
Lucky Wheel Exit Intent Pop Up, Upsell Pop Up – Rafflys Security & Risk Analysis
wordpress.org/plugins/rafflys-lucky-wheelIncrease your email opt-in rates and conversions with our fully customizable, exit intent popup, Lucky Wheel.
Is Lucky Wheel Exit Intent Pop Up, Upsell Pop Up – Rafflys Safe to Use in 2026?
Generally Safe
Score 85/100Lucky Wheel Exit Intent Pop Up, Upsell Pop Up – Rafflys has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.
The 'rafflys-lucky-wheel' v1.0 plugin exhibits a mixed security posture. On the positive side, it demonstrates good practices regarding SQL queries, exclusively using prepared statements, and has a clean vulnerability history with no recorded CVEs. The taint analysis also shows no critical or high severity issues, suggesting that unsanitized data flows are not a significant concern in this version.
However, the plugin presents notable risks due to its attack surface. The presence of two AJAX handlers, one of which lacks authentication checks, is a significant security concern. This unprotected entry point could be exploited by unauthenticated users to trigger plugin functionalities, potentially leading to unintended consequences or further vulnerabilities. Additionally, the use of the `unserialize` function, while not directly flagged as an issue in taint analysis, can be a vector for deserialization vulnerabilities if the data being unserialized is not strictly controlled and sanitized, which is often the case with user-supplied input or external data.
While the plugin's vulnerability history is clean, this can also be interpreted as limited testing or a lack of exposure to sophisticated attacks. The clean history combined with the identified security weaknesses suggests a need for proactive security measures. In conclusion, 'rafflys-lucky-wheel' v1.0 has some strong foundational security practices but is let down by a critical flaw in its AJAX handler authentication and a potentially risky use of `unserialize`. The lack of capability checks on the unprotected AJAX endpoint is the most pressing concern.
Key Concerns
- Unprotected AJAX handler
- Use of unserialize function
- Missing capability checks
Lucky Wheel Exit Intent Pop Up, Upsell Pop Up – Rafflys Security Vulnerabilities
Lucky Wheel Exit Intent Pop Up, Upsell Pop Up – Rafflys Code Analysis
Dangerous Functions Found
Output Escaping
Data Flow Analysis
Lucky Wheel Exit Intent Pop Up, Upsell Pop Up – Rafflys Attack Surface
AJAX Handlers 2
WordPress Hooks 16
Maintenance & Trust
Lucky Wheel Exit Intent Pop Up, Upsell Pop Up – Rafflys Maintenance & Trust
Maintenance Signals
Community Trust
Lucky Wheel Exit Intent Pop Up, Upsell Pop Up – Rafflys Alternatives
Lucky Wheel for WooCommerce – Spin a Sale
woo-lucky-wheel
Engage customers with a fun spin-the-wheel game! Collect emails and reward them with discount coupons instantly.
Lucky Wheel Giveaway
wp-lucky-wheel
Collect customer's emails by spinning the lucky wheel game to get discount coupons.
Spin Wheel – Interactive spinning wheel that offers coupons
spin-wheel
The Spin Wheel plugin allows you to engage your visitors with an interactive spinning wheel that offers coupons and other rewards.
Poptin – Exit Pop Ups & Email Popups
poptin
Free exit intent popup builder, gamified popups with spin the wheel, contact form builder & lead generation pop ups platform for your website. 🎉
Smart Popup by Supsystic
popup-by-supsystic
Create targeted popups for lead capture, event notifications, announcements, and promotions — shown at the right time without disrupting your visitors …
Lucky Wheel Exit Intent Pop Up, Upsell Pop Up – Rafflys Developer Profile
1 plugin · 20 total installs
How We Detect Lucky Wheel Exit Intent Pop Up, Upsell Pop Up – Rafflys
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/rafflys-lucky-wheel/assets/css/rafflys-admin.css/wp-content/plugins/rafflys-lucky-wheel/assets/css/rafflys.css/wp-content/plugins/rafflys-lucky-wheel/assets/js/rafflys-admin.js/wp-content/plugins/rafflys-lucky-wheel/assets/js/rafflys.js/wp-content/plugins/rafflys-lucky-wheel/assets/js/rafflys-admin.js/wp-content/plugins/rafflys-lucky-wheel/assets/js/rafflys.jsrafflys-lucky-wheel/assets/css/rafflys-admin.css?ver=rafflys-lucky-wheel/assets/css/rafflys.css?ver=rafflys-lucky-wheel/assets/js/rafflys-admin.js?ver=rafflys-lucky-wheel/assets/js/rafflys.js?ver=HTML / DOM Fingerprints
rafflys-lucky-wheel-widgetrafflys-app<!-- Rafflys Admin Scripts --><!-- Rafflys Widget --><!-- Rafflys Settings --><!-- Rafflys Setup -->+2 moredata-app-urldata-wp-sitedata-noncedata-create-urldata-connect-urldata-register-url+2 moreRafflysRafflysAdminrafflys_app_data/wp-json/rafflys/v1/settings/wp-json/rafflys/v1/promotions/wp-json/rafflys/v1/users[rafflys_wheel][rafflys_popup]