Gou Manage My Account Menu – User Roles Security & Risk Analysis

wordpress.org/plugins/gou-wc-account-tabs

Extension for WooCommerce to manage my account menus. Functionality to add/update/rename, show/hide, build multi-level menus.

100 active installs v1.0.2.3 PHP 5.6+ WP 4.5+ Updated Jan 5, 2026
custom-menumenumy-accountuser-roleswoocommerce
99
A · Safe
CVEs total1
Unpatched0
Last CVEDec 11, 2024
Safety Verdict

Is Gou Manage My Account Menu – User Roles Safe to Use in 2026?

Generally Safe

Score 99/100

Gou Manage My Account Menu – User Roles has a strong security track record. Known vulnerabilities have been patched promptly.

1 known CVELast CVE: Dec 11, 2024Updated 2mo ago
Risk Assessment

The "gou-wc-account-tabs" plugin exhibits a mixed security posture. On the positive side, it demonstrates good practices by exclusively using prepared statements for all SQL queries and ensuring a high percentage of output is properly escaped. The absence of dangerous functions, file operations, and external HTTP requests further strengthens its security. However, significant concerns arise from its attack surface. With seven AJAX handlers, two of which lack authentication checks, there's a clear potential for unauthorized actions to be performed. While no critical or high-severity taint flows were detected, the presence of missing authorization checks on AJAX endpoints is a direct pathway for exploitation. The vulnerability history, with one medium-severity CVE related to missing authorization, reinforces this concern and suggests a recurring pattern of weak access control in the plugin. Overall, while the plugin implements good coding practices in some areas, the unprotected AJAX endpoints represent a critical weakness that needs immediate attention.

Key Concerns

  • Unprotected AJAX handlers
  • One medium severity CVE with missing authorization
  • Limited capability checks found
Vulnerabilities
1

Gou Manage My Account Menu – User Roles Security Vulnerabilities

CVEs by Year

1 CVE in 2024
2024
Patched Has unpatched

Severity Breakdown

Medium
1

1 total CVE

CVE-2024-54310medium · 5.3Missing Authorization

Gou Manage My Account Menu <= 1.0.1.8 - Missing Authorization

Dec 11, 2024 Patched in 1.0.1.9 (8d)
Code Analysis
Analyzed Mar 16, 2026

Gou Manage My Account Menu – User Roles Code Analysis

Dangerous Functions
0
Raw SQL Queries
0
41 prepared
Unescaped Output
12
89 escaped
Nonce Checks
4
Capability Checks
1
File Operations
0
External Requests
0
Bundled Libraries
0

SQL Query Safety

100% prepared41 total queries

Output Escaping

88% escaped101 total outputs
Attack Surface
2 unprotected

Gou Manage My Account Menu – User Roles Attack Surface

Entry Points7
Unprotected2

AJAX Handlers 7

authwp_ajax_gwat_set_endpointsgou-woo-account-tabs.php:50
noprivwp_ajax_gwat_set_endpointsgou-woo-account-tabs.php:51
authwp_ajax_gwat_set_menu_ordersgou-woo-account-tabs.php:53
noprivwp_ajax_gwat_set_menu_ordersgou-woo-account-tabs.php:54
authwp_ajax_gwat_delete_endpointsgou-woo-account-tabs.php:56
authwp_ajax_gwat_need_help_request_submitgou-woo-account-tabs.php:61
noprivwp_ajax_gwat_need_help_request_submitgou-woo-account-tabs.php:62
WordPress Hooks 14
filterwoocommerce_settings_tabs_arraygou-woo-account-tabs.php:30
actionwoocommerce_settings_tabs_gwatsgou-woo-account-tabs.php:31
actionadmin_enqueue_scriptsgou-woo-account-tabs.php:32
actionwoocommerce_update_options_gwatsgou-woo-account-tabs.php:33
actiongwat_admin_setting_pagesgou-woo-account-tabs.php:34
filterplugin_action_linksgou-woo-account-tabs.php:35
actionwpgou-woo-account-tabs.php:36
actioninitgou-woo-account-tabs.php:43
filterwc_get_templategou-woo-account-tabs.php:44
actionwp_enqueue_scriptsgou-woo-account-tabs.php:45
actionwoocommerce_account_contentgou-woo-account-tabs.php:46
actionadmin_footergou-woo-account-tabs.php:60
actionwoocommerce_account_page_endpointgou-woo-account-tabs.php:575
actionwoocommerce_account_gwat-endpoint-dashboard_endpointgou-woo-account-tabs.php:576
Maintenance & Trust

Gou Manage My Account Menu – User Roles Maintenance & Trust

Maintenance Signals

WordPress version tested6.9.4
Last updatedJan 5, 2026
PHP min version5.6
Downloads8K

Community Trust

Rating100/100
Number of ratings2
Active installs100
Developer Profile

Gou Manage My Account Menu – User Roles Developer Profile

Aslam Khan Gouran

3 plugins · 100 total installs

94
trust score
Avg Security Score
100/100
Avg Patch Time
8 days
View full developer profile
Detection Fingerprints

How We Detect Gou Manage My Account Menu – User Roles

Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.

Asset Fingerprints

Asset Paths
/wp-content/plugins/gou-wc-account-tabs/assets/css/style.css/wp-content/plugins/gou-wc-account-tabs/assets/js/frontend.js
Script Paths
/wp-content/plugins/gou-wc-account-tabs/assets/js/frontend.js
Version Parameters
gou-wc-account-tabs/assets/css/style.css?ver=gou-wc-account-tabs/assets/js/frontend.js?ver=

HTML / DOM Fingerprints

CSS Classes
gwat-nav-linkgwat-custom-nav-link
Data Attributes
data-gwat-iddata-gwat-titledata-gwat-slugdata-gwat-is_defaultdata-gwat-is_activedata-gwat-menu_order+5 more
JS Globals
gwat_vars
REST Endpoints
/wp-json/gwat/v1/endpoints
FAQ

Frequently Asked Questions about Gou Manage My Account Menu – User Roles