
WP Advanced Ticket System, Elite Support Helpdesk Security & Risk Analysis
wordpress.org/plugins/watsWATS is a ticket system, used by helpdesk staff to deliver support. WATS stands for WP Advanced Ticket System.
Is WP Advanced Ticket System, Elite Support Helpdesk Safe to Use in 2026?
Generally Safe
Score 100/100WP Advanced Ticket System, Elite Support Helpdesk has a strong security track record. Known vulnerabilities have been patched promptly.
The "wats" plugin, version 1.0.65, presents a significant security risk due to a large number of unprotected AJAX handlers and concerning code signals. All 16 identified AJAX handlers lack authentication checks, creating a wide attack surface. Furthermore, the presence of the `unserialize` function, combined with 3 high-severity unsanitized taint flows, indicates a strong potential for remote code execution or data manipulation vulnerabilities if user-supplied data is directly deserialized. While the plugin shows good practices in using prepared statements for most SQL queries and implementing nonce and capability checks, these are overshadowed by the critical lack of access control on its AJAX endpoints and the dangerous code patterns identified.
Key Concerns
- All 16 AJAX handlers are unprotected
- 3 high severity unsanitized taint flows
- Dangerous function: unserialize
- Only 29% of outputs are properly escaped
- 1 medium severity CVE history (though currently patched)
WP Advanced Ticket System, Elite Support Helpdesk Security Vulnerabilities
CVEs by Year
Severity Breakdown
1 total CVE
WordPress Advanced Ticket System, Elite Support Helpdesk <= 1.0.63 - Authenticated (Admin+) Stored Cross-Site Scripting
WP Advanced Ticket System, Elite Support Helpdesk Code Analysis
Dangerous Functions Found
SQL Query Safety
Output Escaping
Data Flow Analysis
WP Advanced Ticket System, Elite Support Helpdesk Attack Surface
AJAX Handlers 16
WordPress Hooks 50
Maintenance & Trust
WP Advanced Ticket System, Elite Support Helpdesk Maintenance & Trust
Maintenance Signals
Community Trust
WP Advanced Ticket System, Elite Support Helpdesk Alternatives
Customer Support Ticket System & Helpdesk Plugin for WordPress
wp-ticket
Create a support ticket system in WordPress. Manage customer inquiries, agents, priorities, and more with this flexible helpdesk plugin.
Awesome Support – WordPress HelpDesk & Support Plugin
awesome-support
The most versatile and feature-rich help desk and support plugin for WordPress. Provide awesome support directly from your WordPress site.
Majestic Support – The Leading-Edge Help Desk & Customer Support Plugin
majestic-support
Majestic Support for WordPress is a top-tier ticket system that can significantly enhance your customers' support experience.
Nirweb support
nirweb-support
NirWeb support is a great help desk and support plugin for WordPress with full support of WooCommerce
ELEX WordPress HelpDesk & Customer Ticketing System
elex-helpdesk-customer-support-ticket-system
ELEX WordPress HelpDesk & Customer Ticketing System offers top-notch features for the best customer support experience.
WP Advanced Ticket System, Elite Support Helpdesk Developer Profile
2 plugins · 250 total installs
How We Detect WP Advanced Ticket System, Elite Support Helpdesk
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/wats/css/style.css/wp-content/plugins/wats/css/jquery.mCustomScrollbar.css/wp-content/plugins/wats/js/wats_ticket_form.js/wp-content/plugins/wats/js/wats_admin.js/wp-content/plugins/wats/js/wats_ticket_listing.js/wp-content/plugins/wats/js/wats_ticket_edit.js/wp-content/plugins/wats/js/wats_ticket_view.js/wp-content/plugins/wats/js/wats_ticket_submit.js+8 moreWATS/wp-content/plugins/wats/js/wats_ticket_form.js/wp-content/plugins/wats/js/wats_admin.js/wp-content/plugins/wats/js/wats_ticket_listing.js/wp-content/plugins/wats/js/wats_ticket_edit.js/wp-content/plugins/wats/js/wats_ticket_view.js/wp-content/plugins/wats/js/wats_ticket_submit.js+8 morewats/style.css?ver=wats/css/style.css?ver=wats/css/jquery.mCustomScrollbar.css?ver=wats/js/wats_ticket_form.js?ver=wats/js/wats_admin.js?ver=wats/js/wats_ticket_listing.js?ver=wats/js/wats_ticket_edit.js?ver=wats/js/wats_ticket_view.js?ver=wats/js/wats_ticket_submit.js?ver=wats/js/wats_custom_fields.js?ver=wats/js/wats_ticket_update.js?ver=wats/js/jquery.mCustomScrollbar.concat.min.js?ver=wats/js/wats_ticket_listing_public.js?ver=wats/js/wats_ticket_view_public.js?ver=wats/js/wats_ticket_update_public.js?ver=wats/js/wats_ticket_submit_public.js?ver=wats/js/wats_admin_ajax.js?ver=HTML / DOM Fingerprints
wats-ticket-formwats-ticket-listingwats-ticket-editwats-ticket-viewwats-ticket-submitwats-custom-fieldwats-ticket-updatewats-ticket-id+28 moredata-wats-ticket-iddata-wats-field-iddata-wats-field-typedata-wats-capabilitywats_ticket_form_paramswats_admin_paramswats_ticket_listing_paramswats_ticket_edit_paramswats_ticket_view_paramswats_ticket_submit_params+8 more/wp-json/wats/v1/tickets/wp-json/wats/v1/settings/wp-json/wats/v1/users[wats_ticket_listing][wats_ticket_form][wats_ticket_view][wats_ticket_edit]