Notikumi Ticketing Security & Risk Analysis

wordpress.org/plugins/notikumi-ticketing

This plugin shows your events and your ticketing in your wordpress page.

0 active installs v1.3.3 PHP + WP 3.0.1+ Updated Jun 4, 2024
commentsspam
92
A · Safe
CVEs total0
Unpatched0
Last CVENever
Download
Safety Verdict

Is Notikumi Ticketing Safe to Use in 2026?

Generally Safe

Score 92/100

Notikumi Ticketing has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.

No known CVEs Updated 1yr ago
Risk Assessment

The "notikumi-ticketing" plugin version 1.3.3 demonstrates a generally good security posture based on the provided static analysis. The absence of any known vulnerabilities (CVEs) in its history, coupled with a complete lack of critical or high-severity taint flows, is a significant positive. Furthermore, the use of prepared statements for all SQL queries is an excellent security practice that prevents common SQL injection vulnerabilities.

However, there are areas for improvement. The significant percentage of improperly escaped output (59%) is a notable concern, potentially leading to Cross-Site Scripting (XSS) vulnerabilities. While the plugin employs nonce and capability checks, and the static analysis indicates no unprotected entry points, the volume of unescaped output suggests that user-supplied data may not be sufficiently sanitized before being rendered in the browser. The presence of file operations and external HTTP requests also introduces potential attack vectors, although the taint analysis indicates no immediate issues with path sanitization in this version.

In conclusion, "notikumi-ticketing" v1.3.3 is relatively secure due to its clean vulnerability history and robust SQL handling. The primary weakness lies in its output escaping, which requires attention to mitigate potential XSS risks. The plugin exhibits good development practices in many areas, but neglecting output sanitization remains a critical security blind spot that could be exploited.

Key Concerns

  • Significant amount of improperly escaped output
Vulnerabilities
None known

Notikumi Ticketing Security Vulnerabilities

No known vulnerabilities — this is a good sign.
Version History

Notikumi Ticketing Release Timeline

No version history available.
Code Analysis
Analyzed Mar 17, 2026

Notikumi Ticketing Code Analysis

Dangerous Functions
0
Raw SQL Queries
0
0 prepared
Unescaped Output
99
69 escaped
Nonce Checks
6
Capability Checks
3
File Operations
10
External Requests
2
Bundled Libraries
0

Output Escaping

41% escaped168 total outputs
Data Flows
All sanitized

Data Flow Analysis

2 flows
<credentials> (admin\partials\credentials.php:0)
Source (user input) Sink (dangerous op) Sanitizer Transform Unsanitized Sanitized
Attack Surface

Notikumi Ticketing Attack Surface

Entry Points1
Unprotected0

Shortcodes 1

[notikumi] includes\class-notikumi.php:189
WordPress Hooks 11
actionplugins_loadedincludes\class-notikumi.php:154
actionadmin_enqueue_scriptsincludes\class-notikumi.php:169
actionadmin_enqueue_scriptsincludes\class-notikumi.php:170
actionadmin_menuincludes\class-notikumi.php:171
actionwp_enqueue_scriptsincludes\class-notikumi.php:185
actionwp_enqueue_scriptsincludes\class-notikumi.php:186
filtergenerate_rewrite_rulesincludes\class-notikumi.php:193
filterquery_varsincludes\class-notikumi.php:194
actiontemplate_redirectincludes\class-notikumi.php:195
filterscript_loader_tagincludes\class-notikumi.php:197
filterpre_get_document_titlepublic\class-notikumi-public.php:277
Maintenance & Trust

Notikumi Ticketing Maintenance & Trust

Maintenance Signals

WordPress version tested
Last updatedJun 4, 2024
PHP min version
Downloads1K

Community Trust

Rating0/100
Number of ratings0
Active installs0
Developer Profile

Notikumi Ticketing Developer Profile

canoset

1 plugin · 0 total installs

88
trust score
Avg Security Score
92/100
Avg Patch Time
30 days
View full developer profile
Detection Fingerprints

How We Detect Notikumi Ticketing

Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.

Asset Fingerprints

Asset Paths
/wp-content/plugins/notikumi-ticketing/admin/css/notikumi-admin.css/wp-content/plugins/notikumi-ticketing/admin/js/notikumi-admin.js
Version Parameters
notikumi-ticketing/admin/css/notikumi-admin.css?ver=notikumi-ticketing/admin/js/notikumi-admin.js?ver=

HTML / DOM Fingerprints

CSS Classes
notikumi-main-menu
HTML Comments
<!-- The admin-specific functionality of the plugin. --><!-- This function is provided for demonstration purposes only. --><!-- An instance of this class should be passed to the run() function --><!-- defined in Notikumi_Loader as all of the hooks are defined -->+35 more
Data Attributes
data-toggle="dropdown"aria-expanded="false"
JS Globals
cm_settings
FAQ

Frequently Asked Questions about Notikumi Ticketing