Ticket Tailor — Event Ticketing & Registration Security & Risk Analysis

wordpress.org/plugins/ticket-tailor

Sell event tickets online via your WordPress website. Ticket Tailor is an easy event ticketing & event registration system.

4K active installs v1.13 PHP + WP 2.8+ Updated Jan 31, 2026
event-registrationevent-ticketingeventsticket-salesticketing
100
A · Safe
CVEs total1
Unpatched0
Last CVEMar 15, 2024
Safety Verdict

Is Ticket Tailor — Event Ticketing & Registration Safe to Use in 2026?

Generally Safe

Score 100/100

Ticket Tailor — Event Ticketing & Registration has a strong security track record. Known vulnerabilities have been patched promptly.

1 known CVELast CVE: Mar 15, 2024Updated 2mo ago
Risk Assessment

The 'ticket-tailor' plugin v1.13 exhibits a generally good security posture based on the static analysis. The absence of dangerous functions, file operations, external HTTP requests, and the consistent use of prepared statements for SQL queries are positive indicators. Furthermore, all output appears to be properly escaped, and the plugin demonstrates a strong adherence to capability checks for its entry points. The taint analysis revealing no unsanitized flows is also a significant strength.

However, the plugin's vulnerability history presents a notable concern. While there are no currently unpatched vulnerabilities, the presence of a past medium-severity Cross-Site Scripting (XSS) vulnerability, even if resolved, suggests a potential area for recurring issues if not carefully managed. The static analysis does not directly highlight this specific XSS risk, but the history is a strong signal for potential weaknesses.

In conclusion, 'ticket-tailor' v1.13 has implemented several strong security practices. The lack of exploitable code signals in the static analysis is commendable. The primary area of concern stems from its vulnerability history, specifically the past XSS issue, which warrants continued vigilance and thorough review during future updates to ensure similar vulnerabilities are not reintroduced.

Key Concerns

  • Past medium severity XSS vulnerability
  • No nonce checks on entry points
Vulnerabilities
1

Ticket Tailor — Event Ticketing & Registration Security Vulnerabilities

CVEs by Year

1 CVE in 2024
2024
Patched Has unpatched

Severity Breakdown

Medium
1

1 total CVE

CVE-2024-29104medium · 6.4Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')

Ticket Tailor <= 1.10 - Authenticated (Contributor+) Stored Cross-Site Scripting

Mar 15, 2024 Patched in 1.12 (6d)
Code Analysis
Analyzed Mar 16, 2026

Ticket Tailor — Event Ticketing & Registration Code Analysis

Dangerous Functions
0
Raw SQL Queries
0
0 prepared
Unescaped Output
0
0 escaped
Nonce Checks
0
Capability Checks
1
File Operations
0
External Requests
0
Bundled Libraries
0
Attack Surface

Ticket Tailor — Event Ticketing & Registration Attack Surface

Entry Points1
Unprotected0

Shortcodes 1

[tt-event] ticket-tailor-sell-tickets-online.php:36
WordPress Hooks 2
actionadmin_initticket-tailor-sell-tickets-online.php:20
actionadmin_menuticket-tailor-sell-tickets-online.php:69
Maintenance & Trust

Ticket Tailor — Event Ticketing & Registration Maintenance & Trust

Maintenance Signals

WordPress version tested6.9.4
Last updatedJan 31, 2026
PHP min version
Downloads98K

Community Trust

Rating86/100
Number of ratings46
Active installs4K
Developer Profile

Ticket Tailor — Event Ticketing & Registration Developer Profile

Jonny White (from Ticket Tailor)

1 plugin · 4K total installs

100
trust score
Avg Security Score
100/100
Avg Patch Time
6 days
View full developer profile
Detection Fingerprints

How We Detect Ticket Tailor — Event Ticketing & Registration

Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.

Asset Fingerprints

HTML / DOM Fingerprints

CSS Classes
tt-widget
Data Attributes
data-urldata-typedata-inline-minimaldata-inline-show-logodata-inline-bg-filldata-inline-inherit-ref-from-url-param+1 more
Shortcode Output
<div class="tt-widget"> <script src="https://cdn.tickettailor.com/js/widgets/min/widget.js"data-url="data-type="inline"data-inline-minimal="
FAQ

Frequently Asked Questions about Ticket Tailor — Event Ticketing & Registration