
Invelity GLS Connect Security & Risk Analysis
wordpress.org/plugins/invelity-gls-connectPlugin Invelity GLS connect je vytvorený pre obchodníkov na platforme Woocommerce ktorý potrebuju automaticky exportovat údaje o objednávkach do systé …
Is Invelity GLS Connect Safe to Use in 2026?
Generally Safe
Score 85/100Invelity GLS Connect has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.
The invelity-gls-connect plugin v1.1.7 exhibits a generally strong security posture based on the provided static analysis. The absence of any recorded vulnerabilities (CVEs) and the zero count for critical or high severity taint flows are positive indicators. Furthermore, the plugin demonstrates good coding practices with 100% of its SQL queries utilizing prepared statements, and the presence of nonce and capability checks, although limited in number, suggests some awareness of security fundamentals.
However, there are areas for improvement that introduce minor risks. The most notable concern is the relatively low percentage of properly escaped output (65%). This means that approximately 35% of outputs are potentially vulnerable to Cross-Site Scripting (XSS) attacks if the data being output originates from user input or untrusted sources. While the attack surface appears minimal with zero entry points reported as unprotected, the file operations and external HTTP requests, though not explicitly flagged as risky in this analysis, warrant careful scrutiny in a deeper review, especially considering the unescaped output.
In conclusion, the plugin is not demonstrating any immediate critical vulnerabilities based on this snapshot. Its lack of historical vulnerabilities is encouraging. The primary area of concern is the output escaping, which should be addressed to mitigate potential XSS risks. The limited number of checks and the potential for unescaped data in file operations or external requests suggest that a more thorough manual code review would be beneficial to ensure no subtle vulnerabilities have been missed.
Key Concerns
- Low percentage of properly escaped output
- Limited nonce checks
- Limited capability checks
Invelity GLS Connect Security Vulnerabilities
Invelity GLS Connect Code Analysis
Output Escaping
Invelity GLS Connect Attack Surface
WordPress Hooks 7
Maintenance & Trust
Invelity GLS Connect Maintenance & Trust
Maintenance Signals
Community Trust
Invelity GLS Connect Alternatives
GLS Shipping for WooCommerce
gls-shipping-for-woocommerce
GLS Shipping plugin for WooCommerce
Invelity MyGLS connect
invelity-mygls-connect
Jednoduchý prenos objednávok do GLS cez API a tlač štítkov
Invelity GLS online connect
invelity-gls-online-connect
Plugin Invelity GLS online connect je vytvorený pre obchodníkov na platforme Woocommerce ktorý potrebuju automaticky exportovat údaje o objednávkach d …
Invelity SPS connect
invelity-sps-connect
Plugin Invelity SPS (Slovak parcel service) connect je vytvorený pre obchodníkov na platforme Woocommerce ktorý potrebuju automaticky exportovat údaje …
Weight Based Shipping Table Rate for WooCommerce – Flexible Shipping
flexible-shipping
Weight based shipping methods for WooCommerce. Flexible shipping with table rate rules by cart weight and order value. Accurate rates at checkout.
Invelity GLS Connect Developer Profile
8 plugins · 380 total installs
How We Detect Invelity GLS Connect
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/invelity-gls-connect/assets/css/invelity-plugins-main-admin.cssHTML / DOM Fingerprints
invelity-plugins-main-admin-cssinvelity-plugins-namespaceinvelity-button