Print Label and Tracking Code for GLS Security & Risk Analysis
wordpress.org/plugins/woo-gls-print-label-and-tracking-codeGLS Delivery is a user-friendly WooCommerce plugin that produces customized GLS labels.
Is Print Label and Tracking Code for GLS Safe to Use in 2026?
Generally Safe
Score 85/100Print Label and Tracking Code for GLS has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.
The "woo-gls-print-label-and-tracking-code" plugin version 4.13.0 presents a generally positive security posture based on the static analysis. The absence of any identified attack surface, such as AJAX handlers, REST API routes, shortcodes, or cron events, is a significant strength, minimizing potential entry points for attackers. The code also shows good practices in output escaping, with a high percentage of outputs being properly sanitized, and a low number of critical or high-severity taint flows. The plugin's vulnerability history being completely clean further reinforces this impression, suggesting a well-maintained and secure codebase.
However, there are notable areas of concern. The most significant is the complete lack of capability checks across all code paths. This means that any functionality within the plugin, regardless of its sensitivity, is potentially accessible to any logged-in user, including those with minimal privileges. Additionally, all SQL queries are executed without the use of prepared statements, exposing the plugin to a high risk of SQL injection vulnerabilities. While the static analysis did not flag any specific SQL injection issues in the analyzed flows, the lack of prepared statements for all queries is a systemic weakness that should be addressed. The presence of file operations and external HTTP requests also warrants careful monitoring, although no immediate risks were identified in this analysis.
In conclusion, the plugin demonstrates a strong defense against common entry point exploitation and shows good output sanitization. The clean vulnerability history is a testament to its past security. Nevertheless, the complete absence of capability checks and the universal use of raw SQL queries represent substantial risks that significantly undermine the overall security. Addressing these two issues should be the highest priority to improve the plugin's security.
Key Concerns
- No capability checks found
- 100% of SQL queries are not prepared
Print Label and Tracking Code for GLS Security Vulnerabilities
Print Label and Tracking Code for GLS Code Analysis
SQL Query Safety
Output Escaping
Data Flow Analysis
Print Label and Tracking Code for GLS Attack Surface
WordPress Hooks 35
Maintenance & Trust
Print Label and Tracking Code for GLS Maintenance & Trust
Maintenance Signals
Community Trust
Print Label and Tracking Code for GLS Alternatives
Print Label and Tracking Code for DPD
print-label-and-tracking-code-for-dpd
DPD Delivery is a user-friendly WooCommerce plugin that produces customized DPD labels.
DEPRECATED – Shipmondo – A complete shipping solution for WooCommerce
pakkelabels-for-woocommerce
Shipmondo for WooCommerce – Provide pick-up points in checkout and manage shipping easily
GLS Shipping for WooCommerce
gls-shipping-for-woocommerce
GLS Shipping plugin for WooCommerce
Calculate Prices based on Distance For WooCommerce
calculate-prices-based-on-distance-for-woocommerce
The best WooCommerce Distance Rate Shipping alternative. Secure delivery fee calculation by KM/Mile via Google Maps. Supports Block Checkout & Del …
Invelity MyGLS connect
invelity-mygls-connect
Jednoduchý prenos objednávok do GLS cez API a tlač štítkov
Print Label and Tracking Code for GLS Developer Profile
2 plugins · 120 total installs
How We Detect Print Label and Tracking Code for GLS
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/woo-gls-print-label-and-tracking-code/assets/frontend.css/wp-content/plugins/woo-gls-print-label-and-tracking-code/assets/frontend.jshttps://maps.googleapis.com/maps/api/js?key=https://unpkg.com/@googlemaps/markerclusterer@2.0.8/dist/index.min.jswoo-gls-print-label-and-tracking-code/assets/frontend.css?ver=woo-gls-print-label-and-tracking-code/assets/frontend.js?ver=HTML / DOM Fingerprints
woocommerce-gls-print-label_google_apiwoocommerce-gls-print-label_markerclusterwoocommerce-gls-print-labelreadonly="readonly"LocationsForMapisCheckoutwpglsasseturldisableGeolocationmyLatLngmapZoom