
System Ticket Support Security & Risk Analysis
wordpress.org/plugins/system-ticket-supportThe simple system ticket support. Full features to build a system private ticket, got notification via email.
Is System Ticket Support Safe to Use in 2026?
Generally Safe
Score 85/100System Ticket Support has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.
The "system-ticket-support" v1.0.0 plugin presents a mixed security posture. While it exhibits strong adherence to secure coding practices with a high percentage of prepared SQL statements and properly escaped output, and boasts no recorded vulnerability history, several critical areas raise significant concerns. The presence of the `unserialize` function without apparent sanitization or protection is a major red flag, as it can lead to Remote Code Execution (RCE) if an attacker can control the serialized data. Furthermore, the taint analysis revealing a high number of flows with unsanitized paths, particularly those flagged as high severity, indicates potential vulnerabilities that could arise from user-supplied input being processed without adequate validation or sanitization, even if direct attack vectors like AJAX or REST API endpoints are not immediately apparent as unprotected. The absence of capability checks on entry points, while the entry points themselves are seemingly protected, means that once an entry point is reached, further actions might not be adequately permissioned. The lack of recorded CVEs is positive, but the internal code analysis reveals potential for vulnerabilities that may not have been publicly documented yet.
Key Concerns
- Unsanitized unserialize function
- High number of unsanitized taint flows (high severity)
- No capability checks on entry points
- Bundled outdated TinyMCE v5.1.6
System Ticket Support Security Vulnerabilities
System Ticket Support Code Analysis
Dangerous Functions Found
Bundled Libraries
SQL Query Safety
Output Escaping
Data Flow Analysis
System Ticket Support Attack Surface
WordPress Hooks 65
Scheduled Events 2
Maintenance & Trust
System Ticket Support Maintenance & Trust
Maintenance Signals
Community Trust
System Ticket Support Alternatives
Guest Support
guest-support
Complete WordPress support ticket system. No login needed for users or agents. Includes spam protection, file uploads, and secure replies.
Fluent Support – Helpdesk & Customer Support Ticket System
fluent-support
Feature Rich and Super Fast Support and Customer Ticketing System for WordPress.
SupportCandy – Helpdesk & Customer Support Ticket System
supportcandy
Enhance your WordPress site with our helpdesk and support ticket system. Manage customer support, tickets, and email tickets efficiently.
Awesome Support – WordPress HelpDesk & Support Plugin
awesome-support
The most versatile and feature-rich help desk and support plugin for WordPress. Provide awesome support directly from your WordPress site.
JS Help Desk – AI-Powered Support & Ticketing System
js-support-ticket
Professional, beautiful, complete and powerful help desk & support system for WordPress.
System Ticket Support Developer Profile
8 plugins · 19K total installs
How We Detect System Ticket Support
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/system-ticket-support/assets/css/admin-style.css/wp-content/plugins/system-ticket-support/assets/css/frontend-style.css/wp-content/plugins/system-ticket-support/assets/js/admin-script.js/wp-content/plugins/system-ticket-support/assets/js/frontend-script.js/wp-content/plugins/system-ticket-support/assets/js/vendor/jquery-validation/dist/jquery.validate.min.js/wp-content/plugins/system-ticket-support/assets/js/vendor/sweetalert2/sweetalert2.min.js/wp-content/plugins/system-ticket-support/assets/js/admin-script.js/wp-content/plugins/system-ticket-support/assets/js/frontend-script.js/wp-content/plugins/system-ticket-support/assets/js/vendor/jquery-validation/dist/jquery.validate.min.js/wp-content/plugins/system-ticket-support/assets/js/vendor/sweetalert2/sweetalert2.min.jssystem-ticket-support/assets/css/admin-style.css?ver=system-ticket-support/assets/css/frontend-style.css?ver=system-ticket-support/assets/js/admin-script.js?ver=system-ticket-support/assets/js/frontend-script.js?ver=system-ticket-support/assets/js/vendor/jquery-validation/dist/jquery.validate.min.js?ver=system-ticket-support/assets/js/vendor/sweetalert2/sweetalert2.min.js?ver=HTML / DOM Fingerprints
sts-ticket-formsts-ticket-liststs-single-ticket<!-- System Ticket Support Plugin --><!-- End System Ticket Support Plugin -->data-sts-ticket-iddata-sts-user-idsts_ajax_object/wp-json/sts/v1/tickets/wp-json/sts/v1/tickets/(?P<id>\d+)[sts_ticket_form][sts_ticket_list][sts_single_ticket]