Helpdesk Support Ticket System for WooCommerce Security & Risk Analysis

wordpress.org/plugins/support-ticket-system-for-woocommerce

WordPress ticket system - Manage customer queries and issues on your WordPress eShop with helpdesk WooCommerce support ticket system

200 active installs v2.1.5 PHP 5.2.4+ WP 3.0.1+ Updated Feb 19, 2026
helpdeskhelpdesk-pluginsupportsupport-ticketticket-system
70
B · Generally Safe
CVEs total2
Unpatched1
Last CVESep 22, 2025
Safety Verdict

Is Helpdesk Support Ticket System for WooCommerce Safe to Use in 2026?

Mostly Safe

Score 70/100

Helpdesk Support Ticket System for WooCommerce is generally safe to use. 2 past CVEs were resolved. Keep it updated.

2 known CVEs 1 unpatched Last CVE: Sep 22, 2025Updated 1mo ago
Risk Assessment

The plugin "support-ticket-system-for-woocommerce" v2.1.5 presents a mixed security posture. On the positive side, the plugin demonstrates good practices by exclusively using prepared statements for all SQL queries and having a high percentage of properly escaped output, indicating a strong defense against common SQL injection and XSS vulnerabilities. Furthermore, the absence of dangerous functions, file operations, and external HTTP requests is commendable. However, significant concerns arise from the attack surface analysis. With two out of its four entry points (AJAX handlers) lacking authentication checks, these present direct avenues for unauthorized actions or information disclosure. While the taint analysis shows no critical or high-severity unsanitized flows, the presence of two unprotected AJAX handlers remains a significant risk. The vulnerability history is particularly alarming, with two known CVEs, one of which is critical and currently unpatched, and the other being medium. The types of past vulnerabilities, including missing authorization and unrestricted file uploads, align with the identified unprotected AJAX handlers, suggesting a recurring pattern of authorization issues. The critical unpatched vulnerability is a major red flag, demanding immediate attention.

Key Concerns

  • Unpatched critical CVE
  • Unpatched medium CVE
  • Unprotected AJAX handlers
  • Recurring missing authorization issues
Vulnerabilities
2

Helpdesk Support Ticket System for WooCommerce Security Vulnerabilities

CVEs by Year

2 CVEs in 2025 · unpatched
2025
Patched Has unpatched

Severity Breakdown

Critical
1
Medium
1

2 total CVEs

CVE-2025-57972medium · 5.4Missing Authorization

Helpdesk Support Ticket System for WooCommerce <= 2.1.1 - Missing Authorization

Sep 22, 2025 Patched in 2.1.2 (108d)
CVE-2025-60235critical · 9.8Unrestricted Upload of File with Dangerous Type

Helpdesk Support Ticket System for WooCommerce <= 2.1.0 - Unauthenticated Arbitrary File Upload

Jul 11, 2025Unpatched
Code Analysis
Analyzed Mar 16, 2026

Helpdesk Support Ticket System for WooCommerce Code Analysis

Dangerous Functions
0
Raw SQL Queries
0
7 prepared
Unescaped Output
22
475 escaped
Nonce Checks
8
Capability Checks
3
File Operations
0
External Requests
0
Bundled Libraries
0

SQL Query Safety

100% prepared7 total queries

Output Escaping

96% escaped497 total outputs
Data Flows
All sanitized

Data Flow Analysis

4 flows
responseDelete (includes.php:519)
Source (user input) Sink (dangerous op) Sanitizer Transform Unsanitized Sanitized
Attack Surface
2 unprotected

Helpdesk Support Ticket System for WooCommerce Attack Surface

Entry Points4
Unprotected2

AJAX Handlers 3

authwp_ajax_responseDeleteincludes.php:93
noprivwp_ajax_push_notsupport-ticket-system-for-woocommerce.php:98
authwp_ajax_push_notsupport-ticket-system-for-woocommerce.php:99

Shortcodes 1

[stsw_user_tickets] includes.php:100
WordPress Hooks 33
actioninitincludes\class-wpfactory-wc-sts.php:65
actionbefore_woocommerce_initincludes\class-wpfactory-wc-sts.php:68
actioninitincludes\class-wpfactory-wc-sts.php:127
actionadmin_menuincludes\class-wpfactory-wc-sts.php:130
actioninitincludes.php:85
actionadmin_initincludes.php:87
actionsave_postincludes.php:89
actionpost_updatedincludes.php:90
actionadmin_menuincludes.php:91
actionadmin_footerincludes.php:92
actionbefore_delete_postincludes.php:94
filterwoocommerce_account_menu_itemsincludes.php:96
actioninitincludes.php:97
filterwoocommerce_my_account_my_orders_actionsincludes.php:98
actionwoocommerce_account_tickets_endpointincludes.php:99
filtermanage_stsw_tickets_posts_columnsincludes.php:102
actionmanage_stsw_tickets_posts_custom_columnincludes.php:103
filtermanage_edit-stsw_tickets_sortable_columnsincludes.php:104
filtermanage_stsw_tickets_posts_columnsincludes.php:105
actionrestrict_manage_postsincludes.php:107
actionplugins_loadedincludes.php:109
actionwoocommerce_view_orderincludes.php:110
filterhookincludes.php:112
actionplugins_loadedsupport-ticket-system-for-woocommerce.php:39
actionwp_enqueue_scriptssupport-ticket-system-for-woocommerce.php:68
actionadmin_enqueue_scriptssupport-ticket-system-for-woocommerce.php:70
filterwidget_textsupport-ticket-system-for-woocommerce.php:71
actionwpfactory_wc_sts_output_settingssupport-ticket-system-for-woocommerce.php:73
actionadmin_footersupport-ticket-system-for-woocommerce.php:75
actionadmin_initsupport-ticket-system-for-woocommerce.php:77
actionall_admin_noticessupport-ticket-system-for-woocommerce.php:79
filtercodecabin_deactivate_feedback_form_pluginssupport-ticket-system-for-woocommerce.php:84
actionadmin_noticessupport-ticket-system-for-woocommerce.php:97
Maintenance & Trust

Helpdesk Support Ticket System for WooCommerce Maintenance & Trust

Maintenance Signals

WordPress version tested6.9.4
Last updatedFeb 19, 2026
PHP min version5.2.4
Downloads7K

Community Trust

Rating100/100
Number of ratings1
Active installs200
Developer Profile

Helpdesk Support Ticket System for WooCommerce Developer Profile

WPFactory

63 plugins · 136K total installs

86
trust score
Avg Security Score
97/100
Avg Patch Time
90 days
View full developer profile
Detection Fingerprints

How We Detect Helpdesk Support Ticket System for WooCommerce

Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.

Asset Fingerprints

Asset Paths
/wp-content/plugins/support-ticket-system-for-woocommerce/css/backend.css/wp-content/plugins/support-ticket-system-for-woocommerce/css/font-awesome.min.css/wp-content/plugins/support-ticket-system-for-woocommerce/css/jquery-ui.css/wp-content/plugins/support-ticket-system-for-woocommerce/js/backend.js
Script Paths
/wp-content/plugins/support-ticket-system-for-woocommerce/js/backend.js
Version Parameters
/wp-content/plugins/support-ticket-system-for-woocommerce/css/backend.css?ver=/wp-content/plugins/support-ticket-system-for-woocommerce/css/font-awesome.min.css?ver=/wp-content/plugins/support-ticket-system-for-woocommerce/css/jquery-ui.css?ver=/wp-content/plugins/support-ticket-system-for-woocommerce/js/backend.js?ver=

HTML / DOM Fingerprints

CSS Classes
stsWooCommerce_notificationsupport-ticket-system-woocommercesupport-ticket-system-woocommerceclearfixsupport-ticket-system-woocommercecolumns2proUrl
Data Attributes
data-product-id
JS Globals
STSWooCommerceAdmin
FAQ

Frequently Asked Questions about Helpdesk Support Ticket System for WooCommerce