
Invelity GLS online connect Security & Risk Analysis
wordpress.org/plugins/invelity-gls-online-connectPlugin Invelity GLS online connect je vytvorený pre obchodníkov na platforme Woocommerce ktorý potrebuju automaticky exportovat údaje o objednávkach d …
Is Invelity GLS online connect Safe to Use in 2026?
Generally Safe
Score 85/100Invelity GLS online connect has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.
The 'invelity-gls-online-connect' plugin v1.2.4 presents a mixed security posture. Its strengths lie in the absence of known vulnerabilities (CVEs) and a lack of extensive attack surface points such as unprotected AJAX handlers, REST API routes, shortcodes, or cron events. The code also demonstrates good practices regarding SQL queries, with 100% using prepared statements, and a decent rate of output escaping (65%).
However, significant concerns arise from the static analysis. The presence of two instances of the 'unserialize' function is a red flag, as it can be exploited for remote code execution if used with untrusted input. This is further underscored by the taint analysis, which identified one flow with unsanitized paths and a high severity, indicating a potential pathway for malicious data to reach a sensitive function. The lack of capability checks on any entry points is also a notable weakness, meaning that authenticated users, regardless of their role, might be able to trigger certain functionalities that should be restricted.
The plugin's vulnerability history is clean, with no recorded CVEs. This suggests that either the plugin has been well-maintained or its functionalities have not been a target for exploitation in the past. Despite the positive historical data, the identified 'unserialize' usage and the high-severity taint flow present a real and immediate risk that warrants attention. Overall, the plugin has good foundational security practices but requires immediate attention to address the identified potential for code injection due to the 'unserialize' function and the high-severity taint flow.
Key Concerns
- High severity taint flow with unsanitized path
- Dangerous function used: unserialize
- Lack of capability checks on entry points
- Output escaping only 65% proper
Invelity GLS online connect Security Vulnerabilities
Invelity GLS online connect Code Analysis
Dangerous Functions Found
Output Escaping
Data Flow Analysis
Invelity GLS online connect Attack Surface
WordPress Hooks 7
Maintenance & Trust
Invelity GLS online connect Maintenance & Trust
Maintenance Signals
Community Trust
Invelity GLS online connect Alternatives
GLS Shipping for WooCommerce
gls-shipping-for-woocommerce
GLS Shipping plugin for WooCommerce
Invelity MyGLS connect
invelity-mygls-connect
Jednoduchý prenos objednávok do GLS cez API a tlač štítkov
Invelity SPS connect
invelity-sps-connect
Plugin Invelity SPS (Slovak parcel service) connect je vytvorený pre obchodníkov na platforme Woocommerce ktorý potrebuju automaticky exportovat údaje …
Invelity GLS Connect
invelity-gls-connect
Plugin Invelity GLS connect je vytvorený pre obchodníkov na platforme Woocommerce ktorý potrebuju automaticky exportovat údaje o objednávkach do systé …
Weight Based Shipping Table Rate for WooCommerce – Flexible Shipping
flexible-shipping
Weight based shipping methods for WooCommerce. Flexible shipping with table rate rules by cart weight and order value. Accurate rates at checkout.
Invelity GLS online connect Developer Profile
8 plugins · 380 total installs
How We Detect Invelity GLS online connect
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/invelity-gls-online-connect/assets/css/invelity-plugins-main-admin.cssinvelity-plugins-main-admin-css?ver=1.0.0HTML / DOM Fingerprints
invelity-plugins-namespaceinvelity-buttonplugin-list-item-containerstate-noticestate-successdata-plugin-slug="invelity-gls-online-connect"data-old-plugin-slug="finest-online-connect-export"