
Invelity MyGLS connect Security & Risk Analysis
wordpress.org/plugins/invelity-mygls-connectJednoduchý prenos objednávok do GLS cez API a tlač štítkov
Is Invelity MyGLS connect Safe to Use in 2026?
Mostly Safe
Score 78/100Invelity MyGLS connect is generally safe to use. 1 past CVE were resolved. Keep it updated.
The invelity-mygls-connect plugin v1.1.1 exhibits a mixed security posture. On the positive side, the plugin demonstrates good practices in its handling of SQL queries, utilizing prepared statements exclusively. It also has a low attack surface with no identifiable AJAX handlers, REST API routes, shortcodes, or cron events directly exposed without authentication. Furthermore, a nonce check is present, indicating an awareness of potential CSRF vulnerabilities.
However, several significant concerns emerge. The presence of two instances of the `unserialize` function is a major red flag, as it is a common vector for Remote Code Execution if not handled with extreme caution and strict input validation. The taint analysis revealing one flow with unsanitized paths, classified as high severity, directly correlates with this risk and suggests that external input might be used in a way that could lead to a vulnerability. The limited output escaping (64%) also leaves room for potential Cross-Site Scripting (XSS) vulnerabilities.
The vulnerability history indicates a past medium severity Cross-Site Request Forgery (CSRF) vulnerability, which, although not critical, points to an area where the plugin might have had weaknesses. The fact that a vulnerability was discovered as recently as 2025-09-05, and it remains unpatched, is a critical issue. This suggests a lack of ongoing maintenance or a failure to address known security flaws promptly, further amplifying the risks associated with the identified code signals.
Key Concerns
- Unpatched CVE found
- High severity taint flow
- Dangerous function: unserialize found
- Output escaping is not fully robust (64%)
- Bundled library TCPDF detected (potential outdatedness)
- Zero capability checks found
Invelity MyGLS connect Security Vulnerabilities
CVEs by Year
Severity Breakdown
1 total CVE
Invelity MyGLS connect <= 1.1.1 - Cross-Site Request Forgery
Invelity MyGLS connect Code Analysis
Dangerous Functions Found
Bundled Libraries
Output Escaping
Data Flow Analysis
Invelity MyGLS connect Attack Surface
WordPress Hooks 8
Maintenance & Trust
Invelity MyGLS connect Maintenance & Trust
Maintenance Signals
Community Trust
Invelity MyGLS connect Alternatives
GLS Shipping for WooCommerce
gls-shipping-for-woocommerce
GLS Shipping plugin for WooCommerce
Invelity GLS online connect
invelity-gls-online-connect
Plugin Invelity GLS online connect je vytvorený pre obchodníkov na platforme Woocommerce ktorý potrebuju automaticky exportovat údaje o objednávkach d …
Invelity SPS connect
invelity-sps-connect
Plugin Invelity SPS (Slovak parcel service) connect je vytvorený pre obchodníkov na platforme Woocommerce ktorý potrebuju automaticky exportovat údaje …
Invelity GLS Connect
invelity-gls-connect
Plugin Invelity GLS connect je vytvorený pre obchodníkov na platforme Woocommerce ktorý potrebuju automaticky exportovat údaje o objednávkach do systé …
Weight Based Shipping Table Rate for WooCommerce – Flexible Shipping
flexible-shipping
Weight based shipping methods for WooCommerce. Flexible shipping with table rate rules by cart weight and order value. Accurate rates at checkout.
Invelity MyGLS connect Developer Profile
8 plugins · 380 total installs
How We Detect Invelity MyGLS connect
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/invelity-mygls-connect/assets/css/invelity-mygls-connect-admin.css/wp-content/plugins/invelity-mygls-connect/assets/js/invelity-mygls-connect-admin.js/wp-content/plugins/invelity-mygls-connect/assets/js/invelity-mygls-connect-admin.jsinvelity-mygls-connect-admin.css?ver=invelity-mygls-connect-admin.js?ver=HTML / DOM Fingerprints
invelity-mygls-connect-wrapperdata-plugin-sluginvelityMyGLSConnectAdmin