LTL Freight Quotes – TForce Edition Security & Risk Analysis

wordpress.org/plugins/ltl-freight-quotes-ups-edition

Real-time LTL freight quotes from UPS. Fifteen day free trial.

10 active installs v3.6.9 PHP + WP 6.5+ Updated Feb 5, 2026
enitureltl-freight-quotesltl-freight-ratesshipping-estimatestforce
98
A · Safe
CVEs total1
Unpatched0
Last CVEFeb 18, 2025
Safety Verdict

Is LTL Freight Quotes – TForce Edition Safe to Use in 2026?

Generally Safe

Score 98/100

LTL Freight Quotes – TForce Edition has a strong security track record. Known vulnerabilities have been patched promptly.

1 known CVELast CVE: Feb 18, 2025Updated 1mo ago
Risk Assessment

The "ltl-freight-quotes-ups-edition" plugin v3.6.9 exhibits a mixed security posture. While it demonstrates good practices like a relatively low number of dangerous functions and a moderate percentage of SQL queries using prepared statements, significant concerns arise from its attack surface and output escaping practices. The presence of a REST API route without permission callbacks is a direct, unprotected entry point, posing an immediate risk. Furthermore, over half of the output operations are not properly escaped, increasing the likelihood of Cross-Site Scripting (XSS) vulnerabilities. The taint analysis reveals one high-severity flow, which, combined with the general output escaping issues, suggests potential for data manipulation or unauthorized access. The plugin's vulnerability history, with a past high-severity SQL injection vulnerability, indicates a pattern of security weaknesses that require ongoing vigilance and prompt patching. Although there are no currently unpatched CVEs, the historical context and current code signals warrant a cautious approach to its deployment.

Key Concerns

  • REST API route without permission callbacks
  • High severity taint flow
  • Output escaping: 53% properly escaped
  • SQL queries: 45% using prepared statements
  • History of high severity SQL Injection
Vulnerabilities
1

LTL Freight Quotes – TForce Edition Security Vulnerabilities

CVEs by Year

1 CVE in 2025
2025
Patched Has unpatched

Severity Breakdown

High
1

1 total CVE

CVE-2024-13478high · 7.5Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')

LTL Freight Quotes – TForce Edition <= 3.6.4 - Unauthenticated SQL Injection

Feb 18, 2025 Patched in 3.6.5 (1d)
Code Analysis
Analyzed Mar 16, 2026

LTL Freight Quotes – TForce Edition Code Analysis

Dangerous Functions
0
Raw SQL Queries
21
17 prepared
Unescaped Output
95
106 escaped
Nonce Checks
9
Capability Checks
12
File Operations
0
External Requests
4
Bundled Libraries
0

SQL Query Safety

45% prepared38 total queries

Output Escaping

53% escaped201 total outputs
Data Flows
10 unsanitized

Data Flow Analysis

15 flows10 with unsanitized paths
warehouse_template (warehouse-dropship\wild-delivery.php:42)
Source (user input) Sink (dangerous op) Sanitizer Transform Unsanitized Sanitized
Attack Surface
1 unprotected

LTL Freight Quotes – TForce Edition Attack Surface

Entry Points23
Unprotected1

AJAX Handlers 22

noprivwp_ajax_ups_fdltl-freight-quotes-ups-edition.php:531
authwp_ajax_ups_fdltl-freight-quotes-ups-edition.php:532
authwp_ajax_en_ups_freight_activate_hit_to_update_planupdate-plan.php:11
noprivwp_ajax_en_ups_freight_activate_hit_to_update_planupdate-plan.php:12
noprivwp_ajax_ups_freight_test_connectionups-freight-test-connection.php:13
authwp_ajax_ups_freight_test_connectionups-freight-test-connection.php:14
noprivwp_ajax_en_wd_get_addresswarehouse-dropship\wild\includes\wild-delivery-save.php:24
authwp_ajax_en_wd_get_addresswarehouse-dropship\wild\includes\wild-delivery-save.php:25
noprivwp_ajax_en_ups_ltl_wd_save_warehousewarehouse-dropship\wild\includes\wild-delivery-save.php:28
authwp_ajax_en_ups_ltl_wd_save_warehousewarehouse-dropship\wild\includes\wild-delivery-save.php:29
noprivwp_ajax_en_ups_ltl_wd_delete_warehousewarehouse-dropship\wild\includes\wild-delivery-save.php:31
authwp_ajax_en_ups_ltl_wd_delete_warehousewarehouse-dropship\wild\includes\wild-delivery-save.php:32
noprivwp_ajax_en_ups_ltl_wd_edit_warehousewarehouse-dropship\wild\includes\wild-delivery-save.php:34
authwp_ajax_en_ups_ltl_wd_edit_warehousewarehouse-dropship\wild\includes\wild-delivery-save.php:35
noprivwp_ajax_en_ups_ltl_wd_save_dropshipwarehouse-dropship\wild\includes\wild-delivery-save.php:38
authwp_ajax_en_ups_ltl_wd_save_dropshipwarehouse-dropship\wild\includes\wild-delivery-save.php:39
noprivwp_ajax_en_ups_ltl_wd_edit_dropshipwarehouse-dropship\wild\includes\wild-delivery-save.php:41
authwp_ajax_en_ups_ltl_wd_edit_dropshipwarehouse-dropship\wild\includes\wild-delivery-save.php:42
noprivwp_ajax_en_ups_ltl_wd_delete_dropshipwarehouse-dropship\wild\includes\wild-delivery-save.php:44
authwp_ajax_en_ups_ltl_wd_delete_dropshipwarehouse-dropship\wild\includes\wild-delivery-save.php:45
noprivwp_ajax_en_ups_ltl_wd_bulk_delete_locationswarehouse-dropship\wild\includes\wild-delivery-save.php:47
authwp_ajax_en_ups_ltl_wd_bulk_delete_locationswarehouse-dropship\wild\includes\wild-delivery-save.php:48

REST API Routes 1

POST/wp-json/fdo-company-id/update-statusltl-freight-quotes-ups-edition.php:579
WordPress Hooks 68
actionbefore_woocommerce_initltl-freight-quotes-ups-edition.php:25
filteren_pluginsltl-freight-quotes-ups-edition.php:38
filteren_woo_plans_notification_actionltl-freight-quotes-ups-edition.php:64
filteren_woo_plans_notification_message_actionltl-freight-quotes-ups-edition.php:76
filteren_woo_plans_nested_notification_message_actionltl-freight-quotes-ups-edition.php:89
filtervalid_for_quotesltl-freight-quotes-ups-edition.php:98
actionadmin_noticesltl-freight-quotes-ups-edition.php:109
actionadmin_initltl-freight-quotes-ups-edition.php:125
actionadmin_noticesltl-freight-quotes-ups-edition.php:137
actionadmin_enqueue_scriptsltl-freight-quotes-ups-edition.php:201
actionadmin_initltl-freight-quotes-ups-edition.php:219
actionadmin_enqueue_scriptsltl-freight-quotes-ups-edition.php:222
actionadmin_initltl-freight-quotes-ups-edition.php:274
actionupgrader_process_completeltl-freight-quotes-ups-edition.php:321
actionwoocommerce_shipping_initltl-freight-quotes-ups-edition.php:326
filterwoocommerce_shipping_methodsltl-freight-quotes-ups-edition.php:327
filterwoocommerce_get_settings_pagesltl-freight-quotes-ups-edition.php:328
filterwoocommerce_package_ratesltl-freight-quotes-ups-edition.php:329
actioninitltl-freight-quotes-ups-edition.php:330
filterplugin_action_linksltl-freight-quotes-ups-edition.php:334
actionwp_enqueue_scriptsltl-freight-quotes-ups-edition.php:365
filterups_freight_quotes_quotes_plans_suscription_and_featuresltl-freight-quotes-ups-edition.php:440
filterups_freight_quotes_plans_notification_linkltl-freight-quotes-ups-edition.php:461
filteren_weight_of_handling_unitltl-freight-quotes-ups-edition.php:528
actionrest_api_initltl-freight-quotes-ups-edition.php:576
filteren_suppress_parcel_rates_hookltl-freight-quotes-ups-edition.php:640
actionwoocommerce_thankyouorder\en-order-export.php:14
actioninitorder\en-order-export.php:15
actionen_async_orders_exporting_processorder\en-order-export.php:16
filtercron_schedulesorder\en-order-export.php:17
actionwoocommerce_order_actionsorder\en-order-widget.php:16
actionwoocommerce_order_before_calculate_totalsorder\rates\order-rates.php:13
filteren_order_accessoriesorder\rates\order-rates.php:14
filteren_app_common_plan_statusproduct\en-product-detail.php:24
filteren_compatible_optimized_product_optionsproduct\en-product-detail.php:27
actionwoocommerce_product_options_shippingproduct\en-product-detail.php:33
actionwoocommerce_process_product_metaproduct\en-product-detail.php:34
actionwoocommerce_product_after_variable_attributesproduct\en-product-detail.php:37
actionwoocommerce_save_product_variationproduct\en-product-detail.php:38
filterEn_Plugins_dropship_filterproduct\en-product-detail.php:41
filterEn_Plugins_variable_freight_classification_filterproduct\en-product-detail.php:42
filteren_ups_freight_wd_update_query_stringstandard-package-addon\instore-pickup-local-delivery\instore-local-delivery.php:17
filteren_ups_freight_wd_origin_array_setstandard-package-addon\instore-pickup-local-delivery\instore-local-delivery.php:18
filteren_ups_freight_wd_standard_plansstandard-package-addon\instore-pickup-local-delivery\instore-local-delivery.php:19
filtersuppress_local_deliverystandard-package-addon\instore-pickup-local-delivery\instore-local-delivery.php:20
filterwoocommerce_product_export_product_column_en_nicknametemplate\csv-export.php:9
filterwoocommerce_product_export_product_column_en_citytemplate\csv-export.php:10
filterwoocommerce_product_export_product_column_en_statetemplate\csv-export.php:11
filterwoocommerce_product_export_product_column_en_ziptemplate\csv-export.php:12
filterwoocommerce_product_export_product_column_en_countrytemplate\csv-export.php:13
filterwoocommerce_product_export_product_column_en_product_freight_classtemplate\csv-export.php:16
filterwoocommerce_product_export_product_column_en_product_freight_class_variationtemplate\csv-export.php:17
filterwoocommerce_product_export_column_namestemplate\csv-export.php:20
filterwoocommerce_product_export_product_default_columnstemplate\csv-export.php:21
actionwoocommerce_product_options_shippingtemplate\products-nested-options.php:32
actionwoocommerce_process_product_metatemplate\products-nested-options.php:35
actionwoocommerce_product_after_variable_attributestemplate\products-nested-options.php:45
actionwoocommerce_save_product_variationtemplate\products-nested-options.php:49
actionadmin_noticesupdate-plan.php:259
filterwoocommerce_product_importer_parsed_dataups-freight-admin-filter.php:203
filteren_fdo_image_urls_mergeups-freight-group-package.php:345
filterforce_show_methodsups-freight-shipping-class.php:164
filterwoocommerce_package_ratesups-freight-shipping-class.php:634
filterwoocommerce_package_ratesups-freight-shipping-class.php:745
filterwoocommerce_package_ratesups-freight-shipping-class.php:832
filterwoocommerce_settings_tabs_arrayups-freight-tab-class.php:23
filteren_wd_get_addresswarehouse-dropship\get-distance-request.php:21
actionadmin_enqueue_scriptswarehouse-dropship\wild-delivery.php:34

Scheduled Events 1

en_async_orders_exporting_process
Maintenance & Trust

LTL Freight Quotes – TForce Edition Maintenance & Trust

Maintenance Signals

WordPress version tested6.9.4
Last updatedFeb 5, 2026
PHP min version
Downloads6K

Community Trust

Rating100/100
Number of ratings1
Active installs10
Developer Profile

LTL Freight Quotes – TForce Edition Developer Profile

enituretechnology

29 plugins · 1K total installs

93
trust score
Avg Security Score
98/100
Avg Patch Time
11 days
View full developer profile
Detection Fingerprints

How We Detect LTL Freight Quotes – TForce Edition

Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.

Asset Fingerprints

Asset Paths
/wp-content/plugins/ltl-freight-quotes-ups-edition/css/wickedpicker.min.css/wp-content/plugins/ltl-freight-quotes-ups-edition/js/wickedpicker.js/wp-content/plugins/ltl-freight-quotes-ups-edition/css/ups-freight-style.css/wp-content/plugins/ltl-freight-quotes-ups-edition/logs/en-json-tree-view/en-jtv-style.css/wp-content/plugins/ltl-freight-quotes-ups-edition/logs/en-json-tree-view/en-jtv-script.js
Script Paths
/wp-content/plugins/ltl-freight-quotes-ups-edition/js/wickedpicker.js/wp-content/plugins/ltl-freight-quotes-ups-edition/logs/en-json-tree-view/en-jtv-script.js
Version Parameters
/wp-content/plugins/ltl-freight-quotes-ups-edition/css/wickedpicker.min.css?ver=1.0.0/wp-content/plugins/ltl-freight-quotes-ups-edition/js/wickedpicker.js?ver=1.0.0/wp-content/plugins/ltl-freight-quotes-ups-edition/css/ups-freight-style.css?ver=1.1.5/wp-content/plugins/ltl-freight-quotes-ups-edition/logs/en-json-tree-view/en-jtv-script.js?ver=1.0.0

HTML / DOM Fingerprints

CSS Classes
ups_freight_wc_avaibility_errnotice-error
HTML Comments
<!-- UPS Freight Admin Scripts --><!-- Load scripts for Tforce Freight json tree view -->
Data Attributes
data-plugin-name
JS Globals
ups_freight_wc_version_numberen_tforce_jtv_script
FAQ

Frequently Asked Questions about LTL Freight Quotes – TForce Edition