Tickzo – Support Ticket System Security & Risk Analysis

wordpress.org/plugins/tickzo-support-ticket-system

A professional support ticket system for WordPress with email notifications and multilingual support.

0 active installs v1.4.3 PHP 7.4+ WP 5.0+ Updated Jan 9, 2026
customer-supporthelpdesksupportticket-systemtickets
100
A · Safe
CVEs total0
Unpatched0
Last CVENever
Download
Safety Verdict

Is Tickzo – Support Ticket System Safe to Use in 2026?

Generally Safe

Score 100/100

Tickzo – Support Ticket System has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.

No known CVEs Updated 4mo ago
Risk Assessment

The tickzo-support-ticket-system plugin version 1.4.3 exhibits a mixed security posture. On the positive side, it demonstrates good practices by extensively using prepared statements for SQL queries and properly escaping output. The plugin also incorporates a healthy number of nonce and capability checks, indicating an awareness of WordPress security fundamentals. Furthermore, the absence of any known past vulnerabilities (CVEs) is a strong indicator of its general stability and security.

However, significant concerns arise from the attack surface analysis. With 14 total entry points, a notable four AJAX handlers lack authentication checks. This presents a direct risk, as these endpoints could potentially be accessed and manipulated by unauthenticated users. The taint analysis further highlights this, revealing one high-severity flow with unsanitized paths. This suggests that user-supplied data might be processed in a way that could lead to vulnerabilities like path traversal or unauthorized file access if not handled with extreme care.

In conclusion, while the plugin benefits from strong internal coding practices like prepared statements and output escaping, the presence of unprotected AJAX endpoints and a high-severity unsanitized path flow represent critical security weaknesses. The lack of historical vulnerabilities is a positive sign, but it doesn't negate the risks identified in the current static analysis. Mitigation of these identified risks should be prioritized.

Key Concerns

  • Unprotected AJAX handlers
  • High severity unsanitized path flow
Vulnerabilities
None known

Tickzo – Support Ticket System Security Vulnerabilities

No known vulnerabilities — this is a good sign.
Version History

Tickzo – Support Ticket System Release Timeline

v1.4.2
v1.3.8
v1.3.1
Code Analysis
Analyzed Apr 6, 2026

Tickzo – Support Ticket System Code Analysis

Dangerous Functions
0
Raw SQL Queries
6
112 prepared
Unescaped Output
37
678 escaped
Nonce Checks
27
Capability Checks
9
File Operations
8
External Requests
0
Bundled Libraries
0

SQL Query Safety

95% prepared118 total queries

Output Escaping

95% escaped715 total outputs
Data Flows · Security
2 unsanitized

Data Flow Analysis

10 flows2 with unsanitized paths
admin_tickets_page (admin/class-admin.php:1576)
Source (user input) Sink (dangerous op) Sanitizer Transform Unsanitized Sanitized
Attack Surface
4 unprotected

Tickzo – Support Ticket System Attack Surface

Entry Points14
Unprotected4

AJAX Handlers 10

authwp_ajax_tickzo_manage_ticketadmin/class-admin.php:31
authwp_ajax_tickzo_get_dashboard_statsadmin/class-admin.php:35
authwp_ajax_tickzo_submit_tickettickzo-support-ticket-system.php:474
noprivwp_ajax_tickzo_submit_tickettickzo-support-ticket-system.php:478
authwp_ajax_tickzo_get_ticket_detailstickzo-support-ticket-system.php:482
authwp_ajax_tickzo_add_replytickzo-support-ticket-system.php:483
authwp_ajax_tickzo_upload_attachmenttickzo-support-ticket-system.php:484
noprivwp_ajax_tickzo_upload_attachmenttickzo-support-ticket-system.php:485
authwp_ajax_tickzo_delete_attachmenttickzo-support-ticket-system.php:486
authwp_ajax_tickzo_download_attachmenttickzo-support-ticket-system.php:487

Shortcodes 4

[tickzo_form] tickzo-support-ticket-system.php:491
[tickzo_submit_form] tickzo-support-ticket-system.php:492
[tickzo_tickets] tickzo-support-ticket-system.php:493
[tickzo_ticket] tickzo-support-ticket-system.php:494
WordPress Hooks 16
actionadmin_menuadmin/class-admin.php:26
actionadmin_initadmin/class-admin.php:27
actionadmin_headadmin/class-admin.php:77
actionadmin_noticesadmin/class-admin.php:2267
actionadmin_noticesadmin/class-admin.php:2291
actionadmin_menuadmin/create-tables-admin-page.php:12
actionplugins_loadedincludes/class-database-migrations.php:40
filtertickzo_before_create_ticketincludes/class-guest-support.php:36
actionwp_enqueue_scriptstickzo-support-ticket-system.php:466
actionadmin_enqueue_scriptstickzo-support-ticket-system.php:467
actionplugins_loadedtickzo-support-ticket-system.php:470
actioninittickzo-support-ticket-system.php:490
filterupload_dirtickzo-support-ticket-system.php:1007
actionplugins_loadedtickzo-support-ticket-system.php:1195
actionadmin_noticestickzo-support-ticket-system.php:1229
actiontickzo_auto_close_ticketstickzo-support-ticket-system.php:1304

Scheduled Events 1

tickzo_auto_close_tickets
Maintenance & Trust

Tickzo – Support Ticket System Maintenance & Trust

Maintenance Signals

WordPress version tested6.9.4
Last updatedJan 9, 2026
PHP min version7.4
Downloads342

Community Trust

Rating0/100
Number of ratings0
Active installs0
Developer Profile

Tickzo – Support Ticket System Developer Profile

Thorsten Glander

2 plugins · 10 total installs

94
trust score
Avg Security Score
100/100
Avg Patch Time
30 days
View full developer profile
Detection Fingerprints

How We Detect Tickzo – Support Ticket System

Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.

Asset Fingerprints

Asset Paths
/wp-content/plugins/tickzo-support-ticket-system/assets/css/tickzo-style.css/wp-content/plugins/tickzo-support-ticket-system/assets/js/tickzo-script.js/wp-content/plugins/tickzo-support-ticket-system/assets/js/tickzo-admin.js/wp-content/plugins/tickzo-support-ticket-system/assets/css/tickzo-admin.css/wp-content/plugins/tickzo-support-ticket-system/assets/css/tickzo-bootstrap.css/wp-content/plugins/tickzo-support-ticket-system/assets/css/tickzo-select2.css/wp-content/plugins/tickzo-support-ticket-system/assets/js/tickzo-bootstrap.js/wp-content/plugins/tickzo-support-ticket-system/assets/js/tickzo-select2.js+2 more
Script Paths
/wp-content/plugins/tickzo-support-ticket-system/assets/js/tickzo-script.js/wp-content/plugins/tickzo-support-ticket-system/assets/js/tickzo-admin.js/wp-content/plugins/tickzo-support-ticket-system/assets/js/tickzo-bootstrap.js/wp-content/plugins/tickzo-support-ticket-system/assets/js/tickzo-select2.js/wp-content/plugins/tickzo-support-ticket-system/assets/js/tickzo-datatable.js
Version Parameters
tickzo-support-ticket-system/assets/css/tickzo-style.css?ver=tickzo-support-ticket-system/assets/js/tickzo-script.js?ver=tickzo-support-ticket-system/assets/js/tickzo-admin.js?ver=tickzo-support-ticket-system/assets/css/tickzo-admin.css?ver=tickzo-support-ticket-system/assets/css/tickzo-bootstrap.css?ver=tickzo-support-ticket-system/assets/css/tickzo-select2.css?ver=tickzo-support-ticket-system/assets/js/tickzo-bootstrap.js?ver=tickzo-support-ticket-system/assets/js/tickzo-select2.js?ver=tickzo-support-ticket-system/assets/js/tickzo-datatable.js?ver=tickzo-support-ticket-system/assets/css/tickzo-datatable.css?ver=

HTML / DOM Fingerprints

CSS Classes
tickzo-ticket-formtickzo-ticket-listtickzo-ticket-viewtickzo-reply-formtickzo-attachment-uploadtickzo-ticket-statustickzo-user-profile
HTML Comments
<!-- Tickzo Support Ticket System --><!-- Tickzo Ticket Form --><!-- Tickzo Ticket List --><!-- Tickzo Ticket View -->+2 more
Data Attributes
data-tickzo-ticket-iddata-tickzo-attachment-iddata-tickzo-user-iddata-tickzo-reply-id
JS Globals
tickzo_ajax_objecttickzo_vars
REST Endpoints
/wp-json/tickzo/v1/tickets/wp-json/tickzo/v1/tickets/(?P<id>[\d]+)/wp-json/tickzo/v1/replies/wp-json/tickzo/v1/attachments
Shortcode Output
[tickzo_ticket_form][tickzo_ticket_list][tickzo_ticket_view][tickzo_my_tickets]
FAQ

Frequently Asked Questions about Tickzo – Support Ticket System