LTL Freight Quotes – Estes Edition Security & Risk Analysis

wordpress.org/plugins/ltl-freight-quotes-estes-edition

Real-time LTL freight quotes from Estes. Fifteen day free trial.

30 active installs v3.4.6 PHP + WP 6.4+ Updated Jan 30, 2026
enitureestesltl-freight-quotesltl-freight-ratesshipping-estimates
98
A · Safe
CVEs total1
Unpatched0
Last CVEFeb 14, 2025
Safety Verdict

Is LTL Freight Quotes – Estes Edition Safe to Use in 2026?

Generally Safe

Score 98/100

LTL Freight Quotes – Estes Edition has a strong security track record. Known vulnerabilities have been patched promptly.

1 known CVELast CVE: Feb 14, 2025Updated 2mo ago
Risk Assessment

The "ltl-freight-quotes-estes-edition" v3.4.6 plugin exhibits a mixed security posture. While it demonstrates some good security practices, such as the absence of dangerous functions and file operations, and a reasonable number of nonce and capability checks, several concerning areas require attention. The presence of unprotected AJAX handlers and a REST API route without permission callbacks significantly expands the attack surface and introduces potential vulnerabilities that could be exploited by unauthenticated users. Furthermore, the taint analysis reveals a high severity flow with unsanitized input, suggesting a potential for serious security flaws. The plugin's vulnerability history, while currently showing no unpatched CVEs, has previously had a high-severity SQL Injection vulnerability, indicating a past weakness in handling user input for database queries.

Overall, the plugin has strengths in its lack of certain dangerous code patterns, but its security is undermined by critical flaws in its entry point handling and data sanitization. The previously exploited SQL injection vulnerability highlights a recurring concern with input validation. While there are no immediate unpatched threats, the identified unprotected entry points and taint analysis findings represent a notable risk that should be addressed proactively to prevent future exploitation. It is recommended to review and secure all identified unprotected entry points and investigate the high-severity taint flow to ensure proper sanitization and authorization.

Key Concerns

  • Unprotected AJAX handlers
  • REST API route without permission callbacks
  • High severity taint flow
  • SQL queries with low prepared statement usage
  • Output escaping below acceptable threshold
  • Previous high severity vulnerability
Vulnerabilities
1

LTL Freight Quotes – Estes Edition Security Vulnerabilities

CVEs by Year

1 CVE in 2025
2025
Patched Has unpatched

Severity Breakdown

High
1

1 total CVE

CVE-2024-13488high · 7.5Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')

LTL Freight Quotes – Estes Edition <= 3.3.7 - Unauthenticated SQL Injection

Feb 14, 2025 Patched in 3.3.8 (1d)
Code Analysis
Analyzed Mar 16, 2026

LTL Freight Quotes – Estes Edition Code Analysis

Dangerous Functions
0
Raw SQL Queries
31
18 prepared
Unescaped Output
101
165 escaped
Nonce Checks
13
Capability Checks
28
File Operations
0
External Requests
4
Bundled Libraries
0

SQL Query Safety

37% prepared49 total queries

Output Escaping

62% escaped266 total outputs
Data Flows
8 unsanitized

Data Flow Analysis

13 flows8 with unsanitized paths
warehouse_template (warehouse-dropship\wild-delivery.php:38)
Source (user input) Sink (dangerous op) Sanitizer Transform Unsanitized Sanitized
Attack Surface
3 unprotected

LTL Freight Quotes – Estes Edition Attack Surface

Entry Points31
Unprotected3

AJAX Handlers 30

noprivwp_ajax_estes_test_connectionestes-test-connection.php:12
authwp_ajax_estes_test_connectionestes-test-connection.php:13
noprivwp_ajax_estes_fdltl-freight-quotes-estes-edition.php:501
authwp_ajax_estes_fdltl-freight-quotes-estes-edition.php:502
noprivwp_ajax_en_estes_save_shipping_ruleshipping-rules\shipping-rules-save.php:24
authwp_ajax_en_estes_save_shipping_ruleshipping-rules\shipping-rules-save.php:25
noprivwp_ajax_en_estes_edit_shipping_ruleshipping-rules\shipping-rules-save.php:27
authwp_ajax_en_estes_edit_shipping_ruleshipping-rules\shipping-rules-save.php:28
noprivwp_ajax_en_estes_delete_shipping_ruleshipping-rules\shipping-rules-save.php:30
authwp_ajax_en_estes_delete_shipping_ruleshipping-rules\shipping-rules-save.php:31
noprivwp_ajax_en_estes_update_shipping_rule_statusshipping-rules\shipping-rules-save.php:33
authwp_ajax_en_estes_update_shipping_rule_statusshipping-rules\shipping-rules-save.php:34
authwp_ajax_en_estes_freight_activate_hit_to_update_planupdate-plan.php:10
noprivwp_ajax_en_estes_freight_activate_hit_to_update_planupdate-plan.php:11
noprivwp_ajax_estes_ltl_en_wd_get_addresswarehouse-dropship\wild\includes\wild-delivery-save.php:24
authwp_ajax_estes_ltl_en_wd_get_addresswarehouse-dropship\wild\includes\wild-delivery-save.php:25
noprivwp_ajax_en_wd_delete_dropshipwarehouse-dropship\wild\includes\wild-delivery-save.php:27
authwp_ajax_en_wd_delete_dropshipwarehouse-dropship\wild\includes\wild-delivery-save.php:28
noprivwp_ajax_estes_ltl_en_wd_save_warehousewarehouse-dropship\wild\includes\wild-delivery-save.php:30
authwp_ajax_estes_ltl_en_wd_save_warehousewarehouse-dropship\wild\includes\wild-delivery-save.php:31
noprivwp_ajax_en_wd_save_dropshipwarehouse-dropship\wild\includes\wild-delivery-save.php:33
authwp_ajax_en_wd_save_dropshipwarehouse-dropship\wild\includes\wild-delivery-save.php:34
noprivwp_ajax_en_wd_edit_dropshipwarehouse-dropship\wild\includes\wild-delivery-save.php:37
authwp_ajax_en_wd_edit_dropshipwarehouse-dropship\wild\includes\wild-delivery-save.php:38
noprivwp_ajax_en_wd_delete_warehousewarehouse-dropship\wild\includes\wild-delivery-save.php:40
authwp_ajax_en_wd_delete_warehousewarehouse-dropship\wild\includes\wild-delivery-save.php:41
noprivwp_ajax_en_wd_edit_warehousewarehouse-dropship\wild\includes\wild-delivery-save.php:43
authwp_ajax_en_wd_edit_warehousewarehouse-dropship\wild\includes\wild-delivery-save.php:44
noprivwp_ajax_en_estes_wd_bulk_delete_locationswarehouse-dropship\wild\includes\wild-delivery-save.php:46
authwp_ajax_en_estes_wd_bulk_delete_locationswarehouse-dropship\wild\includes\wild-delivery-save.php:47

REST API Routes 1

POST/wp-json/fdo-company-id/update-statusltl-freight-quotes-estes-edition.php:549
WordPress Hooks 74
filterwoocommerce_product_importer_parsed_dataestes-admin-filter.php:184
filteren_fdo_image_urls_mergeestes-group-package.php:370
filterforce_show_methodsestes-shipping-class.php:217
filterwoocommerce_package_ratesestes-shipping-class.php:887
filterwoocommerce_package_ratesestes-shipping-class.php:911
filterwoocommerce_package_ratesestes-shipping-class.php:926
filterwoocommerce_settings_tabs_arrayestes-tab-class.php:23
actionbefore_woocommerce_initltl-freight-quotes-estes-edition.php:28
filteren_pluginsltl-freight-quotes-estes-edition.php:41
filteren_woo_plans_notification_actionltl-freight-quotes-estes-edition.php:69
filteren_woo_plans_notification_message_actionltl-freight-quotes-estes-edition.php:80
filteren_woo_plans_nested_notification_message_actionltl-freight-quotes-estes-edition.php:93
actionadmin_initltl-freight-quotes-estes-edition.php:120
actionadmin_noticesltl-freight-quotes-estes-edition.php:131
actionadmin_initltl-freight-quotes-estes-edition.php:147
actionadmin_noticesltl-freight-quotes-estes-edition.php:156
actionadmin_enqueue_scriptsltl-freight-quotes-estes-edition.php:199
actionadmin_enqueue_scriptsltl-freight-quotes-estes-edition.php:214
actionadmin_initltl-freight-quotes-estes-edition.php:249
actionupgrader_process_completeltl-freight-quotes-estes-edition.php:317
actionwoocommerce_shipping_initltl-freight-quotes-estes-edition.php:323
filterwoocommerce_shipping_methodsltl-freight-quotes-estes-edition.php:324
filterwoocommerce_get_settings_pagesltl-freight-quotes-estes-edition.php:325
filterwoocommerce_package_ratesltl-freight-quotes-estes-edition.php:326
filterwoocommerce_shipping_calculator_enable_cityltl-freight-quotes-estes-edition.php:327
filterplugin_action_linksltl-freight-quotes-estes-edition.php:334
filterwoocommerce_cart_no_shipping_available_htmlltl-freight-quotes-estes-edition.php:359
actionwp_enqueue_scriptsltl-freight-quotes-estes-edition.php:372
filterestes_ltl_quotes_quotes_plans_suscription_and_featuresltl-freight-quotes-estes-edition.php:412
filterestes_ltl_quotes_plans_notification_linkltl-freight-quotes-estes-edition.php:444
actionrest_api_initltl-freight-quotes-estes-edition.php:546
filteren_suppress_parcel_rates_hookltl-freight-quotes-estes-edition.php:613
actionwoocommerce_thankyouorder\en-order-export.php:14
actioninitorder\en-order-export.php:15
actionen_async_orders_exporting_processorder\en-order-export.php:16
filtercron_schedulesorder\en-order-export.php:17
actionwoocommerce_order_actionsorder\en-order-widget.php:17
actionwoocommerce_order_before_calculate_totalsorder\rates\order-rates.php:13
filteren_order_accessoriesorder\rates\order-rates.php:14
filteren_app_common_plan_statusproduct\en-common-product-detail.php:26
filteren_compatible_optimized_product_optionsproduct\en-common-product-detail.php:29
actionwoocommerce_product_options_shippingproduct\en-common-product-detail.php:33
actionwoocommerce_process_product_metaproduct\en-common-product-detail.php:34
actionwoocommerce_product_after_variable_attributesproduct\en-common-product-detail.php:37
actionwoocommerce_save_product_variationproduct\en-common-product-detail.php:38
filteren_insurance_filterproduct\en-common-product-detail.php:41
filteren_app_common_plan_statusproduct\en-product-detail.php:23
filteren_compatible_optimized_product_optionsproduct\en-product-detail.php:26
actionwoocommerce_product_options_shippingproduct\en-product-detail.php:31
actionwoocommerce_process_product_metaproduct\en-product-detail.php:32
actionwoocommerce_product_after_variable_attributesproduct\en-product-detail.php:35
actionwoocommerce_save_product_variationproduct\en-product-detail.php:36
filterEn_Plugins_dropship_filterproduct\en-product-detail.php:39
filterEn_Plugins_variable_freight_classification_filterproduct\en-product-detail.php:40
filteren_estes_wd_update_query_stringstandard-package-addon\instore-pickup-local-delivery\instore-local-delivery.php:16
filteren_estes_wd_origin_array_setstandard-package-addon\instore-pickup-local-delivery\instore-local-delivery.php:17
filteren_estes_wd_standard_plansstandard-package-addon\instore-pickup-local-delivery\instore-local-delivery.php:18
filteren_estes_suppress_local_deliverystandard-package-addon\instore-pickup-local-delivery\instore-local-delivery.php:19
filterwoocommerce_product_export_product_column_en_nicknametemplate\csv-export.php:9
filterwoocommerce_product_export_product_column_en_citytemplate\csv-export.php:10
filterwoocommerce_product_export_product_column_en_statetemplate\csv-export.php:11
filterwoocommerce_product_export_product_column_en_ziptemplate\csv-export.php:12
filterwoocommerce_product_export_product_column_en_countrytemplate\csv-export.php:13
filterwoocommerce_product_export_product_column_en_product_freight_classtemplate\csv-export.php:16
filterwoocommerce_product_export_product_column_en_product_freight_class_variationtemplate\csv-export.php:17
filterwoocommerce_product_export_column_namestemplate\csv-export.php:20
filterwoocommerce_product_export_product_default_columnstemplate\csv-export.php:21
actionwoocommerce_product_options_shippingtemplate\products-nested-options.php:32
actionwoocommerce_process_product_metatemplate\products-nested-options.php:35
actionwoocommerce_product_after_variable_attributestemplate\products-nested-options.php:45
actionwoocommerce_save_product_variationtemplate\products-nested-options.php:49
actionadmin_noticesupdate-plan.php:254
filterestes_ltl_en_wd_get_addresswarehouse-dropship\get-distance-request.php:21
actionadmin_enqueue_scriptswarehouse-dropship\wild-delivery.php:30

Scheduled Events 1

en_async_orders_exporting_process
Maintenance & Trust

LTL Freight Quotes – Estes Edition Maintenance & Trust

Maintenance Signals

WordPress version tested6.9.4
Last updatedJan 30, 2026
PHP min version
Downloads5K

Community Trust

Rating74/100
Number of ratings3
Active installs30
Developer Profile

LTL Freight Quotes – Estes Edition Developer Profile

enituretechnology

29 plugins · 1K total installs

93
trust score
Avg Security Score
98/100
Avg Patch Time
11 days
View full developer profile
Detection Fingerprints

How We Detect LTL Freight Quotes – Estes Edition

Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.

Asset Fingerprints

Asset Paths
/wp-content/plugins/ltl-freight-quotes-estes-edition/logs/en-json-tree-view/en-jtv-style.css/wp-content/plugins/ltl-freight-quotes-estes-edition/logs/en-json-tree-view/en-jtv-script.js/wp-content/plugins/ltl-freight-quotes-estes-edition/shipping-rules/assets/js/shipping_rules.js/wp-content/plugins/ltl-freight-quotes-estes-edition/shipping-rules/assets/css/shipping_rules.css/wp-content/plugins/ltl-freight-quotes-estes-edition/css/wickedpicker.min.css/wp-content/plugins/ltl-freight-quotes-estes-edition/js/wickedpicker.js/wp-content/plugins/ltl-freight-quotes-estes-edition/css/estes-style.css
Script Paths
wp-content/plugins/ltl-freight-quotes-estes-edition/logs/en-json-tree-view/en-jtv-script.jswp-content/plugins/ltl-freight-quotes-estes-edition/shipping-rules/assets/js/shipping_rules.jswp-content/plugins/ltl-freight-quotes-estes-edition/js/wickedpicker.js
Version Parameters
ltl-freight-quotes-estes-edition/shipping-rules/assets/js/shipping_rules.js?ver=1.0.9ltl-freight-quotes-estes-edition/shipping-rules/assets/css/shipping_rules.css?ver=1.0.4ltl-freight-quotes-estes-edition/css/wickedpicker.min.css?ver=1.0.0ltl-freight-quotes-estes-edition/js/wickedpicker.js?ver=1.0.0ltl-freight-quotes-estes-edition/css/estes-style.css?ver=1.1.6

HTML / DOM Fingerprints

CSS Classes
estes-style
JS Globals
en_estes_sr_script
FAQ

Frequently Asked Questions about LTL Freight Quotes – Estes Edition