TicketSource Ticket Shop Security & Risk Analysis

wordpress.org/plugins/ticketsource-events

Sell event tickets online directly through your WordPress site with TicketSource. An easy to use, self service box office system.

800 active installs v3.2.0 PHP 7.4+ WP 4.0.0+ Updated Dec 11, 2025
calendareventssell-ticketsticketingtickets
99
A · Safe
CVEs total1
Unpatched0
Last CVEDec 19, 2024
Safety Verdict

Is TicketSource Ticket Shop Safe to Use in 2026?

Generally Safe

Score 99/100

TicketSource Ticket Shop has a strong security track record. Known vulnerabilities have been patched promptly. It's a solid choice for most WordPress installations.

1 known CVELast CVE: Dec 19, 2024Updated 5mo ago
Risk Assessment

The "ticketsource-events" plugin v3.2.0 exhibits a mixed security posture. On the positive side, the static analysis reveals good development practices regarding SQL queries and output escaping, with all queries using prepared statements and all outputs being properly escaped. Furthermore, there are no identified dangerous functions, file operations, external HTTP requests, or bundled libraries, which generally reduces the potential attack surface. The absence of critical or high-severity taint flows is also a good sign, indicating that data manipulation within the plugin is likely handled securely.

However, several areas raise concerns. The plugin has a history of known vulnerabilities, specifically one medium-severity Cross-Site Scripting (XSS) vulnerability. While currently patched, this history suggests that the plugin may be a target for attackers and that past security flaws have existed. The complete lack of nonce checks and capability checks across all entry points (even though there is only one shortcode entry point) is a significant weakness. This means that any user, regardless of their role or permissions, could potentially interact with the shortcode and trigger its functionality. This opens the door to unintended actions if the shortcode's logic can be influenced by user input, especially in conjunction with the past XSS vulnerability.

In conclusion, while the plugin demonstrates good practices in data handling and output sanitation, the absence of crucial security checks like nonces and capability checks on its entry points, coupled with its past vulnerability history, presents a notable risk. This warrants careful consideration and potential improvement to bolster its overall security.

Key Concerns

  • Medium severity XSS vulnerability in history
  • Missing nonce checks on entry points
  • Missing capability checks on entry points
Vulnerabilities
1 published

TicketSource Ticket Shop Security Vulnerabilities

CVEs by Year

1 CVE in 2024
2024
Patched Has unpatched

Severity Breakdown

Medium
1

1 total CVE

CVE-2024-11784medium · 6.4Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')

Sell Tickets Online – TicketSource Ticket Shop for WordPress <= 3.0.2 - Authenticated (Contributor+) Stored Cross-Site Scripting

Dec 19, 2024 Patched in 3.1.0 (4d)
Version History

TicketSource Ticket Shop Release Timeline

v3.2.0Current
v3.1.0
v3.0.21 CVE
v3.0.11 CVE
v3.0.01 CVE
v2.0.01 CVE
v1.0.01 CVE
Code Analysis
Analyzed Mar 16, 2026

TicketSource Ticket Shop Code Analysis

Dangerous Functions
0
Raw SQL Queries
0
0 prepared
Unescaped Output
0
4 escaped
Nonce Checks
0
Capability Checks
0
File Operations
0
External Requests
0
Bundled Libraries
0

Output Escaping

100% escaped4 total outputs
Attack Surface

TicketSource Ticket Shop Attack Surface

Entry Points1
Unprotected0

Shortcodes 1

[ticketshop] includes\ticketsource-events-build.php:13
Maintenance & Trust

TicketSource Ticket Shop Maintenance & Trust

Maintenance Signals

WordPress version tested6.9.4
Last updatedDec 11, 2025
PHP min version7.4
Downloads9K

Community Trust

Rating20/100
Number of ratings1
Active installs800
Developer Profile

TicketSource Ticket Shop Developer Profile

ticketsource

1 plugin · 800 total installs

99
trust score
Avg Security Score
99/100
Avg Patch Time
4 days
View full developer profile
Detection Fingerprints

How We Detect TicketSource Ticket Shop

Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.

Asset Fingerprints

Asset Paths
/wp-content/plugins/ticketsource-events/includes/ticketsource-events-build.php

HTML / DOM Fingerprints

HTML Comments
<!-- Start Ticket Shop App --><!-- End Ticket Shop App -->
Data Attributes
id="embedTS_
Shortcode Output
<div id="embedTS_<script type="text/javascript"> (function() { var el = document.createElement("script"); el.type = "text/javascript"; el.async = true; el.src = "
FAQ

Frequently Asked Questions about TicketSource Ticket Shop