
GoHero Store Customizer for WooCommerce Security & Risk Analysis
wordpress.org/plugins/personalize-woocommerce-cart-pageGoHero is just a great WooCommerce extension to customize any store. Like change button text/labels, add contents and much more.
Is GoHero Store Customizer for WooCommerce Safe to Use in 2026?
Generally Safe
Score 90/100GoHero Store Customizer for WooCommerce has a strong security track record. Known vulnerabilities have been patched promptly.
The "personalize-woocommerce-cart-page" plugin v4.0 exhibits a generally strong security posture based on the static analysis. The absence of dangerous functions, SQL queries not using prepared statements, and the presence of nonce checks are positive indicators. The attack surface is small and appears to be protected by authorization checks, which is a good practice. The plugin also avoids external HTTP requests and file operations, reducing potential attack vectors.
However, the plugin's vulnerability history presents a significant concern. With two known CVEs, including one high and one medium severity, and a recent vulnerability in 2025, it suggests a pattern of past security weaknesses. The common vulnerability types listed, particularly 'Missing Authorization', are critical for any plugin interacting with user data or site functionality.
While the current static analysis shows no immediate exploitable flaws and a good adherence to secure coding practices, the historical trend of vulnerabilities necessitates caution. The plugin's development team needs to demonstrate consistent maintenance and a proactive approach to security to address these past issues effectively. Users should remain vigilant and ensure the plugin is always updated to the latest version to mitigate any lingering or newly discovered vulnerabilities.
Key Concerns
- High and Medium severity CVEs in history
- Recent vulnerability in history (2025-01-24)
- Missing Capability Checks (0 found)
GoHero Store Customizer for WooCommerce Security Vulnerabilities
CVEs by Year
Severity Breakdown
2 total CVEs
GoHero Store Customizer for WooCommerce <= 3.5 - Missing Authorization to Unuthenticated Settings Update
Personalized WooCommerce Cart Page <= 2.4 - Cross-Site Request Forgery
GoHero Store Customizer for WooCommerce Code Analysis
Output Escaping
GoHero Store Customizer for WooCommerce Attack Surface
AJAX Handlers 2
WordPress Hooks 7
Maintenance & Trust
GoHero Store Customizer for WooCommerce Maintenance & Trust
Maintenance Signals
Community Trust
GoHero Store Customizer for WooCommerce Alternatives
Custom Add to Cart labels for WooCommerce
wc-custom-add-to-cart-labels
This plugin lets you change the “add to cart” labels on all single product pages (per product type) and also on archive/shop page (per product type)
WooHoo! – WooCommerce customiser
woohoo
Easily and quickly customise your WooCommerce shop.
Woomizer
woomizer
WooCommerce customizer with live preview.
Customization For WooCommerce
customization-for-woocommerce
Customize shop pages, products, categories, and taxonomies effortlessly. Transform your business website with ease!
ShopGlut – Builder for WooCommerce
shopglut
Builder for Woocommerce with 9 powerful modules including single product builder, cart page, checkout editor, order complete, wishlist, custom fields, …
GoHero Store Customizer for WooCommerce Developer Profile
23 plugins · 5K total installs
How We Detect GoHero Store Customizer for WooCommerce
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/personalize-woocommerce-cart-page/css/style.css/wp-content/plugins/personalize-woocommerce-cart-page/css/sweetalert.css/wp-content/plugins/personalize-woocommerce-cart-page/js/easytabs/tabs.css/wp-content/plugins/personalize-woocommerce-cart-page/js/sweetalert.js/wp-content/plugins/personalize-woocommerce-cart-page/js/admin.js/wp-content/plugins/personalize-woocommerce-cart-page/js/nm-global.js/wp-content/plugins/personalize-woocommerce-cart-page/js/easytabs/jquery.easytabs.js/wp-content/plugins/personalize-woocommerce-cart-page/js/wooh-admin.js/wp-content/plugins/personalize-woocommerce-cart-page/js/sweetalert.js/wp-content/plugins/personalize-woocommerce-cart-page/js/admin.js/wp-content/plugins/personalize-woocommerce-cart-page/js/nm-global.js/wp-content/plugins/personalize-woocommerce-cart-page/js/easytabs/jquery.easytabs.js/wp-content/plugins/personalize-woocommerce-cart-page/js/wooh-admin.jspersonalize-woocommerce-cart-page/css/style.css?ver=personalize-woocommerce-cart-page/css/sweetalert.css?ver=personalize-woocommerce-cart-page/js/easytabs/tabs.css?ver=personalize-woocommerce-cart-page/js/sweetalert.js?ver=personalize-woocommerce-cart-page/js/admin.js?ver=personalize-woocommerce-cart-page/js/nm-global.js?ver=personalize-woocommerce-cart-page/js/easytabs/jquery.easytabs.js?ver=personalize-woocommerce-cart-page/js/wooh-admin.js?ver=HTML / DOM Fingerprints
wooh_options_input<!-- **== Direct access not allowed ==** -->/* == Direct access not allowed == *//* == Woohero menu added in menu ==*//* == admin bar menu added ==*/+6 moredata-wooh-noncewooh_vars