Invelity GLS online connect Security & Risk Analysis

wordpress.org/plugins/invelity-gls-online-connect

Plugin Invelity GLS online connect je vytvorený pre obchodníkov na platforme Woocommerce ktorý potrebuju automaticky exportovat údaje o objednávkach d …

60 active installs v1.2.4 PHP 7.4+ WP 5.8.1+ Updated Oct 24, 2022
glsshippingwoocommerce
85
A · Safe
CVEs total0
Unpatched0
Last CVENever
Safety Verdict

Is Invelity GLS online connect Safe to Use in 2026?

Generally Safe

Score 85/100

Invelity GLS online connect has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.

No known CVEs Updated 3yr ago
Risk Assessment

The 'invelity-gls-online-connect' plugin v1.2.4 presents a mixed security posture. Its strengths lie in the absence of known vulnerabilities (CVEs) and a lack of extensive attack surface points such as unprotected AJAX handlers, REST API routes, shortcodes, or cron events. The code also demonstrates good practices regarding SQL queries, with 100% using prepared statements, and a decent rate of output escaping (65%).

However, significant concerns arise from the static analysis. The presence of two instances of the 'unserialize' function is a red flag, as it can be exploited for remote code execution if used with untrusted input. This is further underscored by the taint analysis, which identified one flow with unsanitized paths and a high severity, indicating a potential pathway for malicious data to reach a sensitive function. The lack of capability checks on any entry points is also a notable weakness, meaning that authenticated users, regardless of their role, might be able to trigger certain functionalities that should be restricted.

The plugin's vulnerability history is clean, with no recorded CVEs. This suggests that either the plugin has been well-maintained or its functionalities have not been a target for exploitation in the past. Despite the positive historical data, the identified 'unserialize' usage and the high-severity taint flow present a real and immediate risk that warrants attention. Overall, the plugin has good foundational security practices but requires immediate attention to address the identified potential for code injection due to the 'unserialize' function and the high-severity taint flow.

Key Concerns

  • High severity taint flow with unsanitized path
  • Dangerous function used: unserialize
  • Lack of capability checks on entry points
  • Output escaping only 65% proper
Vulnerabilities
None known

Invelity GLS online connect Security Vulnerabilities

No known vulnerabilities — this is a good sign.
Code Analysis
Analyzed Mar 16, 2026

Invelity GLS online connect Code Analysis

Dangerous Functions
2
Raw SQL Queries
0
0 prepared
Unescaped Output
18
34 escaped
Nonce Checks
1
Capability Checks
0
File Operations
0
External Requests
3
Bundled Libraries
0

Dangerous Functions Found

unserialize$sucessfull = unserialize(str_replace('\\', '', urldecode($_REQUEST['gls-sucessfull'])));classes\class.invelityGlsOnlineConnectProcess.php:320
unserialize$unsucessfull = unserialize(str_replace('\\', '', urldecode($_REQUEST['gls-unsucessfull'])));classes\class.invelityGlsOnlineConnectProcess.php:321

Output Escaping

65% escaped52 total outputs
Data Flows
1 unsanitized

Data Flow Analysis

2 flows1 with unsanitized paths
<class.invelityGlsOnlineConnectProcess> (classes\class.invelityGlsOnlineConnectProcess.php:0)
Source (user input) Sink (dangerous op) Sanitizer Transform Unsanitized Sanitized
Attack Surface

Invelity GLS online connect Attack Surface

Entry Points0
Unprotected0
WordPress Hooks 7
actionadmin_menuclasses\class.invelityGlsOnlineConnectAdmin.php:16
actionadmin_initclasses\class.invelityGlsOnlineConnectAdmin.php:17
actionadmin_footer-edit.phpclasses\class.invelityGlsOnlineConnectProcess.php:18
actionload-edit.phpclasses\class.invelityGlsOnlineConnectProcess.php:19
actionadmin_noticesclasses\class.invelityGlsOnlineConnectProcess.php:20
actionadmin_enqueue_scriptsclasses\class.invelityPluginsAdmin.php:19
actionadmin_menuclasses\class.invelityPluginsAdmin.php:20
Maintenance & Trust

Invelity GLS online connect Maintenance & Trust

Maintenance Signals

WordPress version tested6.0.11
Last updatedOct 24, 2022
PHP min version7.4
Downloads4K

Community Trust

Rating100/100
Number of ratings2
Active installs60
Developer Profile

Invelity GLS online connect Developer Profile

INVELITY

8 plugins · 380 total installs

82
trust score
Avg Security Score
83/100
Avg Patch Time
30 days
View full developer profile
Detection Fingerprints

How We Detect Invelity GLS online connect

Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.

Asset Fingerprints

Asset Paths
/wp-content/plugins/invelity-gls-online-connect/assets/css/invelity-plugins-main-admin.css
Version Parameters
invelity-plugins-main-admin-css?ver=1.0.0

HTML / DOM Fingerprints

CSS Classes
invelity-plugins-namespaceinvelity-buttonplugin-list-item-containerstate-noticestate-success
Data Attributes
data-plugin-slug="invelity-gls-online-connect"data-old-plugin-slug="finest-online-connect-export"
FAQ

Frequently Asked Questions about Invelity GLS online connect