LTL Freight Quotes – Unishippers Edition Security & Risk Analysis

wordpress.org/plugins/ltl-freight-quotes-unishippers-edition

Real-time Unishippers freight quotes from Unishippers. Fifteen day free trial.

50 active installs v2.5.18 PHP + WP 6.4+ Updated Feb 10, 2026
enitureltl-freight-quotesltl-freight-ratesshipping-estimatesunishippers
97
A · Safe
CVEs total3
Unpatched0
Last CVEFeb 12, 2025
Safety Verdict

Is LTL Freight Quotes – Unishippers Edition Safe to Use in 2026?

Generally Safe

Score 97/100

LTL Freight Quotes – Unishippers Edition has a strong security track record. Known vulnerabilities have been patched promptly.

3 known CVEsLast CVE: Feb 12, 2025Updated 1mo ago
Risk Assessment

The "ltl-freight-quotes-unishippers-edition" plugin, version 2.5.18, exhibits a mixed security posture. While it demonstrates good practices in areas like SQL prepared statements (59%) and output escaping (83%), significant concerns arise from its attack surface. The presence of 35 AJAX handlers with 3 lacking authentication checks, and 1 REST API route without a permission callback, exposes potential entry points for unauthorized actions. The taint analysis reveals a high-severity flow with unsanitized input, which, combined with the missing authorization checks, presents a tangible risk of exploitation.

The vulnerability history of this plugin is also a cause for concern. With 3 known CVEs, including a high-severity SQL Injection and Cross-site Scripting, the pattern suggests recurring security weaknesses. Although there are currently no unpatched CVEs, the historical prevalence of critical and high-severity issues, coupled with the recent vulnerability in February 2025, indicates a need for continued vigilance and prompt patching when new vulnerabilities are discovered. The plugin's strengths lie in its generally good handling of SQL queries and output, but the identified unauthenticated entry points and past vulnerability trends necessitate careful consideration of its security implications.

Key Concerns

  • AJAX handlers without auth checks
  • REST API route without permission callback
  • High severity taint flow
  • High severity CVE in history
  • Medium severity CVEs in history (x2)
  • SQL queries not using prepared statements (41%)
  • Output not properly escaped (17%)
Vulnerabilities
3

LTL Freight Quotes – Unishippers Edition Security Vulnerabilities

CVEs by Year

3 CVEs in 2025
2025
Patched Has unpatched

Severity Breakdown

High
1
Medium
2

3 total CVEs

CVE-2025-22284medium · 6.1Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')

LTL Freight Quotes – Unishippers Edition <= 2.5.8 - Reflected Cross-Site Scripting

Feb 12, 2025 Patched in 2.5.9 (7d)
CVE-2025-22289medium · 5.3Missing Authorization

LTL Freight Quotes – Unishippers Edition <= 2.5.8 - Missing Authorization

Feb 12, 2025 Patched in 2.5.9 (7d)
CVE-2024-13477high · 7.5Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')

LTL Freight Quotes – Unishippers Edition <= 2.5.8 - Unauthenticated SQL Injection

Feb 11, 2025 Patched in 2.5.9 (1d)
Code Analysis
Analyzed Mar 16, 2026

LTL Freight Quotes – Unishippers Edition Code Analysis

Dangerous Functions
0
Raw SQL Queries
33
47 prepared
Unescaped Output
54
265 escaped
Nonce Checks
15
Capability Checks
17
File Operations
0
External Requests
9
Bundled Libraries
0

SQL Query Safety

59% prepared80 total queries

Output Escaping

83% escaped319 total outputs
Data Flows
3 unsanitized

Data Flow Analysis

15 flows3 with unsanitized paths
<en-coupon-api> (fdo\en-coupon-api.php:0)
Source (user input) Sink (dangerous op) Sanitizer Transform Unsanitized Sanitized
Attack Surface
4 unprotected

LTL Freight Quotes – Unishippers Edition Attack Surface

Entry Points36
Unprotected4

AJAX Handlers 35

authwp_ajax_en_unishippers_ltl_fdo_connection_status_refreshfdo\en-coupon-api.php:9
noprivwp_ajax_en_unishippers_ltl_fdo_connection_status_refreshfdo\en-coupon-api.php:10
authwp_ajax_en_unishippers_ltl_va_connection_status_refreshfdo\en-coupon-api.php:12
noprivwp_ajax_en_unishippers_ltl_va_connection_status_refreshfdo\en-coupon-api.php:13
noprivwp_ajax_unishippers_fdfdo\en-coupon-api.php:15
authwp_ajax_unishippers_fdfdo\en-coupon-api.php:16
authwp_ajax_eniture_calculate_shipping_rates_adminorder\rates\order-rates.php:17
noprivwp_ajax_en_unishippers_ltl_save_shipping_ruleshipping-rules\shipping-rules-save.php:21
authwp_ajax_en_unishippers_ltl_save_shipping_ruleshipping-rules\shipping-rules-save.php:22
noprivwp_ajax_en_unishippers_ltl_edit_shipping_ruleshipping-rules\shipping-rules-save.php:24
authwp_ajax_en_unishippers_ltl_edit_shipping_ruleshipping-rules\shipping-rules-save.php:25
noprivwp_ajax_en_unishippers_ltl_delete_shipping_ruleshipping-rules\shipping-rules-save.php:27
authwp_ajax_en_unishippers_ltl_delete_shipping_ruleshipping-rules\shipping-rules-save.php:28
noprivwp_ajax_en_unishippers_ltl_update_shipping_rule_statusshipping-rules\shipping-rules-save.php:30
authwp_ajax_en_unishippers_ltl_update_shipping_rule_statusshipping-rules\shipping-rules-save.php:31
noprivwp_ajax_unishippers_ltl_validate_keysunishippers-ltl-test-connecion.php:80
authwp_ajax_unishippers_ltl_validate_keysunishippers-ltl-test-connecion.php:81
authwp_ajax_en_unishippers_freight_activate_hit_to_update_planupdate-plan.php:10
noprivwp_ajax_en_unishippers_freight_activate_hit_to_update_planupdate-plan.php:11
noprivwp_ajax_en_wd_get_addresswarehouse-dropship\wild\includes\wild-delivery-save.php:24
authwp_ajax_en_wd_get_addresswarehouse-dropship\wild\includes\wild-delivery-save.php:25
noprivwp_ajax_en_uni_ltl_wd_save_warehousewarehouse-dropship\wild\includes\wild-delivery-save.php:28
authwp_ajax_en_uni_ltl_wd_save_warehousewarehouse-dropship\wild\includes\wild-delivery-save.php:29
noprivwp_ajax_en_uni_ltl_wd_edit_warehousewarehouse-dropship\wild\includes\wild-delivery-save.php:31
authwp_ajax_en_uni_ltl_wd_edit_warehousewarehouse-dropship\wild\includes\wild-delivery-save.php:32
noprivwp_ajax_en_uni_ltl_wd_delete_warehousewarehouse-dropship\wild\includes\wild-delivery-save.php:34
authwp_ajax_en_uni_ltl_wd_delete_warehousewarehouse-dropship\wild\includes\wild-delivery-save.php:35
noprivwp_ajax_en_uni_ltl_wd_save_dropshipwarehouse-dropship\wild\includes\wild-delivery-save.php:38
authwp_ajax_en_uni_ltl_wd_save_dropshipwarehouse-dropship\wild\includes\wild-delivery-save.php:39
noprivwp_ajax_en_uni_ltl_wd_edit_dropshipwarehouse-dropship\wild\includes\wild-delivery-save.php:41
authwp_ajax_en_uni_ltl_wd_edit_dropshipwarehouse-dropship\wild\includes\wild-delivery-save.php:42
noprivwp_ajax_en_uni_ltl_wd_delete_dropshipwarehouse-dropship\wild\includes\wild-delivery-save.php:44
authwp_ajax_en_uni_ltl_wd_delete_dropshipwarehouse-dropship\wild\includes\wild-delivery-save.php:45
noprivwp_ajax_en_uni_ltl_wd_bulk_delete_locationswarehouse-dropship\wild\includes\wild-delivery-save.php:47
authwp_ajax_en_uni_ltl_wd_bulk_delete_locationswarehouse-dropship\wild\includes\wild-delivery-save.php:48

REST API Routes 1

POST/wp-json/fdo-company-id/update-statusfdo\en-coupon-api.php:95
WordPress Hooks 62
actionrest_api_initfdo\en-coupon-api.php:17
actionbefore_woocommerce_initltl-freight-quotes-unishippers-edition.php:24
filteren_pluginsltl-freight-quotes-unishippers-edition.php:38
filteren_woo_plans_notification_actionltl-freight-quotes-unishippers-edition.php:68
filteren_woo_plans_notification_message_actionltl-freight-quotes-unishippers-edition.php:80
filteren_woo_plans_nested_notification_message_actionltl-freight-quotes-unishippers-edition.php:93
actionadmin_enqueue_scriptsltl-freight-quotes-unishippers-edition.php:154
filterplugin_action_linksltl-freight-quotes-unishippers-edition.php:187
actionadmin_enqueue_scriptsltl-freight-quotes-unishippers-edition.php:190
actionadmin_initltl-freight-quotes-unishippers-edition.php:216
actionadmin_noticesltl-freight-quotes-unishippers-edition.php:285
filterwoocommerce_get_settings_pagesltl-freight-quotes-unishippers-edition.php:287
actionwoocommerce_shipping_initltl-freight-quotes-unishippers-edition.php:290
filterwoocommerce_shipping_methodsltl-freight-quotes-unishippers-edition.php:291
filterwoocommerce_package_ratesltl-freight-quotes-unishippers-edition.php:292
actioninitltl-freight-quotes-unishippers-edition.php:293
actioninitltl-freight-quotes-unishippers-edition.php:335
actionwp_enqueue_scriptsltl-freight-quotes-unishippers-edition.php:357
filtereniture_unishippers_freight_quotes_plans_suscription_and_featuresltl-freight-quotes-unishippers-edition.php:380
filtereniture_unishippers_freight_plans_notification_linkltl-freight-quotes-unishippers-edition.php:402
filteren_suppress_parcel_rates_hookltl-freight-quotes-unishippers-edition.php:528
actionwoocommerce_thankyouorder\en-order-export.php:17
actioninitorder\en-order-export.php:18
actionen_async_orders_exporting_processorder\en-order-export.php:19
filtercron_schedulesorder\en-order-export.php:20
actionwoocommerce_order_actionsorder\en-order-widget.php:22
filteren_order_accessoriesorder\rates\order-rates.php:18
filteren_app_common_plan_statusproduct\en-product-detail.php:27
filteren_compatible_optimized_product_optionsproduct\en-product-detail.php:30
actionwoocommerce_product_options_shippingproduct\en-product-detail.php:36
actionwoocommerce_process_product_metaproduct\en-product-detail.php:37
actionwoocommerce_product_after_variable_attributesproduct\en-product-detail.php:40
actionwoocommerce_save_product_variationproduct\en-product-detail.php:41
filterEn_Plugins_dropship_filterproduct\en-product-detail.php:44
filterEn_Plugins_variable_freight_classification_filterproduct\en-product-detail.php:45
filteren_wd_update_query_stringstandard-package-addon\instore-pickup-local-delivery\instore-local-delivery.php:17
filteren_wd_origin_array_setstandard-package-addon\instore-pickup-local-delivery\instore-local-delivery.php:18
filteren_wd_standard_plansstandard-package-addon\instore-pickup-local-delivery\instore-local-delivery.php:19
filtersuppress_local_deliverystandard-package-addon\instore-pickup-local-delivery\instore-local-delivery.php:20
filterwoocommerce_product_export_product_column_en_nicknametemplate\csv-export.php:12
filterwoocommerce_product_export_product_column_en_citytemplate\csv-export.php:13
filterwoocommerce_product_export_product_column_en_statetemplate\csv-export.php:14
filterwoocommerce_product_export_product_column_en_ziptemplate\csv-export.php:15
filterwoocommerce_product_export_product_column_en_countrytemplate\csv-export.php:16
filterwoocommerce_product_export_product_column_en_product_freight_classtemplate\csv-export.php:19
filterwoocommerce_product_export_product_column_en_product_freight_class_variationtemplate\csv-export.php:20
filterwoocommerce_product_export_column_namestemplate\csv-export.php:23
filterwoocommerce_product_export_product_default_columnstemplate\csv-export.php:24
actionwoocommerce_product_options_shippingtemplate\products-nested-options.php:33
actionwoocommerce_process_product_metatemplate\products-nested-options.php:36
actionwoocommerce_product_after_variable_attributestemplate\products-nested-options.php:47
actionwoocommerce_save_product_variationtemplate\products-nested-options.php:51
filterwoocommerce_product_importer_parsed_dataunishipper-ltl-admin-filter.php:248
filteren_unishippers_ltl_accessorial_excludedunishippers-ltl-carrier-service.php:553
filteren_fdo_image_urls_mergeunishippers-ltl-grouping.php:368
filterforce_show_methodsunishippers-ltl-shipping-class.php:197
filterwoocommerce_package_ratesunishippers-ltl-shipping-class.php:507
filterwoocommerce_package_ratesunishippers-ltl-shipping-class.php:530
filterwoocommerce_package_ratesunishippers-ltl-shipping-class.php:717
filterwoocommerce_settings_tabs_arrayunishippers-ltl-tab-class.php:26
actionadmin_noticesupdate-plan.php:274
actionadmin_enqueue_scriptswarehouse-dropship\wild-delivery.php:30

Scheduled Events 1

en_async_orders_exporting_process
Maintenance & Trust

LTL Freight Quotes – Unishippers Edition Maintenance & Trust

Maintenance Signals

WordPress version tested6.9.4
Last updatedFeb 10, 2026
PHP min version
Downloads5K

Community Trust

Rating0/100
Number of ratings0
Active installs50
Developer Profile

LTL Freight Quotes – Unishippers Edition Developer Profile

enituretechnology

29 plugins · 1K total installs

93
trust score
Avg Security Score
98/100
Avg Patch Time
11 days
View full developer profile
Detection Fingerprints

How We Detect LTL Freight Quotes – Unishippers Edition

Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.

Asset Fingerprints

Asset Paths
/wp-content/plugins/ltl-freight-quotes-unishippers-edition/css/wickedpicker.min.css/wp-content/plugins/ltl-freight-quotes-unishippers-edition/js/wickedpicker.js/wp-content/plugins/ltl-freight-quotes-unishippers-edition/css/unishippers_ltl_style.css/wp-content/plugins/ltl-freight-quotes-unishippers-edition/js/eniture-calculate-shipping-admin.js/wp-content/plugins/ltl-freight-quotes-unishippers-edition/logs/en-json-tree-view/en-jtv-style.css/wp-content/plugins/ltl-freight-quotes-unishippers-edition/logs/en-json-tree-view/en-jtv-script.js
Script Paths
js/wickedpicker.jsjs/eniture-calculate-shipping-admin.jslogs/en-json-tree-view/en-jtv-script.js
Version Parameters
ltl-freight-quotes-unishippers-edition/css/wickedpicker.min.css?ver=ltl-freight-quotes-unishippers-edition/js/wickedpicker.js?ver=ltl-freight-quotes-unishippers-edition/css/unishippers_ltl_style.css?ver=ltl-freight-quotes-unishippers-edition/js/eniture-calculate-shipping-admin.js?ver=ltl-freight-quotes-unishippers-edition/logs/en-json-tree-view/en-jtv-style.css?ver=ltl-freight-quotes-unishippers-edition/logs/en-json-tree-view/en-jtv-script.js?ver=

HTML / DOM Fingerprints

CSS Classes
en_jtv_container
Data Attributes
data-eniture-plugin-name
JS Globals
eniture_unishippers_freight_domain_hitting_urlunishippers_freight_domain_hitting_urlunishippers_freight_new_api_domain_hitting_urlunishippers_freight_fdo_hitting_urlunishippers_freight_fdo_coupon_base_urlunishippers_freight_va_coupon_base_url+5 more
FAQ

Frequently Asked Questions about LTL Freight Quotes – Unishippers Edition