LTL Freight Quotes – TQL Edition Security & Risk Analysis

wordpress.org/plugins/ltl-freight-quotes-tql-edition

Real-time LTL freight quotes from Tql. Fifteen day free trial.

0 active installs v1.2.11 PHP + WP 6.4+ Updated Feb 20, 2026
enitureltl-freight-quotesltl-freight-ratesshipping-estimatestql
99
A · Safe
CVEs total1
Unpatched0
Last CVESep 3, 2025
Safety Verdict

Is LTL Freight Quotes – TQL Edition Safe to Use in 2026?

Generally Safe

Score 99/100

LTL Freight Quotes – TQL Edition has a strong security track record. Known vulnerabilities have been patched promptly.

1 known CVELast CVE: Sep 3, 2025Updated 1mo ago
Risk Assessment

The "ltl-freight-quotes-tql-edition" v1.2.11 plugin exhibits a mixed security posture. While it demonstrates some good practices, such as a moderate use of prepared statements for SQL queries and a good number of capability checks, there are significant areas of concern. The presence of unprotected AJAX handlers and REST API routes creates direct entry points for potential attackers. The taint analysis revealing unsanitized paths, particularly one with high severity, is a critical finding that could lead to various exploitation vectors if data is not properly handled. Furthermore, the plugin's vulnerability history, although currently showing no unpatched vulnerabilities, includes a past medium-severity "Deserialization of Untrusted Data" vulnerability. This suggests a recurring pattern of potential weaknesses in data handling, which, when combined with the identified unsanitized taint flows, warrants careful attention. Overall, while the plugin has strengths, the unprotected entry points and critical taint flow present notable risks that require remediation.

Key Concerns

  • Unprotected AJAX handlers
  • Unprotected REST API routes
  • Taint flow with high severity
  • Taint flows with unsanitized paths
  • SQL queries not using prepared statements
  • Output not properly escaped
Vulnerabilities
1

LTL Freight Quotes – TQL Edition Security Vulnerabilities

CVEs by Year

1 CVE in 2025
2025
Patched Has unpatched

Severity Breakdown

Medium
1

1 total CVE

CVE-2025-58644medium · 6.6Deserialization of Untrusted Data

LTL Freight Quotes - TQL Edition <= 1.2.6 - Authenticated (Administrator+) PHP Object Injection

Sep 3, 2025 Patched in 1.2.7 (9d)
Code Analysis
Analyzed Mar 17, 2026

LTL Freight Quotes – TQL Edition Code Analysis

Dangerous Functions
0
Raw SQL Queries
10
12 prepared
Unescaped Output
64
104 escaped
Nonce Checks
6
Capability Checks
14
File Operations
0
External Requests
2
Bundled Libraries
0

SQL Query Safety

55% prepared22 total queries

Output Escaping

62% escaped168 total outputs
Data Flows
5 unsanitized

Data Flow Analysis

6 flows5 with unsanitized paths
en_save_carriers (admin\tab\carriers\en-carriers.php:53)
Source (user input) Sink (dangerous op) Sanitizer Transform Unsanitized Sanitized
Attack Surface
3 unprotected

LTL Freight Quotes – TQL Edition Attack Surface

Entry Points12
Unprotected3

AJAX Handlers 11

noprivwp_ajax_en_tql_admin_order_quotesadmin\order\en-order-rates.php:25
authwp_ajax_en_tql_admin_order_quotesadmin\order\en-order-rates.php:26
noprivwp_ajax_en_tql_test_connectionadmin\tab\connection-settings\en-connection-ajax.php:24
authwp_ajax_en_tql_test_connectionadmin\tab\connection-settings\en-connection-ajax.php:25
authwp_ajax_en_tql_location_save_form_dataadmin\tab\location\includes\en-location-ajax.php:17
authwp_ajax_en_tql_get_locationadmin\tab\location\includes\en-location-ajax.php:18
authwp_ajax_en_tql_location_delete_rowadmin\tab\location\includes\en-location-ajax.php:19
authwp_ajax_en_tql_wd_bulk_delete_locationsadmin\tab\location\includes\en-location-ajax.php:20
authwp_ajax_en_tql_get_current_plancommon\en-plans.php:29
noprivwp_ajax_tql_fden-install.php:568
authwp_ajax_tql_fden-install.php:569

REST API Routes 1

POST/wp-json/fdo-company-id/update-statusen-install.php:616
WordPress Hooks 55
actionadmin_print_scriptsadmin\order\en-order-script.php:22
actionwoocommerce_order_actionsadmin\order\en-order-widget.php:25
actionwoocommerce_product_options_shippingadmin\product\en-product-detail.php:36
actionwoocommerce_process_product_metaadmin\product\en-product-detail.php:37
actionwoocommerce_product_after_variable_attributesadmin\product\en-product-detail.php:40
actionwoocommerce_save_product_variationadmin\product\en-product-detail.php:41
filterEn_Plugins_dropship_filteradmin\product\en-product-detail.php:44
filterEn_Plugins_variable_freight_classification_filteradmin\product\en-product-detail.php:45
filteren_tql_reason_quotes_not_returnedadmin\tab\connection-settings\en-connection-settings.php:75
filterwoocommerce_settings_tabs_arrayadmin\tab\en-tab.php:22
filterwoocommerce_product_export_product_column_en_nicknamecommon\en-csv.php:11
filterwoocommerce_product_export_product_column_en_citycommon\en-csv.php:12
filterwoocommerce_product_export_product_column_en_statecommon\en-csv.php:13
filterwoocommerce_product_export_product_column_en_zipcommon\en-csv.php:14
filterwoocommerce_product_export_product_column_en_countrycommon\en-csv.php:15
filterwoocommerce_product_export_product_column_en_product_freight_classcommon\en-csv.php:18
filterwoocommerce_product_export_product_column_en_product_freight_class_variationcommon\en-csv.php:19
filterwoocommerce_product_export_column_namescommon\en-csv.php:22
filterwoocommerce_product_export_product_default_columnscommon\en-csv.php:23
actionadmin_noticescommon\en-guard.php:42
actionwoocommerce_loadedcommon\en-guard.php:111
filteren_register_activation_hookcommon\en-plans.php:24
filtertql_plans_notification_linkcommon\en-plans.php:26
filtertql_plans_suscription_and_featurescommon\en-plans.php:27
filteren_register_activation_hookdb\en-warehouse.php:25
actioniniten-install.php:30
actionadmin_enqueue_scriptsen-install.php:89
actionwp_enqueue_scriptsen-install.php:104
filterwoocommerce_get_settings_pagesen-install.php:123
filterplugin_action_linksen-install.php:150
actionadmin_print_scriptsen-install.php:167
filterwoocommerce_shipping_methodsen-install.php:207
filterwoocommerce_cart_no_shipping_available_htmlen-install.php:222
filteren_app_common_plan_statusen-install.php:248
filterwoocommerce_package_ratesen-install.php:319
filteren_shipping_applicationsen-install.php:333
filteradmin_noticesen-install.php:352
actionwoocommerce_proceed_to_checkouten-install.php:375
filterwoocommerce_cart_no_shipping_available_htmlen-install.php:388
filterwoocommerce_product_importer_parsed_dataen-install.php:484
filteren_pluginsen-install.php:548
actionrest_api_initen-install.php:613
actionbefore_woocommerce_initltl-freight-quotes-tql-edition.php:21
actionadmin_initltl-freight-quotes-tql-edition.php:44
filteren_suppress_parcel_rates_hookltl-freight-quotes-tql-edition.php:47
filteren_register_activation_hookserver\common\en-create-ltl-class.php:24
actionwoocommerce_thankyouserver\common\en-order-export.php:22
actioninitserver\common\en-order-export.php:23
actionen_async_orders_exporting_processserver\common\en-order-export.php:24
filtercron_schedulesserver\common\en-order-export.php:25
actionwoocommerce_shipping_initserver\en-shipping-rates.php:19
filteren_package_converterserver\en-shipping-rates.php:107
filteren_eniture_shipmentserver\en-shipping-rates.php:141
filteren_tql_reason_quotes_not_returnedserver\package\en-package.php:262
filteren_fdo_image_urls_mergeserver\package\en-package.php:311

Scheduled Events 1

en_async_orders_exporting_process
Maintenance & Trust

LTL Freight Quotes – TQL Edition Maintenance & Trust

Maintenance Signals

WordPress version tested6.9.4
Last updatedFeb 20, 2026
PHP min version
Downloads2K

Community Trust

Rating0/100
Number of ratings0
Active installs0
Developer Profile

LTL Freight Quotes – TQL Edition Developer Profile

enituretechnology

29 plugins · 1K total installs

93
trust score
Avg Security Score
98/100
Avg Patch Time
11 days
View full developer profile
Detection Fingerprints

How We Detect LTL Freight Quotes – TQL Edition

Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.

Asset Fingerprints

Asset Paths
/wp-content/plugins/ltl-freight-quotes-tql-edition/admin/tab/logs/en-json-tree-view/en-jtv-style.css/wp-content/plugins/ltl-freight-quotes-tql-edition/admin/tab/logs/en-json-tree-view/en-jtv-script.js/wp-content/plugins/ltl-freight-quotes-tql-edition/admin/tab/location/assets/js/en-tql-tagging.js/wp-content/plugins/ltl-freight-quotes-tql-edition/admin/assets/en-tql-admin.js/wp-content/plugins/ltl-freight-quotes-tql-edition/admin/tab/location/assets/js/en-tql-location.js/wp-content/plugins/ltl-freight-quotes-tql-edition/admin/tab/location/assets/css/en-tql-location.css/wp-content/plugins/ltl-freight-quotes-tql-edition/admin/assets/en-tql-admin.css/wp-content/plugins/ltl-freight-quotes-tql-edition/admin/assets/wickedpicker.min.css+2 more
Script Paths
admin/tab/logs/en-json-tree-view/en-jtv-script.jsadmin/tab/location/assets/js/en-tql-tagging.jsadmin/assets/en-tql-admin.jsadmin/tab/location/assets/js/en-tql-location.jsadmin/assets/wickedpicker.jsadmin/assets/en-tql-frontend.js

HTML / DOM Fingerprints

CSS Classes
en-tql-admin-cssen-tql-location-css
JS Globals
scripten_tql_admin_script
FAQ

Frequently Asked Questions about LTL Freight Quotes – TQL Edition