
CRM Perks – WordPress HelpDesk Integration – Zendesk, Freshdesk, HelpScout Security & Risk Analysis
wordpress.org/plugins/support-xShow user tickets from HelpScout, ZenDesk, FreshDesk and Teamwork in wordpress. Users can create new support tickets and reply to old tickets.
Is CRM Perks – WordPress HelpDesk Integration – Zendesk, Freshdesk, HelpScout Safe to Use in 2026?
Generally Safe
Score 97/100CRM Perks – WordPress HelpDesk Integration – Zendesk, Freshdesk, HelpScout has a strong security track record. Known vulnerabilities have been patched promptly.
The 'support-x' plugin version 1.1.8 exhibits a mixed security posture. While it demonstrates good practices like using prepared statements for all SQL queries and having no currently unpatched CVEs, significant concerns arise from its attack surface and output escaping. The presence of three AJAX handlers without authentication checks presents a direct entry point for potential attackers to exploit. Furthermore, the low percentage of properly escaped output (14%) indicates a high risk of Cross-Site Scripting (XSS) vulnerabilities, which is corroborated by its vulnerability history containing three medium severity XSS issues. Although the taint analysis shows no critical or high severity unsanitized flows, the combination of unprotected entry points and poor output sanitization warrants caution. The plugin's history of XSS vulnerabilities and the static analysis findings suggest a recurring weakness in input validation and output sanitization, which attackers could potentially leverage, especially given the unprotected AJAX endpoints. Therefore, while some secure coding practices are in place, the identified weaknesses, particularly the unprotected AJAX handlers and widespread unescaped output, significantly elevate the risk.
Key Concerns
- Unprotected AJAX handlers
- Low percentage of properly escaped output
- Flows with unsanitized paths (Taint Analysis)
- Medium severity XSS vulnerabilities in history
CRM Perks – WordPress HelpDesk Integration – Zendesk, Freshdesk, HelpScout Security Vulnerabilities
CVEs by Year
Severity Breakdown
3 total CVEs
CRM Perks <= 1.1.7 - Reflected Cross-Site Scripting
CRM Perks – WordPress HelpDesk Integration – Zendesk, Freshdesk, HelpScout <= 1.1.6 - Authenticated (Contributor+) Stored Cross-Site Scripting
CRM Perks – WordPress HelpDesk Integration – Zendesk, Freshdesk, HelpScout <= 1.1.5 - Reflected Cross-Site Scripting
CRM Perks – WordPress HelpDesk Integration – Zendesk, Freshdesk, HelpScout Code Analysis
Output Escaping
Data Flow Analysis
CRM Perks – WordPress HelpDesk Integration – Zendesk, Freshdesk, HelpScout Attack Surface
AJAX Handlers 3
Shortcodes 2
WordPress Hooks 11
Maintenance & Trust
CRM Perks – WordPress HelpDesk Integration – Zendesk, Freshdesk, HelpScout Maintenance & Trust
Maintenance Signals
Community Trust
CRM Perks – WordPress HelpDesk Integration – Zendesk, Freshdesk, HelpScout Alternatives
Zendesk Support for WordPress
zendesk
Bring the helpdesk into your blog
Freshdesk (official)
freshdesk-support
Quickly embed the Freshdesk help widget, convert WordPress comments to tickets and seamlessly log your WordPress users into your support portal.
Viable Support for Zendesk
viable-support-for-zendesk
Connect your Zendesk Support account with WordPress — create tickets, sync custom fields, and automatically convert comments into Zendesk tickets.
Fluent Support – Helpdesk & Customer Support Ticket System
fluent-support
Feature Rich and Super Fast Support and Customer Ticketing System for WordPress.
SupportCandy – Helpdesk & Customer Support Ticket System
supportcandy
Enhance your WordPress site with our helpdesk and support ticket system. Manage customer support, tickets, and email tickets efficiently.
CRM Perks – WordPress HelpDesk Integration – Zendesk, Freshdesk, HelpScout Developer Profile
32 plugins · 105K total installs
How We Detect CRM Perks – WordPress HelpDesk Integration – Zendesk, Freshdesk, HelpScout
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/support-x/assets/css/style.css/wp-content/plugins/support-x/assets/js/main.js/wp-content/plugins/support-x/templates/style.php/wp-content/plugins/support-x/templates/ticket-form.phphttps://www.google.com/recaptcha/api.jssupport-x/assets/css/style.css?ver=support-x/assets/js/main.js?ver=HTML / DOM Fingerprints
vx_entries_tablevx_ticket_formvx_form_rowvx_form_groupvx_ticket_detailvx_support_x_user_ticket_listdata-vx-iddata-vx-typedata-vx-fielddata-vx-crmvx_support_x_objvx_support_x_vars/wp-json/support-x/v1/tickets/wp-json/support-x/v1/ticket[crm-perks-tickets][crm-perks-form]