
Order Sync with Zendesk for WooCommerce Security & Risk Analysis
wordpress.org/plugins/mwb-zendesk-woo-order-syncManage New Tickets and Orders with Zendesk Woo Order Sync
Is Order Sync with Zendesk for WooCommerce Safe to Use in 2026?
Generally Safe
Score 100/100Order Sync with Zendesk for WooCommerce has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.
The "mwb-zendesk-woo-order-sync" v2.2.1 plugin exhibits a generally good security posture, with several strengths noted in the static analysis. The absence of dangerous functions, the exclusive use of prepared statements for SQL queries, and a high percentage of properly escaped output are positive indicators. The plugin also appears to handle nonces correctly and has a history free of known vulnerabilities, suggesting a commitment to secure development practices. However, there are a few areas for concern that warrant attention.
The primary concern lies in the attack surface, specifically the presence of one REST API route that lacks a permission callback. This could potentially expose sensitive functionality to unauthenticated users. While the taint analysis did not reveal any unsanitized paths or critical/high severity flows, the lack of a permission check on a REST API endpoint is a significant oversight that bypasses WordPress's robust access control mechanisms.
Overall, the plugin is well-developed from a security perspective, with no critical or high-risk issues identified through taint analysis or its vulnerability history. The strengths in code hygiene and SQL security are commendable. Nevertheless, the unprotected REST API route is a notable weakness that should be addressed to ensure complete security. Addressing this single unprotected entry point would significantly enhance the plugin's security profile.
Key Concerns
- REST API route without permission callback
Order Sync with Zendesk for WooCommerce Security Vulnerabilities
Order Sync with Zendesk for WooCommerce Code Analysis
Output Escaping
Data Flow Analysis
Order Sync with Zendesk for WooCommerce Attack Surface
AJAX Handlers 6
REST API Routes 1
Shortcodes 1
WordPress Hooks 23
Maintenance & Trust
Order Sync with Zendesk for WooCommerce Maintenance & Trust
Maintenance Signals
Community Trust
Order Sync with Zendesk for WooCommerce Alternatives
Zendesk Support for WordPress
zendesk
Bring the helpdesk into your blog
Live Chat with Messenger Customer Chat
fb-messenger-live-chat
Support your customers via Facebook Messenger Live Chat conveniently from your own website.
Re:amaze Helpdesk & Live Chat
reamaze
Boost sales conversions, loyalty, and engagement. Manage your social, email, sms, live chat, FAQ for your WordPress or WooCommerce store.
ChipBot – Video, Live Chat, & AI Help Desk
chipbot
ChipBot turns your website into a face-to-face story experience powered by AI, video, and chat.
Guest Support
guest-support
Complete WordPress support ticket system. No login needed for users or agents. Includes spam protection, file uploads, and secure replies.
Order Sync with Zendesk for WooCommerce Developer Profile
13 plugins · 43K total installs
How We Detect Order Sync with Zendesk for WooCommerce
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/mwb-zendesk-woo-order-sync/assets/zndsk-admin.css/wp-content/plugins/mwb-zendesk-woo-order-sync/assets/zndsk-admin.js/wp-content/plugins/mwb-zendesk-woo-order-sync/assets/zndsk-admin-global.js/wp-content/plugins/mwb-zendesk-woo-order-sync/assets/zndsk-global.css/wp-content/plugins/mwb-zendesk-woo-order-sync/assets/zndsk-ticket.js/wp-content/plugins/mwb-zendesk-woo-order-sync/assets/zndsk-public-ticket.css//js.hsforms.net/forms/shell.jsmwb-zendesk-woo-order-sync/assets/zndsk-admin.css?ver=mwb-zendesk-woo-order-sync/assets/zndsk-admin.js?ver=mwb-zendesk-woo-order-sync/assets/zndsk-admin-global.js?ver=mwb-zendesk-woo-order-sync/assets/zndsk-global.css?ver=mwb-zendesk-woo-order-sync/assets/zndsk-ticket.js?ver=mwb-zendesk-woo-order-sync/assets/zndsk-public-ticket.css?ver=HTML / DOM Fingerprints
zndsk_ajax_object/wp-json/mwb-zendesk-connect-api