LTL Freight Quotes – FreightQuote Edition Security & Risk Analysis

wordpress.org/plugins/ltl-freight-quotes-freightquote-edition

Real-time LTL freight quotes from FreightQuote. Fifteen day free trial.

70 active installs v2.4.17 PHP + WP 6.4+ Updated Feb 4, 2026
eniturefreightquoteltl-freight-quotesltl-freight-ratesshipping-estimates
98
A · Safe
CVEs total2
Unpatched0
Last CVEFeb 12, 2025
Safety Verdict

Is LTL Freight Quotes – FreightQuote Edition Safe to Use in 2026?

Generally Safe

Score 98/100

LTL Freight Quotes – FreightQuote Edition has a strong security track record. Known vulnerabilities have been patched promptly.

2 known CVEsLast CVE: Feb 12, 2025Updated 1mo ago
Risk Assessment

The "ltl-freight-quotes-freightquote-edition" plugin version 2.4.17 exhibits a mixed security posture. While it demonstrates good practices such as a high percentage of properly escaped output and a significant number of nonce and capability checks, there are notable areas of concern. The presence of one unprotected REST API route is a direct entry point for potential unauthorized access or manipulation.

Static analysis revealed a concerning number of flows with unsanitized paths, with one identified as high severity. This, coupled with a significant percentage of SQL queries not using prepared statements, suggests a potential for SQL injection vulnerabilities. The plugin's history of known CVEs, including a high-severity one related to SQL Injection and missing authorization, further reinforces these concerns and indicates a recurring pattern of vulnerabilities in these areas. While there are no currently unpatched CVEs, the past issues and current code signals warrant careful attention.

In conclusion, while the plugin has strengths in output escaping and authorization checks, the identified unprotected API route and the potential for SQL injection due to a high number of raw SQL queries and unsanitized paths in taint analysis, coupled with historical vulnerability patterns, present significant risks. The plugin is not inherently insecure, but these specific weaknesses require remediation.

Key Concerns

  • REST API route without permission callback
  • Flows with unsanitized paths (high severity)
  • SQL queries not using prepared statements
  • High severity historical vulnerability
  • Medium severity historical vulnerability
Vulnerabilities
2

LTL Freight Quotes – FreightQuote Edition Security Vulnerabilities

CVEs by Year

2 CVEs in 2025
2025
Patched Has unpatched

Severity Breakdown

High
1
Medium
1

2 total CVEs

CVE-2025-22290high · 7.5Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')

LTL Freight Quotes – FreightQuote Edition <= 2.3.11 - Unauthenticated SQL Injection

Feb 12, 2025 Patched in 2.3.12 (38d)
CVE-2025-22287medium · 5.3Missing Authorization

LTL Freight Quotes – FreightQuote Edition <= 2.3.11 - Missing Authorization

Feb 12, 2025 Patched in 2.3.12 (38d)
Code Analysis
Analyzed Mar 16, 2026

LTL Freight Quotes – FreightQuote Edition Code Analysis

Dangerous Functions
0
Raw SQL Queries
54
35 prepared
Unescaped Output
61
266 escaped
Nonce Checks
13
Capability Checks
30
File Operations
0
External Requests
4
Bundled Libraries
0

SQL Query Safety

39% prepared89 total queries

Output Escaping

81% escaped327 total outputs
Data Flows
8 unsanitized

Data Flow Analysis

15 flows8 with unsanitized paths
freightquote_warehouse_template (warehouse-dropship\wild-delivery.php:40)
Source (user input) Sink (dangerous op) Sanitizer Transform Unsanitized Sanitized
Attack Surface
1 unprotected

LTL Freight Quotes – FreightQuote Edition Attack Surface

Entry Points31
Unprotected1

AJAX Handlers 30

noprivwp_ajax_freightquote_ltl_validate_keysfreightquote-test-connection.php:13
authwp_ajax_freightquote_ltl_validate_keysfreightquote-test-connection.php:14
noprivwp_ajax_freightquote_fdltl-freight-quotes-freightquote-edition.php:405
authwp_ajax_freightquote_fdltl-freight-quotes-freightquote-edition.php:406
noprivwp_ajax_en_fq_save_shipping_ruleshipping-rules\shipping-rules-save.php:24
authwp_ajax_en_fq_save_shipping_ruleshipping-rules\shipping-rules-save.php:25
noprivwp_ajax_en_fq_edit_shipping_ruleshipping-rules\shipping-rules-save.php:27
authwp_ajax_en_fq_edit_shipping_ruleshipping-rules\shipping-rules-save.php:28
noprivwp_ajax_en_fq_delete_shipping_ruleshipping-rules\shipping-rules-save.php:30
authwp_ajax_en_fq_delete_shipping_ruleshipping-rules\shipping-rules-save.php:31
noprivwp_ajax_en_fq_update_shipping_rule_statusshipping-rules\shipping-rules-save.php:33
authwp_ajax_en_fq_update_shipping_rule_statusshipping-rules\shipping-rules-save.php:34
authwp_ajax_freightquote_en_ltl_activate_hit_to_update_planupdate-plan.php:11
noprivwp_ajax_freightquote_en_ltl_activate_hit_to_update_planupdate-plan.php:12
noprivwp_ajax_eniture_chr_wd_get_addresswarehouse-dropship\wild\includes\wild-delivery-save.php:24
authwp_ajax_eniture_chr_wd_get_addresswarehouse-dropship\wild\includes\wild-delivery-save.php:25
noprivwp_ajax_en_fq_wd_save_warehousewarehouse-dropship\wild\includes\wild-delivery-save.php:28
authwp_ajax_en_fq_wd_save_warehousewarehouse-dropship\wild\includes\wild-delivery-save.php:29
noprivwp_ajax_en_fq_wd_edit_warehousewarehouse-dropship\wild\includes\wild-delivery-save.php:31
authwp_ajax_en_fq_wd_edit_warehousewarehouse-dropship\wild\includes\wild-delivery-save.php:32
noprivwp_ajax_en_fq_wd_delete_warehousewarehouse-dropship\wild\includes\wild-delivery-save.php:34
authwp_ajax_en_fq_wd_delete_warehousewarehouse-dropship\wild\includes\wild-delivery-save.php:35
noprivwp_ajax_en_fq_wd_save_dropshipwarehouse-dropship\wild\includes\wild-delivery-save.php:38
authwp_ajax_en_fq_wd_save_dropshipwarehouse-dropship\wild\includes\wild-delivery-save.php:39
noprivwp_ajax_en_fq_wd_edit_dropshipwarehouse-dropship\wild\includes\wild-delivery-save.php:41
authwp_ajax_en_fq_wd_edit_dropshipwarehouse-dropship\wild\includes\wild-delivery-save.php:42
noprivwp_ajax_en_fq_wd_delete_dropshipwarehouse-dropship\wild\includes\wild-delivery-save.php:44
authwp_ajax_en_fq_wd_delete_dropshipwarehouse-dropship\wild\includes\wild-delivery-save.php:45
noprivwp_ajax_fq_ltl_en_wd_bulk_delete_locationswarehouse-dropship\wild\includes\wild-delivery-save.php:47
authwp_ajax_fq_ltl_en_wd_bulk_delete_locationswarehouse-dropship\wild\includes\wild-delivery-save.php:48

REST API Routes 1

POST/wp-json/fdo-company-id/update-statusltl-freight-quotes-freightquote-edition.php:453
WordPress Hooks 74
filteren_accessorial_excludedfeightquote-carrier-service.php:602
actionadmin_noticesfreightquote-admin-filter.php:42
filterwoocommerce_product_importer_parsed_datafreightquote-admin-filter.php:305
filteren_fdo_image_urls_mergefreightquote-group-package.php:368
filterforce_show_methodsfreightquote-ltl-shipping-class.php:191
filterwoocommerce_package_ratesfreightquote-ltl-shipping-class.php:853
filterwoocommerce_package_ratesfreightquote-ltl-shipping-class.php:878
filterwoocommerce_package_ratesfreightquote-ltl-shipping-class.php:1096
filterwoocommerce_settings_tabs_arrayfreightquote-tab-class.php:25
actionbefore_woocommerce_initltl-freight-quotes-freightquote-edition.php:45
filteren_pluginsltl-freight-quotes-freightquote-edition.php:62
actionadmin_enqueue_scriptsltl-freight-quotes-freightquote-edition.php:64
filterfreightquote_en_woo_plans_notification_actionltl-freight-quotes-freightquote-edition.php:95
filterfreightquote_en_woo_plans_notification_message_actionltl-freight-quotes-freightquote-edition.php:107
actionadmin_initltl-freight-quotes-freightquote-edition.php:134
filterfreightquote_en_woo_plans_nested_notification_message_actionltl-freight-quotes-freightquote-edition.php:168
actionadmin_enqueue_scriptsltl-freight-quotes-freightquote-edition.php:171
filterplugin_action_linksltl-freight-quotes-freightquote-edition.php:229
actionadmin_initltl-freight-quotes-freightquote-edition.php:262
actionadmin_initltl-freight-quotes-freightquote-edition.php:263
actionadmin_initltl-freight-quotes-freightquote-edition.php:264
actionadmin_noticesltl-freight-quotes-freightquote-edition.php:302
filterwoocommerce_get_settings_pagesltl-freight-quotes-freightquote-edition.php:304
actionadmin_initltl-freight-quotes-freightquote-edition.php:307
actionwoocommerce_shipping_initltl-freight-quotes-freightquote-edition.php:308
filterwoocommerce_shipping_methodsltl-freight-quotes-freightquote-edition.php:309
filterwoocommerce_package_ratesltl-freight-quotes-freightquote-edition.php:310
actioninitltl-freight-quotes-freightquote-edition.php:311
filterwoocommerce_cart_shipping_method_full_labelltl-freight-quotes-freightquote-edition.php:312
actionwp_enqueue_scriptsltl-freight-quotes-freightquote-edition.php:325
actionupgrader_process_completeltl-freight-quotes-freightquote-edition.php:365
filterfreightquote_quests_quotes_plans_suscription_and_featuresltl-freight-quotes-freightquote-edition.php:367
filterfreightquote_quests_plans_notification_linkltl-freight-quotes-freightquote-edition.php:387
actionrest_api_initltl-freight-quotes-freightquote-edition.php:450
filteren_suppress_parcel_rates_hookltl-freight-quotes-freightquote-edition.php:514
actionwoocommerce_thankyouorder\en-order-export.php:14
actioninitorder\en-order-export.php:15
actionen_async_orders_exporting_processorder\en-order-export.php:16
filtercron_schedulesorder\en-order-export.php:17
actionwoocommerce_order_actionsorder\en-order-widget.php:17
actionwoocommerce_order_before_calculate_totalsorder\rates\order-rates.php:13
filteren_order_accessoriesorder\rates\order-rates.php:14
filteren_app_common_plan_statusproduct\en-product-detail.php:23
filteren_compatible_optimized_product_optionsproduct\en-product-detail.php:26
actionwoocommerce_product_options_shippingproduct\en-product-detail.php:31
actionwoocommerce_process_product_metaproduct\en-product-detail.php:32
actionwoocommerce_product_after_variable_attributesproduct\en-product-detail.php:35
actionwoocommerce_save_product_variationproduct\en-product-detail.php:36
filterEn_Plugins_dropship_filterproduct\en-product-detail.php:39
filterEn_Plugins_variable_freight_classification_filterproduct\en-product-detail.php:40
filteren_freightquote_freight_handling_unit_fieldsproduct\en-product-detail.php:45
actionwoocommerce_product_options_shippingproduct\en-product-detail.php:48
actionwoocommerce_process_product_metaproduct\en-product-detail.php:49
actionwoocommerce_product_after_variable_attributesproduct\en-product-detail.php:52
actionwoocommerce_save_product_variationproduct\en-product-detail.php:53
filteren_wd_update_query_stringstandard-package-addon\instore-pickup-local-delivery\instore-local-delivery.php:16
filteren_wd_origin_array_setstandard-package-addon\instore-pickup-local-delivery\instore-local-delivery.php:17
filteren_wd_standard_plansstandard-package-addon\instore-pickup-local-delivery\instore-local-delivery.php:18
filtersuppress_local_deliverystandard-package-addon\instore-pickup-local-delivery\instore-local-delivery.php:19
filterwoocommerce_product_export_product_column_en_nicknametemplate\csv-export.php:9
filterwoocommerce_product_export_product_column_en_citytemplate\csv-export.php:10
filterwoocommerce_product_export_product_column_en_statetemplate\csv-export.php:11
filterwoocommerce_product_export_product_column_en_ziptemplate\csv-export.php:12
filterwoocommerce_product_export_product_column_en_countrytemplate\csv-export.php:13
filterwoocommerce_product_export_product_column_en_product_freight_classtemplate\csv-export.php:16
filterwoocommerce_product_export_product_column_en_product_freight_class_variationtemplate\csv-export.php:17
filterwoocommerce_product_export_column_namestemplate\csv-export.php:20
filterwoocommerce_product_export_product_default_columnstemplate\csv-export.php:21
actionwoocommerce_product_options_shippingtemplate\products-nested-options.php:31
actionwoocommerce_process_product_metatemplate\products-nested-options.php:34
actionwoocommerce_product_after_variable_attributestemplate\products-nested-options.php:44
actionwoocommerce_save_product_variationtemplate\products-nested-options.php:48
actionadmin_noticesupdate-plan.php:251
actionadmin_enqueue_scriptswarehouse-dropship\wild-delivery.php:32

Scheduled Events 1

en_async_orders_exporting_process
Maintenance & Trust

LTL Freight Quotes – FreightQuote Edition Maintenance & Trust

Maintenance Signals

WordPress version tested6.9.4
Last updatedFeb 4, 2026
PHP min version
Downloads7K

Community Trust

Rating0/100
Number of ratings0
Active installs70
Developer Profile

LTL Freight Quotes – FreightQuote Edition Developer Profile

enituretechnology

29 plugins · 1K total installs

93
trust score
Avg Security Score
98/100
Avg Patch Time
11 days
View full developer profile
Detection Fingerprints

How We Detect LTL Freight Quotes – FreightQuote Edition

Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.

Asset Fingerprints

Asset Paths
/wp-content/plugins/ltl-freight-quotes-freightquote-edition/logs/en-json-tree-view/en-jtv-style.css/wp-content/plugins/ltl-freight-quotes-freightquote-edition/logs/en-json-tree-view/en-jtv-script.js/wp-content/plugins/ltl-freight-quotes-freightquote-edition/shipping-rules/assets/js/shipping_rules.js/wp-content/plugins/ltl-freight-quotes-freightquote-edition/shipping-rules/assets/css/shipping_rules.css/wp-content/plugins/ltl-freight-quotes-freightquote-edition/js/en-freightquote.js
Script Paths
/wp-content/plugins/ltl-freight-quotes-freightquote-edition/logs/en-json-tree-view/en-jtv-script.js/wp-content/plugins/ltl-freight-quotes-freightquote-edition/shipping-rules/assets/js/shipping_rules.js/wp-content/plugins/ltl-freight-quotes-freightquote-edition/js/en-freightquote.js
Version Parameters
ltl-freight-quotes-freightquote-edition/logs/en-json-tree-view/en-jtv-style.css?ver=ltl-freight-quotes-freightquote-edition/logs/en-json-tree-view/en-jtv-script.js?ver=ltl-freight-quotes-freightquote-edition/shipping-rules/assets/js/shipping_rules.js?ver=ltl-freight-quotes-freightquote-edition/shipping-rules/assets/css/shipping_rules.css?ver=ltl-freight-quotes-freightquote-edition/js/en-freightquote.js?ver=

HTML / DOM Fingerprints

CSS Classes
freightquote-shipping-rules-form
HTML Comments
<!-- LTL Freightquote for WooCommerce - Freightquote Edition --><!-- Copyright (C) 2016 Eniture LLC d/b/a Eniture Technology --><!-- This program is free software; you can redistribute it and/or --><!-- modify it under the terms of the GNU General Public License version 2 -->+12 more
Data Attributes
en_tree_view_urlen_fq_sr_script
JS Globals
en_freight_quote_admin_script
FAQ

Frequently Asked Questions about LTL Freight Quotes – FreightQuote Edition