
Account Manager for WooCommerce Security & Risk Analysis
wordpress.org/plugins/account-manager-woocommerceAdd Account Manager Functionality, Customer Insights and Commission Management to WooCommerce
Is Account Manager for WooCommerce Safe to Use in 2026?
Mostly Safe
Score 79/100Account Manager for WooCommerce is generally safe to use. 1 past CVE were resolved. Keep it updated.
The "account-manager-woocommerce" v2.1.2 plugin exhibits a concerning security posture, primarily due to its unprotected entry points and a history of vulnerabilities. The static analysis reveals a significant attack surface with 3 AJAX handlers, all lacking authentication checks. This, combined with only 7 nonce checks across the codebase, creates a substantial risk of unauthorized actions being performed by unauthenticated users. While the plugin has a moderate number of SQL queries (76), only 18% use prepared statements, which is a weakness. However, the proper escaping of 70% of outputs and the absence of file operations and external HTTP requests are positive indicators of secure coding practices in those areas.
The plugin's vulnerability history is a major red flag, with one known medium-severity CVE that remains unpatched. The common vulnerability type of "Missing Authorization" found in past issues directly correlates with the current static analysis findings of unprotected AJAX handlers. This pattern suggests a recurring issue with how the plugin handles user permissions and access control. While the plugin demonstrates some good practices like proper output escaping and the bundling of a library like Select2 (though its security implications are not detailed here), the prevalent lack of authorization checks on critical entry points and the existing unpatched vulnerability significantly elevate the risk. The 3 unsanitized paths in taint analysis, although not classified as critical or high severity, warrant further investigation to understand their potential impact. Overall, the plugin presents a medium to high risk due to the combination of an exposed attack surface, a history of authorization flaws, and an unpatched vulnerability.
Key Concerns
- Unprotected AJAX handlers
- SQL queries without prepared statements
- Unpatched CVE
- Low percentage of prepared statements
- Low number of nonce checks
- Flows with unsanitized paths
Account Manager for WooCommerce Security Vulnerabilities
CVEs by Year
Severity Breakdown
1 total CVE
Account Manager for WooCommerce <= 2.1.1 - Missing Authorization
Account Manager for WooCommerce Code Analysis
Bundled Libraries
SQL Query Safety
Output Escaping
Data Flow Analysis
Account Manager for WooCommerce Attack Surface
AJAX Handlers 3
WordPress Hooks 27
Maintenance & Trust
Account Manager for WooCommerce Maintenance & Trust
Maintenance Signals
Community Trust
Account Manager for WooCommerce Alternatives
ERP: Complete HR, Accounting & CRM Suite with WooCommerce CRM Support
erp
Manage your business with a complete ERP system featuring powerful HR management, CRM tools, accounting, and seamless WooCommerce CRM integration.
CRM ERP Business Solution | freelancers & SME | for WordPress & WooCommerce
crm-erp-business-solution
CRM ERP BUSINESS SOLUTION for WordPress and WooCommerce for freelancers and SME to Import your Transactions, Products, Customers, Vendors, Appointment …
Extended WooCommerce Customer Management for Users Insights
extended-woocommerce-customer-management-for-users-insights
Extends the WooCommerce Customer Management of the Users Insights plugin by providing additional WooCommerce order data in the customer activity table
Jetpack CRM – Clients, Leads, Invoices, Billing, Email Marketing, & Automation
zero-bs-crm
The CRM for small businesses. Manage leads, invoicing, billing, email marketing, clients, contacts, quotes, automation. Works with WooCommerce too.
Guest Checkout Account Creator
guest-checkout-account-creator
Automatically create customer accounts during WooCommerce guest checkout. Boost sales while building your customer database.
Account Manager for WooCommerce Developer Profile
7 plugins · 3K total installs
How We Detect Account Manager for WooCommerce
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/account-manager-woocommerce/css/style.css/wp-content/plugins/account-manager-woocommerce/js/select2.js/wp-content/plugins/account-manager-woocommerce/js/script.js/wp-content/plugins/account-manager-woocommerce/js/select2.js/wp-content/plugins/account-manager-woocommerce/js/script.jsaccount-manager-woocommerce/css/style.css?ver=account-manager-woocommerce/js/select2.js?ver=account-manager-woocommerce/js/script.js?ver=HTML / DOM Fingerprints
zacctmgr-commission-formzacctmgr_user_commission<!-- Zacctmgr_Core_Admin::custom_user_profile_fields --><!-- Zacctmgr_Core_Admin::edit_others_commission --><!-- Zacctmgr_Core_Admin::save_custom_user_fields_new_user --><!-- Zacctmgr_Core_Admin::save_custom_user_fields -->+14 moredata-role="zacctmgr_user_commission"ajax_object