
Order Sync with Zendesk for WooCommerce Security & Risk Analysis
wordpress.org/plugins/mwb-zendesk-woo-order-syncManage Customer Support Tickets and Orders with Zendesk Woo Order Sync
Is Order Sync with Zendesk for WooCommerce Safe to Use in 2026?
Generally Safe
Score 100/100Order Sync with Zendesk for WooCommerce has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.
The "mwb-zendesk-woo-order-sync" v2.2.1 plugin exhibits a generally good security posture, with several strengths noted in the static analysis. The absence of dangerous functions, the exclusive use of prepared statements for SQL queries, and a high percentage of properly escaped output are positive indicators. The plugin also appears to handle nonces correctly and has a history free of known vulnerabilities, suggesting a commitment to secure development practices. However, there are a few areas for concern that warrant attention.
The primary concern lies in the attack surface, specifically the presence of one REST API route that lacks a permission callback. This could potentially expose sensitive functionality to unauthenticated users. While the taint analysis did not reveal any unsanitized paths or critical/high severity flows, the lack of a permission check on a REST API endpoint is a significant oversight that bypasses WordPress's robust access control mechanisms.
Overall, the plugin is well-developed from a security perspective, with no critical or high-risk issues identified through taint analysis or its vulnerability history. The strengths in code hygiene and SQL security are commendable. Nevertheless, the unprotected REST API route is a notable weakness that should be addressed to ensure complete security. Addressing this single unprotected entry point would significantly enhance the plugin's security profile.
Key Concerns
- REST API route without permission callback
Order Sync with Zendesk for WooCommerce Security Vulnerabilities
Order Sync with Zendesk for WooCommerce Release Timeline
Order Sync with Zendesk for WooCommerce Code Analysis
Output Escaping
Data Flow Analysis
Order Sync with Zendesk for WooCommerce Attack Surface
AJAX Handlers 6
REST API Routes 1
Shortcodes 1
WordPress Hooks 23
Maintenance & Trust
Order Sync with Zendesk for WooCommerce Maintenance & Trust
Maintenance Signals
Community Trust
Order Sync with Zendesk for WooCommerce Alternatives
Zendesk Support for WordPress
zendesk
Bring the helpdesk into your blog
Integration for Epos Now and WooCommerce
woo-epos-now-integration
Seamlessly integrate WooCommerce and Epos Now.
WP Gravity Forms Zendesk
gf-zendesk
Gravity Forms Zendesk Add-on sends Gravity Forms entries to Zendesk.
Yetix Request Form for Zendesk
yetix-request-form
Zendesk Ticket Form into your WordPress site.
Bizzmags Sync for Trendyol and WC
bizzmagssynctrendyolwc
Connect WooCommerce with Trendyol Marketplace and automate product, stock, and order synchronization.
Order Sync with Zendesk for WooCommerce Developer Profile
13 plugins · 42K total installs
How We Detect Order Sync with Zendesk for WooCommerce
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/mwb-zendesk-woo-order-sync/assets/zndsk-admin.css/wp-content/plugins/mwb-zendesk-woo-order-sync/assets/zndsk-admin.js/wp-content/plugins/mwb-zendesk-woo-order-sync/assets/zndsk-admin-global.js/wp-content/plugins/mwb-zendesk-woo-order-sync/assets/zndsk-global.css/wp-content/plugins/mwb-zendesk-woo-order-sync/assets/zndsk-ticket.js/wp-content/plugins/mwb-zendesk-woo-order-sync/assets/zndsk-public-ticket.css//js.hsforms.net/forms/shell.jsmwb-zendesk-woo-order-sync/assets/zndsk-admin.css?ver=mwb-zendesk-woo-order-sync/assets/zndsk-admin.js?ver=mwb-zendesk-woo-order-sync/assets/zndsk-admin-global.js?ver=mwb-zendesk-woo-order-sync/assets/zndsk-global.css?ver=mwb-zendesk-woo-order-sync/assets/zndsk-ticket.js?ver=mwb-zendesk-woo-order-sync/assets/zndsk-public-ticket.css?ver=HTML / DOM Fingerprints
zndsk_ajax_object/wp-json/mwb-zendesk-connect-api