LTL Freight Quotes – GlobalTranz Edition Security & Risk Analysis

wordpress.org/plugins/ltl-freight-quotes-globaltranz-edition

Real-time LTL freight quotes from GlobalTranz. Fifteen day free trial.

30 active installs v2.3.19 PHP + WP 6.4+ Updated Jan 28, 2026
enitureglobaltranzltl-freight-quotesltl-freight-ratesshipping-estimates
98
A · Safe
CVEs total2
Unpatched0
Last CVEFeb 19, 2025
Safety Verdict

Is LTL Freight Quotes – GlobalTranz Edition Safe to Use in 2026?

Generally Safe

Score 98/100

LTL Freight Quotes – GlobalTranz Edition has a strong security track record. Known vulnerabilities have been patched promptly.

2 known CVEsLast CVE: Feb 19, 2025Updated 2mo ago
Risk Assessment

The "ltl-freight-quotes-globaltranz-edition" plugin v2.3.19 exhibits a mixed security posture. While it demonstrates some good practices like a significant percentage of SQL queries using prepared statements and a majority of output being properly escaped, there are notable areas of concern. The large attack surface, with 42 entry points and 28 of them lacking authentication checks, presents a significant risk. Furthermore, the taint analysis revealed two high-severity flows with unsanitized paths, indicating potential vulnerabilities that could be exploited if user input is not handled carefully.

The vulnerability history shows a pattern of critical issues, with past CVEs including SQL Injection and Missing Authorization, which are directly relevant to the findings in the static and taint analysis. The fact that there are currently no unpatched CVEs is a positive sign, but the recurring nature of these vulnerability types suggests underlying architectural weaknesses that need to be addressed. While the absence of dangerous functions and file operations is encouraging, the number of AJAX handlers without authentication is a substantial weakness that could lead to unauthorized actions or information disclosure.

In conclusion, the plugin has strengths in its handling of SQL and output escaping, and it's positive that existing vulnerabilities are patched. However, the significant number of unprotected entry points and the presence of high-severity taint flows are critical weaknesses. The historical prevalence of authorization and injection vulnerabilities further underscores the need for robust security measures, particularly around input validation and access control for its extensive attack surface.

Key Concerns

  • Large attack surface without auth checks
  • High severity taint flows
  • REST API routes without permission callbacks
  • AJAX handlers without auth checks
  • External HTTP requests (potential for SSRF/MITM)
  • Historical SQL Injection vulnerability
  • Historical Missing Authorization vulnerability
  • Significant percentage of SQL not prepared
  • Moderate percentage of output not escaped
Vulnerabilities
2

LTL Freight Quotes – GlobalTranz Edition Security Vulnerabilities

CVEs by Year

2 CVEs in 2025
2025
Patched Has unpatched

Severity Breakdown

High
1
Medium
1

2 total CVEs

CVE-2025-1483medium · 5.3Missing Authorization

LTL Freight Quotes – GlobalTranz Edition <= 2.3.12 - Missing Authorization to Unauthenticated Settings Update

Feb 19, 2025 Patched in 2.3.13 (1d)
CVE-2024-13476high · 7.5Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')

LTL Freight Quotes – GlobalTranz Edition <= 2.3.11 - Unauthenticated SQL Injection

Feb 19, 2025 Patched in 2.3.12 (1d)
Code Analysis
Analyzed Mar 16, 2026

LTL Freight Quotes – GlobalTranz Edition Code Analysis

Dangerous Functions
0
Raw SQL Queries
44
39 prepared
Unescaped Output
104
247 escaped
Nonce Checks
7
Capability Checks
8
File Operations
0
External Requests
9
Bundled Libraries
0

SQL Query Safety

47% prepared83 total queries

Output Escaping

70% escaped351 total outputs
Data Flows
11 unsanitized

Data Flow Analysis

15 flows11 with unsanitized paths
engtz_warehouse_template (includes\warehouse-dropship\wild-delivery.php:39)
Source (user input) Sink (dangerous op) Sanitizer Transform Unsanitized Sanitized
Attack Surface
28 unprotected

LTL Freight Quotes – GlobalTranz Edition Attack Surface

Entry Points42
Unprotected28

AJAX Handlers 41

authwp_ajax_en_gtz_ltl_fdo_connection_status_refreshfdo\en-coupon-api.php:9
noprivwp_ajax_en_gtz_ltl_fdo_connection_status_refreshfdo\en-coupon-api.php:10
authwp_ajax_en_gtz_ltl_va_connection_status_refreshfdo\en-coupon-api.php:12
noprivwp_ajax_en_gtz_ltl_va_connection_status_refreshfdo\en-coupon-api.php:13
noprivwp_ajax_gtz_fdfdo\en-coupon-api.php:15
authwp_ajax_gtz_fdfdo\en-coupon-api.php:16
noprivwp_ajax_refresh_carriersincludes\carriers\en-globaltranz-carrier-list.php:27
authwp_ajax_refresh_carriersincludes\carriers\en-globaltranz-carrier-list.php:28
noprivwp_ajax_auto_enable_actionincludes\carriers\en-globaltranz-carrier-list.php:30
authwp_ajax_auto_enable_actionincludes\carriers\en-globaltranz-carrier-list.php:31
noprivwp_ajax_test_connection_callincludes\en-globaltranz-connection-request.php:25
authwp_ajax_test_connection_callincludes\en-globaltranz-connection-request.php:26
noprivwp_ajax_en_gtz_ltl_save_shipping_ruleincludes\templates\shipping-rules\shipping-rules-save.php:19
authwp_ajax_en_gtz_ltl_save_shipping_ruleincludes\templates\shipping-rules\shipping-rules-save.php:20
noprivwp_ajax_en_gtz_ltl_edit_shipping_ruleincludes\templates\shipping-rules\shipping-rules-save.php:22
authwp_ajax_en_gtz_ltl_edit_shipping_ruleincludes\templates\shipping-rules\shipping-rules-save.php:23
noprivwp_ajax_en_gtz_ltl_delete_shipping_ruleincludes\templates\shipping-rules\shipping-rules-save.php:25
authwp_ajax_en_gtz_ltl_delete_shipping_ruleincludes\templates\shipping-rules\shipping-rules-save.php:26
noprivwp_ajax_en_gtz_ltl_update_shipping_rule_statusincludes\templates\shipping-rules\shipping-rules-save.php:28
authwp_ajax_en_gtz_ltl_update_shipping_rule_statusincludes\templates\shipping-rules\shipping-rules-save.php:29
noprivwp_ajax_engtz_wd_get_addressincludes\warehouse-dropship\wild\includes\wild-delivery-save.php:24
authwp_ajax_engtz_wd_get_addressincludes\warehouse-dropship\wild\includes\wild-delivery-save.php:25
noprivwp_ajax_en_wd_delete_dropshipincludes\warehouse-dropship\wild\includes\wild-delivery-save.php:27
authwp_ajax_en_wd_delete_dropshipincludes\warehouse-dropship\wild\includes\wild-delivery-save.php:28
noprivwp_ajax_engtz_wd_save_warehouseincludes\warehouse-dropship\wild\includes\wild-delivery-save.php:30
authwp_ajax_engtz_wd_save_warehouseincludes\warehouse-dropship\wild\includes\wild-delivery-save.php:31
noprivwp_ajax_engtz_wd_save_dropshipincludes\warehouse-dropship\wild\includes\wild-delivery-save.php:33
authwp_ajax_engtz_wd_save_dropshipincludes\warehouse-dropship\wild\includes\wild-delivery-save.php:34
noprivwp_ajax_engtz_wd_edit_dropshipincludes\warehouse-dropship\wild\includes\wild-delivery-save.php:37
authwp_ajax_engtz_wd_edit_dropshipincludes\warehouse-dropship\wild\includes\wild-delivery-save.php:38
noprivwp_ajax_en_wd_delete_warehouseincludes\warehouse-dropship\wild\includes\wild-delivery-save.php:40
authwp_ajax_en_wd_delete_warehouseincludes\warehouse-dropship\wild\includes\wild-delivery-save.php:41
noprivwp_ajax_engtz_wd_edit_warehouseincludes\warehouse-dropship\wild\includes\wild-delivery-save.php:43
authwp_ajax_engtz_wd_edit_warehouseincludes\warehouse-dropship\wild\includes\wild-delivery-save.php:44
noprivwp_ajax_en_gtz_wd_bulk_delete_locationsincludes\warehouse-dropship\wild\includes\wild-delivery-save.php:46
authwp_ajax_en_gtz_wd_bulk_delete_locationsincludes\warehouse-dropship\wild\includes\wild-delivery-save.php:47
noprivwp_ajax_engtz_cerasis_admin_order_quotesorders\create_order_from_admin.php:13
authwp_ajax_engtz_cerasis_admin_order_quotesorders\create_order_from_admin.php:14
authwp_ajax_eniture_calculate_shipping_rates_adminorders\rates\order-rates.php:13
authwp_ajax_engtz_cerasis_freight_activate_hit_to_update_planupdate-plan.php:10
noprivwp_ajax_engtz_cerasis_freight_activate_hit_to_update_planupdate-plan.php:11

REST API Routes 1

POST/wp-json/fdo-company-id/update-statusfdo\en-coupon-api.php:103
WordPress Hooks 81
filteren_gtz_ltl_accessorial_excludedapi-v2\en-response.php:124
actionrest_api_initfdo\en-coupon-api.php:17
actioninitincludes\en-globaltranz-admin-settings.php:28
actioninitincludes\en-globaltranz-admin-settings.php:29
actionadmin_enqueue_scriptsincludes\en-globaltranz-admin-settings.php:30
filterwoocommerce_package_ratesincludes\en-globaltranz-admin-settings.php:31
filterwoocommerce_no_shipping_available_htmlincludes\en-globaltranz-admin-settings.php:35
filterwoocommerce_cart_no_shipping_available_htmlincludes\en-globaltranz-admin-settings.php:36
filterwoocommerce_product_importer_parsed_dataincludes\en-globaltranz-admin-settings.php:365
filterengtz_triggeredincludes\en-globaltranz-cart-to-request.php:232
filteren_fdo_image_urls_mergeincludes\en-globaltranz-cart-to-request.php:294
actionadmin_noticesincludes\en-globaltranz-ltl.php:72
filterwoocommerce_get_settings_pagesincludes\en-globaltranz-ltl.php:74
actionadmin_initincludes\en-globaltranz-ltl.php:76
filterwoocommerce_settings_tabs_arrayincludes\en-globaltranz-settings-tabs-class.php:28
filterforce_show_methodsincludes\en-globaltranz-shipping-method.php:150
filterwoocommerce_package_ratesincludes\en-globaltranz-shipping-method.php:643
filterwoocommerce_package_ratesincludes\en-globaltranz-shipping-method.php:667
filterwoocommerce_package_ratesincludes\en-globaltranz-shipping-method.php:801
filterengtz_wd_update_query_stringincludes\standard-package-addon\instore-pickup-local-delivery\instore-local-delivery.php:17
filterengtz_wd_origin_array_setincludes\standard-package-addon\instore-pickup-local-delivery\instore-local-delivery.php:18
filterengtz_wd_standard_plansincludes\standard-package-addon\instore-pickup-local-delivery\instore-local-delivery.php:19
filtersuppress_local_deliveryincludes\standard-package-addon\instore-pickup-local-delivery\instore-local-delivery.php:20
filterwoocommerce_product_export_product_column_en_nicknameincludes\templates\csv-export.php:9
filterwoocommerce_product_export_product_column_en_cityincludes\templates\csv-export.php:10
filterwoocommerce_product_export_product_column_en_stateincludes\templates\csv-export.php:11
filterwoocommerce_product_export_product_column_en_zipincludes\templates\csv-export.php:12
filterwoocommerce_product_export_product_column_en_countryincludes\templates\csv-export.php:13
filterwoocommerce_product_export_product_column_en_product_freight_classincludes\templates\csv-export.php:16
filterwoocommerce_product_export_product_column_en_product_freight_class_variationincludes\templates\csv-export.php:17
filterwoocommerce_product_export_column_namesincludes\templates\csv-export.php:20
filterwoocommerce_product_export_product_default_columnsincludes\templates\csv-export.php:21
actionwoocommerce_product_options_shippingincludes\templates\en-globaltranz-products-nested-options.php:30
actionwoocommerce_process_product_metaincludes\templates\en-globaltranz-products-nested-options.php:33
actionwoocommerce_product_after_variable_attributesincludes\templates\en-globaltranz-products-nested-options.php:43
actionwoocommerce_save_product_variationincludes\templates\en-globaltranz-products-nested-options.php:47
actionwoocommerce_product_options_shippingincludes\templates\en-globaltranz-products-options.php:33
actionwoocommerce_process_product_metaincludes\templates\en-globaltranz-products-options.php:36
actionwoocommerce_product_after_variable_attributesincludes\templates\en-globaltranz-products-options.php:47
actionwoocommerce_save_product_variationincludes\templates\en-globaltranz-products-options.php:50
actionwoocommerce_product_options_shippingincludes\templates\en-globaltranz-products-stackable-option.php:30
actionwoocommerce_process_product_metaincludes\templates\en-globaltranz-products-stackable-option.php:33
actionwoocommerce_product_after_variable_attributesincludes\templates\en-globaltranz-products-stackable-option.php:43
actionwoocommerce_save_product_variationincludes\templates\en-globaltranz-products-stackable-option.php:46
filterengtz_wd_get_addressincludes\warehouse-dropship\get-distance-request.php:23
actionadmin_enqueue_scriptsincludes\warehouse-dropship\wild-delivery.php:31
actionbefore_woocommerce_initltl-freight-quotes-globaltranz-edition.php:27
filteren_pluginsltl-freight-quotes-globaltranz-edition.php:48
filterengtz_plans_notification_PDltl-freight-quotes-globaltranz-edition.php:73
filterengtz_plans_notification_message_actionltl-freight-quotes-globaltranz-edition.php:85
filterengtz_woo_plans_nested_notification_message_actionltl-freight-quotes-globaltranz-edition.php:97
actionadmin_initltl-freight-quotes-globaltranz-edition.php:123
filterplugin_action_linksltl-freight-quotes-globaltranz-edition.php:149
actionadmin_enqueue_scriptsltl-freight-quotes-globaltranz-edition.php:184
actionadmin_initltl-freight-quotes-globaltranz-edition.php:289
actionwoocommerce_shipping_initltl-freight-quotes-globaltranz-edition.php:290
filterwoocommerce_shipping_methodsltl-freight-quotes-globaltranz-edition.php:291
actionupgrader_process_completeltl-freight-quotes-globaltranz-edition.php:321
actionwp_enqueue_scriptsltl-freight-quotes-globaltranz-edition.php:352
filtercron_schedulesltl-freight-quotes-globaltranz-edition.php:369
actionengtz_add_every_weekly_cron_get_carriersltl-freight-quotes-globaltranz-edition.php:387
filterglobaltranz_quotes_plans_suscription_and_featuresltl-freight-quotes-globaltranz-edition.php:425
filterglobaltranz_plans_notification_linkltl-freight-quotes-globaltranz-edition.php:447
filteren_suppress_parcel_rates_hookltl-freight-quotes-globaltranz-edition.php:640
actionwoocommerce_thankyouorders\en-order-export.php:14
actioninitorders\en-order-export.php:15
actionen_async_orders_exporting_processorders\en-order-export.php:16
filtercron_schedulesorders\en-order-export.php:17
actionwoocommerce_order_actionsorders\en-order-widget.php:16
actionwoocommerce_order_actionsorders\ltl-order-widget-details.php:39
actionadmin_enqueue_scriptsorders\orders.php:18
filteren_order_accessoriesorders\rates\order-rates.php:14
filteren_app_common_plan_statusproduct\en-product-detail.php:23
filteren_compatible_optimized_product_optionsproduct\en-product-detail.php:26
actionwoocommerce_product_options_shippingproduct\en-product-detail.php:31
actionwoocommerce_process_product_metaproduct\en-product-detail.php:32
actionwoocommerce_product_after_variable_attributesproduct\en-product-detail.php:35
actionwoocommerce_save_product_variationproduct\en-product-detail.php:36
filterEn_Plugins_dropship_filterproduct\en-product-detail.php:39
filterEn_Plugins_variable_freight_classification_filterproduct\en-product-detail.php:40
actionadmin_noticesupdate-plan.php:278

Scheduled Events 2

engtz_add_every_weekly_cron_get_carriers
en_async_orders_exporting_process
Maintenance & Trust

LTL Freight Quotes – GlobalTranz Edition Maintenance & Trust

Maintenance Signals

WordPress version tested6.9.4
Last updatedJan 28, 2026
PHP min version
Downloads5K

Community Trust

Rating100/100
Number of ratings1
Active installs30
Developer Profile

LTL Freight Quotes – GlobalTranz Edition Developer Profile

enituretechnology

29 plugins · 1K total installs

93
trust score
Avg Security Score
98/100
Avg Patch Time
11 days
View full developer profile
Detection Fingerprints

How We Detect LTL Freight Quotes – GlobalTranz Edition

Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.

Asset Fingerprints

Asset Paths
/wp-content/plugins/ltl-freight-quotes-globaltranz-edition/assets/css/wickedpicker.min.css/wp-content/plugins/ltl-freight-quotes-globaltranz-edition/assets/js/wickedpicker.js/wp-content/plugins/ltl-freight-quotes-globaltranz-edition/assets/js/en-globaltranz-settings.js/wp-content/plugins/ltl-freight-quotes-globaltranz-edition/includes/templates/logs/en-json-tree-view/en-jtv-style.css/wp-content/plugins/ltl-freight-quotes-globaltranz-edition/includes/templates/logs/en-json-tree-view/en-jtv-script.js/wp-content/plugins/ltl-freight-quotes-globaltranz-edition/includes/templates/shipping-rules/assets/js/shipping_rules.js/wp-content/plugins/ltl-freight-quotes-globaltranz-edition/includes/templates/shipping-rules/assets/css/shipping_rules.css
Script Paths
/wp-content/plugins/ltl-freight-quotes-globaltranz-edition/assets/js/wickedpicker.js/wp-content/plugins/ltl-freight-quotes-globaltranz-edition/assets/js/en-globaltranz-settings.js/wp-content/plugins/ltl-freight-quotes-globaltranz-edition/includes/templates/logs/en-json-tree-view/en-jtv-script.js/wp-content/plugins/ltl-freight-quotes-globaltranz-edition/includes/templates/shipping-rules/assets/js/shipping_rules.js
Version Parameters
en-globaltranz-settings.js?ver=1.2.0wickedpicker.js?ver=1.0.0shipping_rules.js?ver=1.0.0shipping_rules.css?ver=1.0.0en-jtv-script.js?ver=1.0.0en-jtv-style.css?ver=1.0.0wickedpicker.min.css?ver=1.0.0

HTML / DOM Fingerprints

CSS Classes
en-jtv-containeren-jtv-nodeen-jtv-keyen-jtv-valueen-gtz-shipping-rules-section
Data Attributes
data-plugin-name="LTL Freight Quotes – GlobalTranz Edition"data-version="2.3.19"
JS Globals
scripten_globaltranz_admin_script
FAQ

Frequently Asked Questions about LTL Freight Quotes – GlobalTranz Edition