
Nirweb support Security & Risk Analysis
wordpress.org/plugins/nirweb-supportNirWeb support is a great help desk and support plugin for WordPress with full support of WooCommerce
Is Nirweb support Safe to Use in 2026?
Use With Caution
Score 58/100Nirweb support has 1 unpatched vulnerability. Evaluate alternatives or apply available mitigations.
The nirweb-support plugin v3.0.3 presents a significant security risk primarily due to its extensive attack surface of unprotected AJAX handlers. With 15 AJAX endpoints exposed without authentication checks, and 15 taint flows identified as having unsanitized paths with critical severity, there's a high probability of unauthorized access and data manipulation. While the plugin demonstrates good practices in using prepared statements for the vast majority of its SQL queries and incorporates nonce checks and capability checks, these strengths are heavily overshadowed by the critical vulnerabilities in its handling of user input and lack of authorization on key entry points.
The plugin's vulnerability history further exacerbates these concerns. Having two known CVEs, with one critical and currently unpatched, indicates a recurring pattern of severe security flaws. The common vulnerability types of Missing Authorization and SQL Injection are directly reflected in the static and taint analysis results. The recent nature of the last vulnerability (2025-01-31) suggests ongoing issues that have not been fully remediated. The overall security posture is therefore poor, with critical weaknesses that require immediate attention, despite some positive technical implementations within the code.
Key Concerns
- Unprotected AJAX handlers
- Critical severity taint flows
- Unpatched critical CVE
- Unsanitized paths in taint flows
- Missing Authorization vulnerability history
- SQL Injection vulnerability history
- Poor output escaping
Nirweb support Security Vulnerabilities
CVEs by Year
Severity Breakdown
2 total CVEs
Nirweb support <= 3.0.3 - Missing Authorization
Nirweb support <= 2.7.9 - SQL Injection
Nirweb support Code Analysis
SQL Query Safety
Output Escaping
Data Flow Analysis
Nirweb support Attack Surface
AJAX Handlers 15
Shortcodes 3
WordPress Hooks 30
Maintenance & Trust
Nirweb support Maintenance & Trust
Maintenance Signals
Community Trust
Nirweb support Alternatives
Awesome Support – WordPress HelpDesk & Support Plugin
awesome-support
The most versatile and feature-rich help desk and support plugin for WordPress. Provide awesome support directly from your WordPress site.
Customer Support Ticket System & Helpdesk Plugin for WordPress
wp-ticket
Create a support ticket system in WordPress. Manage customer inquiries, agents, priorities, and more with this flexible helpdesk plugin.
ELEX WordPress HelpDesk & Customer Ticketing System
elex-helpdesk-customer-support-ticket-system
ELEX WordPress HelpDesk & Customer Ticketing System offers top-notch features for the best customer support experience.
Helpdesk Support Ticket System for WooCommerce
support-ticket-system-for-woocommerce
WordPress ticket system - Manage customer queries and issues on your WordPress eShop with helpdesk WooCommerce support ticket system
Chimney Rock Support Tickets
chimney-rock-support-tickets
Create and manage support tickets for your customers or subscribers with ease.
Nirweb support Developer Profile
2 plugins · 1K total installs
How We Detect Nirweb support
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/nirweb-support/assets/css/all.min.css/wp-content/plugins/nirweb-support/assets/css/user-rtl.css/wp-content/plugins/nirweb-support/assets/css/user.css/wp-content/plugins/nirweb-support/assets/js/user.js/wp-content/plugins/nirweb-support/assets/js/user.jsHTML / DOM Fingerprints
update-pluginsupdate-countdata-upload_urldata-ajax_urldata-noncedata-reset_form_titledata-reset_form_subtitledata-reset_form_success+15 morewpyarticket