
Invelity GLS ParcelShop Security & Risk Analysis
wordpress.org/plugins/invelity-gls-parcelshopPlugin Invelity GLS ParcelShop je určený pre pridanie dopravnej metódy a pop-up okna s mapou pobočiek GLS ParcelShopov na Slovensku.
Is Invelity GLS ParcelShop Safe to Use in 2026?
Generally Safe
Score 85/100Invelity GLS ParcelShop has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.
The invelity-gls-parcelshop plugin exhibits several significant security concerns, primarily stemming from its unprotected entry points and lack of robust security checks. The presence of three AJAX handlers without any authentication or capability checks creates a substantial attack surface that could be exploited by unauthenticated users. This is further exacerbated by the use of the `unserialize` function, a known vector for object injection vulnerabilities, especially when the input source is not strictly controlled. While the plugin has no recorded vulnerability history, this should not be interpreted as a guarantee of current security, as the code itself presents inherent risks.
The static analysis reveals a low percentage of properly escaped output and a notable absence of nonce checks on AJAX requests, both of which increase the likelihood of cross-site scripting (XSS) vulnerabilities. The moderate use of prepared statements for SQL queries is a positive sign, but the remaining raw SQL queries could still pose a risk if they are susceptible to SQL injection. The taint analysis did not reveal any critical or high-severity unsanitized paths, which is a small positive, but the overall lack of security hardening in the entry points is a major weakness.
Key Concerns
- AJAX handlers without auth checks
- Dangerous function: unserialize
- Low output escaping percentage
- Missing nonce checks on AJAX
- SQL queries not using prepared statements
Invelity GLS ParcelShop Security Vulnerabilities
Invelity GLS ParcelShop Code Analysis
Dangerous Functions Found
SQL Query Safety
Output Escaping
Data Flow Analysis
Invelity GLS ParcelShop Attack Surface
AJAX Handlers 3
WordPress Hooks 19
Scheduled Events 1
Maintenance & Trust
Invelity GLS ParcelShop Maintenance & Trust
Maintenance Signals
Community Trust
Invelity GLS ParcelShop Alternatives
GLS Shipping for WooCommerce
gls-shipping-for-woocommerce
GLS Shipping plugin for WooCommerce
Invelity MyGLS connect
invelity-mygls-connect
Jednoduchý prenos objednávok do GLS cez API a tlač štítkov
Invelity GLS online connect
invelity-gls-online-connect
Plugin Invelity GLS online connect je vytvorený pre obchodníkov na platforme Woocommerce ktorý potrebuju automaticky exportovat údaje o objednávkach d …
Invelity SPS connect
invelity-sps-connect
Plugin Invelity SPS (Slovak parcel service) connect je vytvorený pre obchodníkov na platforme Woocommerce ktorý potrebuju automaticky exportovat údaje …
Invelity GLS Connect
invelity-gls-connect
Plugin Invelity GLS connect je vytvorený pre obchodníkov na platforme Woocommerce ktorý potrebuju automaticky exportovat údaje o objednávkach do systé …
Invelity GLS ParcelShop Developer Profile
8 plugins · 380 total installs
How We Detect Invelity GLS ParcelShop
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/invelity-gls-parcelshop/assets/css/select2.min.css/wp-content/plugins/invelity-gls-parcelshop/assets/js/select2.min.js/wp-content/plugins/invelity-gls-parcelshop/assets/js/parcelshops.js/wp-content/plugins/invelity-gls-parcelshop/assets/js/invelity-gls-parcelshop-settings.js/wp-content/plugins/invelity-gls-parcelshop/assets/js/select2.min.js/wp-content/plugins/invelity-gls-parcelshop/assets/js/parcelshops.js/wp-content/plugins/invelity-gls-parcelshop/assets/js/invelity-gls-parcelshop-settings.jsinvelity-gls-parcelshop/assets/css/select2.min.css?ver=invelity-gls-parcelshop/assets/js/select2.min.js?ver=invelity-gls-parcelshop/assets/js/parcelshops.js?ver=invelity-gls-parcelshop/assets/js/invelity-gls-parcelshop-settings.js?ver=HTML / DOM Fingerprints
invelity-plugins-main-admin-cssinvelity-buttoninvelity-plugins-main-admin.css<!-- Plugin úspešne nainštalovaný.Pridajte GLS ParcelShop doprava metódu. -->data-admin-urlinvelity_gls_parcelshop_settings