Product Ticket System For WooCommerce Security & Risk Analysis

wordpress.org/plugins/product-ticket-system-for-woocommerce

Boost customer support with our WooCommerce Product Ticket System. Let customers create tickets from orders; admins manage with ease.

0 active installs v1.0 PHP 5.6+ WP 6.0+ Updated May 13, 2024
orderproductsupportticketwoocommerce
92
A · Safe
CVEs total0
Unpatched0
Last CVENever
Download
Safety Verdict

Is Product Ticket System For WooCommerce Safe to Use in 2026?

Generally Safe

Score 92/100

Product Ticket System For WooCommerce has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.

No known CVEs Updated 1yr ago
Risk Assessment

The "product-ticket-system-for-woocommerce" plugin version 1.0 demonstrates a generally strong security posture based on the provided static analysis and vulnerability history. The absence of any known CVEs, coupled with a low number of identified code signals like dangerous functions and file operations, is a positive indicator. The plugin also shows good practices in output escaping (90%) and uses prepared statements for a majority of its SQL queries (73%).

However, there are areas for improvement. The presence of 3 AJAX handlers, even without immediately apparent authentication flaws, represents a potential attack surface that requires careful review. While the taint analysis did not reveal any critical or high-severity unsanitized flows, this is a dynamic analysis component and does not cover all potential exploitation vectors. The single capability check and 10 nonce checks, while present, could be more robust depending on the functionality of the AJAX endpoints.

In conclusion, the plugin appears to be well-developed from a security perspective, with no historical vulnerabilities and good implementation of security best practices in areas like SQL querying and output sanitization. The primary area of concern lies within the AJAX endpoints, which warrant further scrutiny to ensure all actions are adequately protected against unauthorized access or manipulation.

Key Concerns

  • AJAX handlers present, requires careful review
  • SQL queries have a portion not using prepared statements
  • Output escaping is good, but not 100%
Vulnerabilities
None known

Product Ticket System For WooCommerce Security Vulnerabilities

No known vulnerabilities — this is a good sign.
Code Analysis
Analyzed Mar 17, 2026

Product Ticket System For WooCommerce Code Analysis

Dangerous Functions
0
Raw SQL Queries
4
11 prepared
Unescaped Output
26
242 escaped
Nonce Checks
10
Capability Checks
1
File Operations
0
External Requests
0
Bundled Libraries
1

Bundled Libraries

Select2

SQL Query Safety

73% prepared15 total queries

Output Escaping

90% escaped268 total outputs
Data Flows
All sanitized

Data Flow Analysis

4 flows
<wcpt-save-settings> (inc\admin\partials\wcpt-save-settings.php:0)
Source (user input) Sink (dangerous op) Sanitizer Transform Unsanitized Sanitized
Attack Surface

Product Ticket System For WooCommerce Attack Surface

Entry Points3
Unprotected0

AJAX Handlers 3

authwp_ajax_orders_productsinc\class.wcpt.php:56
authwp_ajax_ysl_product_ticketinc\class.wcpt.php:57
authwp_ajax_chatajaxinc\class.wcpt.php:58
WordPress Hooks 34
actionadmin_menuinc\admin\class.wcpt.admin.action.php:25
actionadmin_initinc\admin\class.wcpt.admin.action.php:26
actionadd_meta_boxes_product_ticketinc\admin\class.wcpt.admin.action.php:28
actionsave_post_product_ticketinc\admin\class.wcpt.admin.action.php:29
actionwp_loadedinc\admin\class.wcpt.admin.action.php:31
actionmanage_posts_custom_columninc\admin\class.wcpt.admin.action.php:33
actionbulk_edit_custom_boxinc\admin\class.wcpt.admin.action.php:34
actionsave_postinc\admin\class.wcpt.admin.action.php:35
actionplugins_loadedinc\admin\class.wcpt.admin.action.php:227
filterwoocommerce_prevent_admin_accessinc\admin\class.wcpt.admin.filter.php:24
filtermanage_posts_columnsinc\admin\class.wcpt.admin.filter.php:25
filterwp_editor_settingsinc\admin\class.wcpt.admin.filter.php:26
actionplugins_loadedinc\admin\class.wcpt.admin.filter.php:83
actionplugins_loadedinc\admin\class.wcpt.admin.php:64
actioninitinc\class.wcpt.php:43
actioninitinc\class.wcpt.php:45
actionplugins_loadedinc\class.wcpt.php:47
actionwp_enqueue_scriptsinc\class.wcpt.php:49
actionwp_enqueue_scriptsinc\class.wcpt.php:50
actionadmin_enqueue_scriptsinc\class.wcpt.php:51
filterquery_varsinc\class.wcpt.php:53
filterwoocommerce_account_menu_itemsinc\class.wcpt.php:54
actioncurrent_screeninc\class.wcpt.php:59
actionadmin_print_scriptsinc\class.wcpt.php:85
actionwp_enqueue_scriptsinc\front\class.wcpt.front.action.php:25
actionwoocommerce_account_viewticket_endpointinc\front\class.wcpt.front.action.php:26
actionwoocommerce_account_mytickets_endpointinc\front\class.wcpt.front.action.php:27
actionplugins_loadedinc\front\class.wcpt.front.action.php:494
filterwoocommerce_my_account_my_orders_actionsinc\front\class.wcpt.front.filter.php:26
filterthe_titleinc\front\class.wcpt.front.filter.php:27
actionplugins_loadedinc\front\class.wcpt.front.filter.php:91
actionplugins_loadedinc\front\class.wcpt.front.php:65
actionadmin_initysl-product-ticket.php:110
actionadmin_noticesysl-product-ticket.php:121
Maintenance & Trust

Product Ticket System For WooCommerce Maintenance & Trust

Maintenance Signals

WordPress version tested6.5.8
Last updatedMay 13, 2024
PHP min version5.6
Downloads576

Community Trust

Rating0/100
Number of ratings0
Active installs0
Developer Profile

Product Ticket System For WooCommerce Developer Profile

Yudiz Solutions Pvt. Ltd.

14 plugins · 6K total installs

85
trust score
Avg Security Score
96/100
Avg Patch Time
59 days
View full developer profile
Detection Fingerprints

How We Detect Product Ticket System For WooCommerce

Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.

Asset Fingerprints

Asset Paths
/wp-content/plugins/product-ticket-system-for-woocommerce/assets/css/select2.min.css/wp-content/plugins/product-ticket-system-for-woocommerce/assets/js/select2.min.js/wp-content/plugins/product-ticket-system-for-woocommerce/inc/admin/partials/wcpt-settings.php/wp-content/plugins/product-ticket-system-for-woocommerce/inc/front/class.wcpt.front.action.php/wp-content/plugins/product-ticket-system-for-woocommerce/inc/front/class.wcpt.front.filter.php/wp-content/plugins/product-ticket-system-for-woocommerce/inc/front/class.wcpt.front.php/wp-content/plugins/product-ticket-system-for-woocommerce/inc/admin/class.wcpt.admin.action.php/wp-content/plugins/product-ticket-system-for-woocommerce/inc/admin/class.wcpt.admin.filter.php+2 more
Script Paths
/wp-content/plugins/product-ticket-system-for-woocommerce/assets/js/select2.min.js
Version Parameters
product-ticket-system-for-woocommerce/assets/css/select2.min.css?ver=product-ticket-system-for-woocommerce/assets/js/select2.min.js?ver=

HTML / DOM Fingerprints

HTML Comments
<!-- Plugin Settings. --><!-- Action: admin_init --><!-- Register admin min js and admin css --><!-- ## ###### ######## #### ####### ## ## ###### -->+12 more
Data Attributes
wcpt_meta_prefixwcpt_prefix
JS Globals
WCPT_VERSIONWCPT_FILEWCPT_DIRWCPT_URLWCPT_PLUGIN_BASENAMEWCPT_META_PREFIX+1 more
FAQ

Frequently Asked Questions about Product Ticket System For WooCommerce