GoHero Store Customizer for WooCommerce Security & Risk Analysis

wordpress.org/plugins/personalize-woocommerce-cart-page

GoHero is just a great WooCommerce extension to customize any store. Like change button text/labels, add contents and much more.

700 active installs v4.0 PHP + WP 3.9+ Updated Jan 27, 2025
add-to-cart-labelcustomize-product-pagepersonalized-woocommercewoocommercewoocommerce-customizer
90
A · Safe
CVEs total2
Unpatched0
Last CVEJan 24, 2025
Safety Verdict

Is GoHero Store Customizer for WooCommerce Safe to Use in 2026?

Generally Safe

Score 90/100

GoHero Store Customizer for WooCommerce has a strong security track record. Known vulnerabilities have been patched promptly.

2 known CVEsLast CVE: Jan 24, 2025Updated 1yr ago
Risk Assessment

The "personalize-woocommerce-cart-page" plugin v4.0 exhibits a generally strong security posture based on the static analysis. The absence of dangerous functions, SQL queries not using prepared statements, and the presence of nonce checks are positive indicators. The attack surface is small and appears to be protected by authorization checks, which is a good practice. The plugin also avoids external HTTP requests and file operations, reducing potential attack vectors.

However, the plugin's vulnerability history presents a significant concern. With two known CVEs, including one high and one medium severity, and a recent vulnerability in 2025, it suggests a pattern of past security weaknesses. The common vulnerability types listed, particularly 'Missing Authorization', are critical for any plugin interacting with user data or site functionality.

While the current static analysis shows no immediate exploitable flaws and a good adherence to secure coding practices, the historical trend of vulnerabilities necessitates caution. The plugin's development team needs to demonstrate consistent maintenance and a proactive approach to security to address these past issues effectively. Users should remain vigilant and ensure the plugin is always updated to the latest version to mitigate any lingering or newly discovered vulnerabilities.

Key Concerns

  • High and Medium severity CVEs in history
  • Recent vulnerability in history (2025-01-24)
  • Missing Capability Checks (0 found)
Vulnerabilities
2

GoHero Store Customizer for WooCommerce Security Vulnerabilities

CVEs by Year

1 CVE in 2019
2019
1 CVE in 2025
2025
Patched Has unpatched

Severity Breakdown

High
1
Medium
1

2 total CVEs

CVE-2024-12826medium · 4.3Missing Authorization

GoHero Store Customizer for WooCommerce <= 3.5 - Missing Authorization to Unuthenticated Settings Update

Jan 24, 2025 Patched in 4.0 (6d)
CVE-2019-5979high · 8.8

Personalized WooCommerce Cart Page <= 2.4 - Cross-Site Request Forgery

Jun 19, 2019 Patched in 2.5 (1679d)
Code Analysis
Analyzed Mar 16, 2026

GoHero Store Customizer for WooCommerce Code Analysis

Dangerous Functions
0
Raw SQL Queries
0
0 prepared
Unescaped Output
10
91 escaped
Nonce Checks
1
Capability Checks
0
File Operations
0
External Requests
0
Bundled Libraries
0

Output Escaping

90% escaped101 total outputs
Attack Surface

GoHero Store Customizer for WooCommerce Attack Surface

Entry Points2
Unprotected0

AJAX Handlers 2

authwp_ajax_wooh_save_settingsinc\classes\class.admin.php:29
noprivwp_ajax_wooh_save_settingsinc\classes\class.admin.php:30
WordPress Hooks 7
actionadmin_menuinc\classes\class.admin.php:17
filterwoocommerce_product_tabsinc\classes\class.settings.php:118
filtergettextinc\classes\class.settings.php:122
actionwoocommerce_cart_couponinc\classes\class.settings.php:133
actionwp_enqueue_scriptsinc\classes\class.settings.php:142
actioninitwoohero.php:36
actionplugins_loadedwoohero.php:57
Maintenance & Trust

GoHero Store Customizer for WooCommerce Maintenance & Trust

Maintenance Signals

WordPress version tested6.7.5
Last updatedJan 27, 2025
PHP min version
Downloads59K

Community Trust

Rating92/100
Number of ratings10
Active installs700
Developer Profile

GoHero Store Customizer for WooCommerce Developer Profile

N-Media

23 plugins · 5K total installs

69
trust score
Avg Security Score
85/100
Avg Patch Time
588 days
View full developer profile
Detection Fingerprints

How We Detect GoHero Store Customizer for WooCommerce

Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.

Asset Fingerprints

Asset Paths
/wp-content/plugins/personalize-woocommerce-cart-page/css/style.css/wp-content/plugins/personalize-woocommerce-cart-page/css/sweetalert.css/wp-content/plugins/personalize-woocommerce-cart-page/js/easytabs/tabs.css/wp-content/plugins/personalize-woocommerce-cart-page/js/sweetalert.js/wp-content/plugins/personalize-woocommerce-cart-page/js/admin.js/wp-content/plugins/personalize-woocommerce-cart-page/js/nm-global.js/wp-content/plugins/personalize-woocommerce-cart-page/js/easytabs/jquery.easytabs.js/wp-content/plugins/personalize-woocommerce-cart-page/js/wooh-admin.js
Script Paths
/wp-content/plugins/personalize-woocommerce-cart-page/js/sweetalert.js/wp-content/plugins/personalize-woocommerce-cart-page/js/admin.js/wp-content/plugins/personalize-woocommerce-cart-page/js/nm-global.js/wp-content/plugins/personalize-woocommerce-cart-page/js/easytabs/jquery.easytabs.js/wp-content/plugins/personalize-woocommerce-cart-page/js/wooh-admin.js
Version Parameters
personalize-woocommerce-cart-page/css/style.css?ver=personalize-woocommerce-cart-page/css/sweetalert.css?ver=personalize-woocommerce-cart-page/js/easytabs/tabs.css?ver=personalize-woocommerce-cart-page/js/sweetalert.js?ver=personalize-woocommerce-cart-page/js/admin.js?ver=personalize-woocommerce-cart-page/js/nm-global.js?ver=personalize-woocommerce-cart-page/js/easytabs/jquery.easytabs.js?ver=personalize-woocommerce-cart-page/js/wooh-admin.js?ver=

HTML / DOM Fingerprints

CSS Classes
wooh_options_input
HTML Comments
<!-- **== Direct access not allowed ==** -->/* == Direct access not allowed == *//* == Woohero menu added in menu ==*//* == admin bar menu added ==*/+6 more
Data Attributes
data-wooh-nonce
JS Globals
wooh_vars
FAQ

Frequently Asked Questions about GoHero Store Customizer for WooCommerce