Support Tickets v2 Security & Risk Analysis

wordpress.org/plugins/support-tickets-v2

With this plugin, you can manage a simple support ticket system on your WordPress site.

10 active installs v2.0.1 PHP + WP 2.8+ Updated Unknown
ajaxcaptchahelpdesksupportsupport-tickets
100
A · Safe
CVEs total0
Unpatched0
Last CVENever
Safety Verdict

Is Support Tickets v2 Safe to Use in 2026?

Generally Safe

Score 100/100

Support Tickets v2 has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.

No known CVEs
Risk Assessment

The "support-tickets-v2" plugin v2.0.1 exhibits a generally good security posture, with no known vulnerabilities or CVEs in its history. The static analysis reveals a commendable effort in implementing secure coding practices, such as a high percentage of SQL queries using prepared statements and properly escaped output. The absence of a significant attack surface, particularly unprotected entry points, is a strong positive indicator. However, several areas warrant attention. The presence of dangerous functions like `preg_replace(/e)` and `create_function` indicates potential for remote code execution if not handled with extreme care and user input validation. Furthermore, the taint analysis highlights a concerning number of flows with unsanitized paths, specifically four classified as high severity. This suggests potential vulnerabilities where user-supplied data might be used in a way that leads to unintended consequences or security breaches.

Key Concerns

  • High severity unsanitized paths found
  • Dangerous function: preg_replace(/e)
  • Dangerous function: create_function
  • File operations detected
Vulnerabilities
None known

Support Tickets v2 Security Vulnerabilities

No known vulnerabilities — this is a good sign.
Code Analysis
Analyzed Mar 16, 2026

Support Tickets v2 Code Analysis

Dangerous Functions
2
Raw SQL Queries
8
68 prepared
Unescaped Output
36
241 escaped
Nonce Checks
12
Capability Checks
2
File Operations
1
External Requests
0
Bundled Libraries
0

Dangerous Functions Found

preg_replace(/e)preg_replace( '|\s*</eincludes\formatting.php:16
create_function$pee = preg_replace_callback( '/<(script|style|textarea).*?<\/\\1>/s', create_function( '$matches', includes\formatting.php:34

SQL Query Safety

89% prepared76 total queries

Output Escaping

87% escaped277 total outputs
Data Flows
6 unsanitized

Data Flow Analysis

15 flows6 with unsanitized paths
<edit-forms> (admin\edit-forms.php:0)
Source (user input) Sink (dangerous op) Sanitizer Transform Unsanitized Sanitized
Attack Surface

Support Tickets v2 Attack Surface

Entry Points0
Unprotected0
WordPress Hooks 54
actionadmin_headadmin\admin.php:3
actionwp_print_scriptsadmin\admin.php:32
actionadmin_menuadmin\admin.php:89
actionwp_dashboard_setupadmin\admin.php:334
filtersuptic_pre_message_bodyincludes\classes.php:1423
filtersuptic_pre_message_bodyincludes\classes.php:1424
filtersuptic_message_bodyincludes\classes.php:1426
filtersuptic_message_bodyincludes\classes.php:1427
filtersuptic_message_bodyincludes\classes.php:1428
filtersuptic_message_bodyincludes\classes.php:1429
filtersuptic_message_bodyincludes\classes.php:1430
filtersuptic_message_bodyincludes\classes.php:1431
actioninitincludes\controller.php:3
filterthe_contentincludes\controller.php:210
actionsuptic_control_create_ticketincludes\notifications-toxikos.php:3
actionsuptic_control_add_messageincludes\notifications-toxikos.php:53
actionsuptic_control_create_ticketincludes\notifications.php:3
actionsuptic_control_add_messageincludes\notifications.php:41
filtersuptic_acceptancemodules\acceptance.php:60
filtersuptic_validate_captcharmodules\captcha.php:108
filtersuptic_ajax_json_echomodules\captcha.php:131
filtersuptic_validate_checkboxmodules\checkbox.php:118
filtersuptic_validate_checkbox*modules\checkbox.php:119
filtersuptic_validate_radiomodules\checkbox.php:120
filtersuptic_form_tagmodules\icl.php:52
actionsuptic_after_save_formmodules\icl.php:121
filtersuptic_get_form_for_pagemodules\icl.php:209
actionsuptic_after_create_ticketmodules\icl.php:240
filtersuptic_edit_tickets_subsubsubmodules\icl.php:248
actionsuptic_admin_tickets_filtermodules\icl.php:286
filtersuptic_admin_tickets_on_edit_ticketsmodules\icl.php:299
filtersuptic_ticket_message_inputmodules\icl.php:417
actionsuptic_after_create_messagemodules\icl.php:450
actioninitmodules\icl.php:488
filtersuptic_message_bodymodules\icl.php:561
actioninitmodules\icl.php:637
actionwp_headmodules\icl.php:664
actionsuptic_after_delete_ticketmodules\icl.php:719
actionsuptic_after_delete_messagemodules\icl.php:725
filtersuptic_message_bodymodules\paypal.php:4
filtersuptic_validate_quizmodules\quiz.php:86
filtersuptic_ajax_json_echomodules\quiz.php:106
filtersuptic_validate_selectmodules\select.php:100
filtersuptic_validate_select*modules\select.php:101
filtersuptic_validate_textmodules\text.php:89
filtersuptic_validate_text*modules\text.php:90
filtersuptic_validate_emailmodules\text.php:91
filtersuptic_validate_email*modules\text.php:92
filtersuptic_validate_textareamodules\textarea.php:80
filtersuptic_validate_textarea*modules\textarea.php:81
actionplugins_loadedsettings.php:85
actionwp_headsettings.php:99
actionwp_print_scriptssettings.php:108
actioninitsettings.php:131
Maintenance & Trust

Support Tickets v2 Maintenance & Trust

Maintenance Signals

WordPress version tested3.4.2
Last updatedUnknown
PHP min version
Downloads9K

Community Trust

Rating80/100
Number of ratings4
Active installs10
Developer Profile

Support Tickets v2 Developer Profile

kezakez

1 plugin · 10 total installs

94
trust score
Avg Security Score
100/100
Avg Patch Time
30 days
View full developer profile
Detection Fingerprints

How We Detect Support Tickets v2

Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.

Asset Fingerprints

Asset Paths
/wp-content/plugins/support-tickets-v2/settings.css/wp-content/plugins/support-tickets-v2/ticket.css/wp-content/plugins/support-tickets-v2/ticket.js
Script Paths
/wp-content/plugins/support-tickets-v2/admin/scripts.js
Version Parameters
support-tickets-v2/settings.css?ver=support-tickets-v2/ticket.css?ver=support-tickets-v2/ticket.js?ver=support-tickets-v2/admin/scripts.js?ver=

HTML / DOM Fingerprints

CSS Classes
suptic-formsuptic-messagesuptic-ticket-form-wrapsuptic-ticket-form
HTML Comments
<!-- You can edit this file to adjust the plugin's output -->
Data Attributes
data-suptic-plugin-url
JS Globals
_suptic
FAQ

Frequently Asked Questions about Support Tickets v2