
LTL Freight Quotes – GlobalTranz Edition Security & Risk Analysis
wordpress.org/plugins/ltl-freight-quotes-globaltranz-editionReal-time LTL freight quotes from GlobalTranz. Fifteen day free trial.
Is LTL Freight Quotes – GlobalTranz Edition Safe to Use in 2026?
Generally Safe
Score 98/100LTL Freight Quotes – GlobalTranz Edition has a strong security track record. Known vulnerabilities have been patched promptly.
The "ltl-freight-quotes-globaltranz-edition" plugin v2.3.19 exhibits a mixed security posture. While it demonstrates some good practices like a significant percentage of SQL queries using prepared statements and a majority of output being properly escaped, there are notable areas of concern. The large attack surface, with 42 entry points and 28 of them lacking authentication checks, presents a significant risk. Furthermore, the taint analysis revealed two high-severity flows with unsanitized paths, indicating potential vulnerabilities that could be exploited if user input is not handled carefully.
The vulnerability history shows a pattern of critical issues, with past CVEs including SQL Injection and Missing Authorization, which are directly relevant to the findings in the static and taint analysis. The fact that there are currently no unpatched CVEs is a positive sign, but the recurring nature of these vulnerability types suggests underlying architectural weaknesses that need to be addressed. While the absence of dangerous functions and file operations is encouraging, the number of AJAX handlers without authentication is a substantial weakness that could lead to unauthorized actions or information disclosure.
In conclusion, the plugin has strengths in its handling of SQL and output escaping, and it's positive that existing vulnerabilities are patched. However, the significant number of unprotected entry points and the presence of high-severity taint flows are critical weaknesses. The historical prevalence of authorization and injection vulnerabilities further underscores the need for robust security measures, particularly around input validation and access control for its extensive attack surface.
Key Concerns
- Large attack surface without auth checks
- High severity taint flows
- REST API routes without permission callbacks
- AJAX handlers without auth checks
- External HTTP requests (potential for SSRF/MITM)
- Historical SQL Injection vulnerability
- Historical Missing Authorization vulnerability
- Significant percentage of SQL not prepared
- Moderate percentage of output not escaped
LTL Freight Quotes – GlobalTranz Edition Security Vulnerabilities
CVEs by Year
Severity Breakdown
2 total CVEs
LTL Freight Quotes – GlobalTranz Edition <= 2.3.12 - Missing Authorization to Unauthenticated Settings Update
LTL Freight Quotes – GlobalTranz Edition <= 2.3.11 - Unauthenticated SQL Injection
LTL Freight Quotes – GlobalTranz Edition Code Analysis
SQL Query Safety
Output Escaping
Data Flow Analysis
LTL Freight Quotes – GlobalTranz Edition Attack Surface
AJAX Handlers 41
REST API Routes 1
WordPress Hooks 81
Scheduled Events 2
Maintenance & Trust
LTL Freight Quotes – GlobalTranz Edition Maintenance & Trust
Maintenance Signals
Community Trust
LTL Freight Quotes – GlobalTranz Edition Alternatives
LTL Freight Quotes – FreightQuote Edition
ltl-freight-quotes-freightquote-edition
Real-time LTL freight quotes from FreightQuote. Fifteen day free trial.
LTL Freight Quotes – XPO Edition
ltl-freight-quotes-xpo-edition
Real-time LTL freight quotes from XPO Logistics. Fifteen day free trial.
LTL Freight Quotes – Unishippers Edition
ltl-freight-quotes-unishippers-edition
Real-time Unishippers freight quotes from Unishippers. Fifteen day free trial.
LTL Freight Quotes – Estes Edition
ltl-freight-quotes-estes-edition
Real-time LTL freight quotes from Estes. Fifteen day free trial.
LTL Freight Quotes – Old Dominion Edition
ltl-freight-quotes-odfl-edition
Real-time LTL freight quotes from Old Dominion Freight Line. Fifteen day free trial.
LTL Freight Quotes – GlobalTranz Edition Developer Profile
29 plugins · 1K total installs
How We Detect LTL Freight Quotes – GlobalTranz Edition
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/ltl-freight-quotes-globaltranz-edition/assets/css/wickedpicker.min.css/wp-content/plugins/ltl-freight-quotes-globaltranz-edition/assets/js/wickedpicker.js/wp-content/plugins/ltl-freight-quotes-globaltranz-edition/assets/js/en-globaltranz-settings.js/wp-content/plugins/ltl-freight-quotes-globaltranz-edition/includes/templates/logs/en-json-tree-view/en-jtv-style.css/wp-content/plugins/ltl-freight-quotes-globaltranz-edition/includes/templates/logs/en-json-tree-view/en-jtv-script.js/wp-content/plugins/ltl-freight-quotes-globaltranz-edition/includes/templates/shipping-rules/assets/js/shipping_rules.js/wp-content/plugins/ltl-freight-quotes-globaltranz-edition/includes/templates/shipping-rules/assets/css/shipping_rules.css/wp-content/plugins/ltl-freight-quotes-globaltranz-edition/assets/js/wickedpicker.js/wp-content/plugins/ltl-freight-quotes-globaltranz-edition/assets/js/en-globaltranz-settings.js/wp-content/plugins/ltl-freight-quotes-globaltranz-edition/includes/templates/logs/en-json-tree-view/en-jtv-script.js/wp-content/plugins/ltl-freight-quotes-globaltranz-edition/includes/templates/shipping-rules/assets/js/shipping_rules.jsen-globaltranz-settings.js?ver=1.2.0wickedpicker.js?ver=1.0.0shipping_rules.js?ver=1.0.0shipping_rules.css?ver=1.0.0en-jtv-script.js?ver=1.0.0en-jtv-style.css?ver=1.0.0wickedpicker.min.css?ver=1.0.0HTML / DOM Fingerprints
en-jtv-containeren-jtv-nodeen-jtv-keyen-jtv-valueen-gtz-shipping-rules-sectiondata-plugin-name="LTL Freight Quotes – GlobalTranz Edition"data-version="2.3.19"scripten_globaltranz_admin_script