Lucky Orange Security & Risk Analysis

wordpress.org/plugins/lucky-orange

Less time crunching numbers, more time growing your business.

2K active installs v2.1.1 PHP + WP 2.0.3+ Updated Apr 14, 2025
analyticsconversion-rate-optimizationheatmapssession-recordingssurveys
100
A · Safe
CVEs total0
Unpatched0
Last CVENever
Safety Verdict

Is Lucky Orange Safe to Use in 2026?

Generally Safe

Score 100/100

Lucky Orange has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.

No known CVEs Updated 11mo ago
Risk Assessment

The "lucky-orange" plugin version 2.1.1 presents a generally positive security posture based on the provided static analysis. The plugin exhibits no obvious vulnerabilities in terms of attack surface, with zero AJAX handlers, REST API routes, shortcodes, or cron events found. Furthermore, the absence of dangerous functions, raw SQL queries, and unsanitized taint flows indicates a robust development approach. The presence of capability checks and the complete absence of known CVEs further bolster its security reputation.

However, a notable concern arises from the output escaping. With 33% of outputs not properly escaped, there is a potential risk of cross-site scripting (XSS) vulnerabilities, especially if user-supplied data is involved in these unescaped outputs. While the plugin performs external HTTP requests, the static analysis doesn't detail how this is handled, which could be a minor area for further investigation. Overall, the plugin demonstrates strong security fundamentals, but the unescaped output is a specific area that warrants attention to ensure complete security.

Key Concerns

  • Unescaped output detected
Vulnerabilities
None known

Lucky Orange Security Vulnerabilities

No known vulnerabilities — this is a good sign.
Code Analysis
Analyzed Mar 16, 2026

Lucky Orange Code Analysis

Dangerous Functions
0
Raw SQL Queries
0
0 prepared
Unescaped Output
4
8 escaped
Nonce Checks
0
Capability Checks
2
File Operations
0
External Requests
1
Bundled Libraries
0

Output Escaping

67% escaped12 total outputs
Attack Surface

Lucky Orange Attack Surface

Entry Points0
Unprotected0
WordPress Hooks 3
actionadmin_initlucky_wordpress.php:63
actionadmin_menulucky_wordpress.php:101
actionwp_headlucky_wordpress.php:204
Maintenance & Trust

Lucky Orange Maintenance & Trust

Maintenance Signals

WordPress version tested6.8.0
Last updatedApr 14, 2025
PHP min version
Downloads70K

Community Trust

Rating86/100
Number of ratings24
Active installs2K
Developer Profile

Lucky Orange Developer Profile

luckyorange

1 plugin · 2K total installs

94
trust score
Avg Security Score
100/100
Avg Patch Time
30 days
View full developer profile
Detection Fingerprints

How We Detect Lucky Orange

Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.

Asset Fingerprints

Asset Paths
/wp-content/plugins/lucky-orange/lucky-orange.php
Script Paths
https://d10lpsik1i8c69.cloudfront.net/w.jshttps://tools.luckyorange.com/core/lo.js

HTML / DOM Fingerprints

HTML Comments
<!-- Generator: Sketch 48.2 (47327) - http://www.bohemiancoding.com/sketch -->
Data Attributes
data:image/svg+xml;base64,PD94bWwgdmVyc2lvbj0iMS4wIiBlbmNvZGluZz0iVVRGLTgiPz4KPHN2ZyB3aWR0aD0iMTI4cHgiIGhlaWdodD0iMTI4cHgiIHZpZXdCb3g9IjAgMCAxMjggMTI4IiB2ZXJzaW9uPSIxLjEiIHhtbG5zPSJodHRwOi8vd3d3LnczLm9yZy8yMDAwL3N2ZyIgeG1sbnM6eGxpbms9Imh0dHA6Ly93d3cudzMub3JnLzE5OTkveGxpbmsiPgogICAgPCEtLSBHZW5lcmF0b3I6IFNrZXRjaCA0OC4yICg0NzMyNykgLSBodHRwOi8vd3d3LmJvaGVtaWFuY29kaW5nLmNvbS9za2V0Y2ggLS0+CiAgICA8dGl0bGU+QXJ0Ym9hcmQ8L3RpdGxlPgogICAgPGRlc2M+Q3JlYXRlZCB3aXRoIFNrZXRjaC48L2Rlc2M+CiAgICA8ZGVmcz48L2RlZnM+CiAgICA8ZyBpZD0iUGFnZS0xIiBzdHJva2U9Im5vbmUiIHN0cm9rZS13aWR0aD0iMSIgZmlsbD0ibm9uZSIgZmlsbC1ydWxlPSJldmVub2RkIj4KICAgICAgICA8ZyBpZD0iQXJ0Ym9hcmQiIGZpbGwtcnVsZT0ibm9uemVybyI+CiAgICAgICAgICAgIDxnIGlkPSJMTy1JY29uIiB0cmFuc2Zvcm09InRyYW5zbGF0ZSgyNi4wMDAwMDAsIDAuMDAwMDAwKSI+CiAgICAgICAgICAgICAgICA8cGF0aCBkPSJNOS44NjEzMzk0MywxMTUuOTc5ODE1IEMyLjc1ODQzNjU3LDEwNS4wOTU0MzkgLTIuODczMTk3NzEsOTEuMTI1OTM1MSAxLjU4ODg4MjI5LDc4LjMyNDg0MTEgQzYuMDQ5ODY1MTQsNjUuNTIzNzQ3IDEyLjA1MzQzMDksNTYuNDc5NTA3NyAyMi4yOTk2NDgsNTIuODIwMDIwNSBDMjcuNjcyMzU2Niw1MC45MDExMTQ1IDQzLjgzODc1NjYsNDMuNjkxNTQxOCA1Ni40MjA3OTA5LDU0LjgzMDgyNCBDNjkuMDAxNzI4LDY1Ljk3MTIgNzUuMzE0Njg4LDc5Ljg3Mzk2OTIgNzUuNzg4MDk3Myw4OS41Mzk2MTAyIEM3Ny4wNzIzMTA5LDExNi4zMDQ3MzggNDEuNjg1MDY1MSwxMjcuMjgzMiAzNS40Njc1NTY2LDEyNy4yODMyIEMyNy4wODUzODUxLDEyNy4yODMyIDE0LjU4MzQ0MjMsMTIzLjIxNjczOSA5Ljg2MTMzOTQzLDExNS45Nzk4MTUiIGlkPSJTaGFwZSIgZmlsbD0iI0ZGNzA0QyI+PC9wYXRoPgogICAgICAgICAgICAgICAgPHBhdGggZD0iTTU2LjA1MDA2NjMsMC43MjY2NDYxNTQgQzUxLjMxNTg5NDksLTUuODczNTU4OTggMzYuMTU2NjcyLDM0LjU3NzcyMzEgNDMuMzQwNzYzNCwzOS41Njc1MzUxIEM0NS4xNjA5MjM0LDQwLjgzMjIxODggNjYuMzI5MTk3NywxNS4wNTgyNzAxIDU2LjA1MDA2NjMsMC43MjY2NDYxNTQgTTM1LjA1MDg2MTcsMzkuNzcwNDc1MiBDMzYuMTI4MjU2LDQ1LjQzMzEwNzcgMjIuOTQ0OTg3NCwyNi41MjA4MzQyIDI1LjY0OTQ0NDYsMjMuMDUxNzA2IEMzMS44NTA0OTYsMTUuMDkzODI1NiAzNC40MTU2MTYsMzYuNDMwNDQxMSAzNS4wNTA4NjE3LDM5Ljc3MDQ3NTIiIGlkPSJTaGFwZSIgZmlsbD0iIzQyNEEzQyI+PC9wYXRoPgogICAgICAgICAgICA8L2c+CiAgICAgICAgPC9nPgogICAgPC9nPgo8L3N2Zz4=
JS Globals
window.__lo_site_idwindow.LOSiteId
FAQ

Frequently Asked Questions about Lucky Orange