Desk & Customer Support Plugin Code Analysis
Dangerous Functions Found
SQL Query Safety
Output Escaping
Data Flow Analysis
Majestic Support – The Leading-Edge Help Desk & Customer Support Plugin Attack Surface
AJAX Handlers 2
Shortcodes 4
WordPress Hooks 89
Scheduled Events 6
Maintenance & Trust
Majestic Support – The Leading-Edge Help Desk & Customer Support Plugin Maintenance & Trust
Maintenance Signals
Community Trust
Majestic Support – The Leading-Edge Help Desk & Customer Support Plugin Alternatives
Fluent Support – Helpdesk & Customer Support Ticket System
fluent-support
Feature Rich and Super Fast Support and Customer Ticketing System for WordPress.
Customer Support Ticket System & Helpdesk Plugin for WordPress
wp-ticket
Create a support ticket system in WordPress. Manage customer inquiries, agents, priorities, and more with this flexible helpdesk plugin.
NexlifyDesk
nexlifydesk
Enterprise-grade WordPress helpdesk solution with intelligent ticket management, email piping, agent workflows, and WooCommerce integration.
Tickzo – Support Ticket System
tickzo-support-ticket-system
A professional support ticket system for WordPress with email notifications and multilingual support.
SupportCandy – Helpdesk & Customer Support Ticket System
supportcandy
Enhance your WordPress site with our helpdesk and support ticket system. Manage customer support, tickets, and email tickets efficiently.
Majestic Support – The Leading-Edge Help Desk & Customer Support Plugin Developer Profile
1 plugin · 2K total installs
How We Detect Majestic Support – The Leading-Edge Help Desk & Customer Support Plugin
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/majestic-support/css/style.css/wp-content/plugins/majestic-support/css/ms-main-style.css/wp-content/plugins/majestic-support/css/jquery-ui.min.css/wp-content/plugins/majestic-support/css/datePicker.css/wp-content/plugins/majestic-support/css/ms-admin.css/wp-content/plugins/majestic-support/css/select2.min.css/wp-content/plugins/majestic-support/css/bootstrap.min.css/wp-content/plugins/majestic-support/css/bootstrap-datetimepicker.min.css+26 more/wp-content/plugins/majestic-support/js/moment.min.js/wp-content/plugins/majestic-support/js/jquery-ui.min.js/wp-content/plugins/majestic-support/js/bootstrap.min.js/wp-content/plugins/majestic-support/js/bootstrap-datetimepicker.min.js/wp-content/plugins/majestic-support/js/tinymce/tinymce.min.js/wp-content/plugins/majestic-support/js/tinymce/plugins/textcolor/plugin.js+20 moremajestic-support/css/style.css?ver=majestic-support/css/ms-main-style.css?ver=majestic-support/css/jquery-ui.min.css?ver=majestic-support/css/datePicker.css?ver=majestic-support/css/ms-admin.css?ver=majestic-support/css/select2.min.css?ver=majestic-support/css/bootstrap.min.css?ver=majestic-support/css/bootstrap-datetimepicker.min.css?ver=majestic-support/js/moment.min.js?ver=majestic-support/js/jquery-ui.min.js?ver=majestic-support/js/bootstrap.min.js?ver=majestic-support/js/bootstrap-datetimepicker.min.js?ver=majestic-support/js/tinymce/tinymce.min.js?ver=majestic-support/js/tinymce/plugins/textcolor/plugin.js?ver=majestic-support/js/tinymce/plugins/colorpicker/plugin.js?ver=majestic-support/js/tinymce/plugins/image/plugin.js?ver=majestic-support/js/tinymce/plugins/link/plugin.js?ver=majestic-support/js/tinymce/plugins/paste/plugin.js?ver=majestic-support/js/tinymce/plugins/lists/plugin.js?ver=majestic-support/js/tinymce/plugins/autoresize/plugin.js?ver=majestic-support/js/tinymce/plugins/hr/plugin.js?ver=majestic-support/js/tinymce/plugins/code/plugin.js?ver=majestic-support/js/tinymce/plugins/table/plugin.js?ver=majestic-support/js/tinymce/plugins/tabfocus/plugin.js?ver=majestic-support/js/tinymce/plugins/insertdatetime/plugin.js?ver=majestic-support/js/tinymce/plugins/advlist/plugin.js?ver=majestic-support/js/tinymce/plugins/imagetools/plugin.js?ver=majestic-support/js/tinymce/plugins/wordcount/plugin.js?ver=majestic-support/js/tinymce/plugins/emoticons/plugin.js?ver=majestic-support/js/tinymce/plugins/template/plugin.js?ver=majestic-support/js/tinymce/themes/modern/theme.js?ver=majestic-support/js/select2.min.js?ver=majestic-support/js/ms-main-script.js?ver=majestic-support/js/ms-public-script.js?ver=HTML / DOM Fingerprints
ms-containerms-ticket-list-sectionms-ticket-detail-sectionms-new-ticket-formms-user-profile-sectionms-admin-dashboard-widget<!-- Majestic Support Plugin --><!-- End Majestic Support Plugin -->data-ms-ticket-iddata-ms-user-idmajesticsupportms_datatinymce_config/wp-json/majestic-support/v1/tickets/wp-json/majestic-support/v1/users[majestic_support_form][majestic_support_ticket_list][majestic_support_ticket_view]