Invelity GLS Connect Security & Risk Analysis

wordpress.org/plugins/invelity-gls-connect

Plugin Invelity GLS connect je vytvorený pre obchodníkov na platforme Woocommerce ktorý potrebuju automaticky exportovat údaje o objednávkach do systé …

20 active installs v1.1.7 PHP 5.6+ WP 4.6.1+ Updated May 2, 2019
glsshippingwoocommerce
85
A · Safe
CVEs total0
Unpatched0
Last CVENever
Safety Verdict

Is Invelity GLS Connect Safe to Use in 2026?

Generally Safe

Score 85/100

Invelity GLS Connect has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.

No known CVEs Updated 6yr ago
Risk Assessment

The invelity-gls-connect plugin v1.1.7 exhibits a generally strong security posture based on the provided static analysis. The absence of any recorded vulnerabilities (CVEs) and the zero count for critical or high severity taint flows are positive indicators. Furthermore, the plugin demonstrates good coding practices with 100% of its SQL queries utilizing prepared statements, and the presence of nonce and capability checks, although limited in number, suggests some awareness of security fundamentals.

However, there are areas for improvement that introduce minor risks. The most notable concern is the relatively low percentage of properly escaped output (65%). This means that approximately 35% of outputs are potentially vulnerable to Cross-Site Scripting (XSS) attacks if the data being output originates from user input or untrusted sources. While the attack surface appears minimal with zero entry points reported as unprotected, the file operations and external HTTP requests, though not explicitly flagged as risky in this analysis, warrant careful scrutiny in a deeper review, especially considering the unescaped output.

In conclusion, the plugin is not demonstrating any immediate critical vulnerabilities based on this snapshot. Its lack of historical vulnerabilities is encouraging. The primary area of concern is the output escaping, which should be addressed to mitigate potential XSS risks. The limited number of checks and the potential for unescaped data in file operations or external requests suggest that a more thorough manual code review would be beneficial to ensure no subtle vulnerabilities have been missed.

Key Concerns

  • Low percentage of properly escaped output
  • Limited nonce checks
  • Limited capability checks
Vulnerabilities
None known

Invelity GLS Connect Security Vulnerabilities

No known vulnerabilities — this is a good sign.
Code Analysis
Analyzed Mar 16, 2026

Invelity GLS Connect Code Analysis

Dangerous Functions
0
Raw SQL Queries
0
0 prepared
Unescaped Output
16
30 escaped
Nonce Checks
1
Capability Checks
1
File Operations
5
External Requests
3
Bundled Libraries
0

Output Escaping

65% escaped46 total outputs
Attack Surface

Invelity GLS Connect Attack Surface

Entry Points0
Unprotected0
WordPress Hooks 7
actionadmin_menuclasses\class.invelityGlsExportAdmin.php:16
actionadmin_initclasses\class.invelityGlsExportAdmin.php:17
actionadmin_footer-edit.phpclasses\class.invelityGlsExportProcess.php:18
actionload-edit.phpclasses\class.invelityGlsExportProcess.php:19
actionadmin_noticesclasses\class.invelityGlsExportProcess.php:20
actionadmin_enqueue_scriptsclasses\class.invelityPluginsAdmin.php:19
actionadmin_menuclasses\class.invelityPluginsAdmin.php:20
Maintenance & Trust

Invelity GLS Connect Maintenance & Trust

Maintenance Signals

WordPress version tested4.9.29
Last updatedMay 2, 2019
PHP min version5.6
Downloads2K

Community Trust

Rating100/100
Number of ratings1
Active installs20
Developer Profile

Invelity GLS Connect Developer Profile

INVELITY

8 plugins · 380 total installs

82
trust score
Avg Security Score
83/100
Avg Patch Time
30 days
View full developer profile
Detection Fingerprints

How We Detect Invelity GLS Connect

Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.

Asset Fingerprints

Asset Paths
/wp-content/plugins/invelity-gls-connect/assets/css/invelity-plugins-main-admin.css

HTML / DOM Fingerprints

CSS Classes
invelity-plugins-main-admin-cssinvelity-plugins-namespaceinvelity-button
FAQ

Frequently Asked Questions about Invelity GLS Connect