Top 3 Lottery Jackpots Security & Risk Analysis

wordpress.org/plugins/top-3-jackpots

This plugin is made for you to monetize your WordPress website's traffic with a great lottery offer!

10 active installs v1.0.7 PHP + WP 4.0+ Updated Oct 27, 2019
drawjackpotlotterylottowinnings-numbers
85
A · Safe
CVEs total0
Unpatched0
Last CVENever
Safety Verdict

Is Top 3 Lottery Jackpots Safe to Use in 2026?

Generally Safe

Score 85/100

Top 3 Lottery Jackpots has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.

No known CVEs Updated 6yr ago
Risk Assessment

The "top-3-jackpots" v1.0.7 plugin exhibits a mixed security posture. On the positive side, it has no known vulnerabilities (CVEs) and its SQL queries are properly prepared, indicating a good understanding of database security. The absence of bundled libraries also removes a common vector for outdated component vulnerabilities.

However, several significant concerns are raised by the static analysis. The presence of 3 unprotected AJAX handlers represents a substantial attack surface. Coupled with the use of the dangerous `unserialize` function, which can lead to remote code execution if user-controlled data is unserialized without proper validation, this plugin has critical potential weaknesses. The taint analysis revealing 2 flows with unsanitized paths, even without a critical or high severity rating, suggests potential vulnerabilities that could be exploited. The low percentage of properly escaped output also increases the risk of cross-site scripting (XSS) vulnerabilities.

Overall, while the plugin's vulnerability history is clean, this is overshadowed by the numerous security risks identified in the static analysis. The lack of nonce checks on AJAX handlers and the potential for unserialize vulnerabilities are the most pressing issues that require immediate attention. Until these are addressed, the plugin should be considered to have a moderate to high risk.

Key Concerns

  • Unprotected AJAX handlers
  • Dangerous unserialize function usage
  • Unsanitized paths in taint analysis
  • Low output escaping percentage
  • Missing nonce checks
Vulnerabilities
None known

Top 3 Lottery Jackpots Security Vulnerabilities

No known vulnerabilities — this is a good sign.
Version History

Top 3 Lottery Jackpots Release Timeline

No version history available.
Code Analysis
Analyzed Apr 16, 2026

Top 3 Lottery Jackpots Code Analysis

Dangerous Functions
5
Raw SQL Queries
0
0 prepared
Unescaped Output
5
7 escaped
Nonce Checks
0
Capability Checks
3
File Operations
0
External Requests
1
Bundled Libraries
0

Dangerous Functions Found

unserialize$lottodata = unserialize( $lottodata_ );inc/frontend-editor/template.php:44
unserialize$lottodata = unserialize( $lottodata_ );inc/receiver.php:24
unserialize$lottodata = unserialize( $lottodata_ );inc/shortcodes.php:28
unserialize$lottodata = unserialize( $lottodata_ );inc/shortcodes.php:112
unserialize$lotteries_data = unserialize( $lotteries_data_ );inc/updates.php:90

Output Escaping

58% escaped12 total outputs
Data Flows · Security
2 unsanitized

Data Flow Analysis

2 flows2 with unsanitized paths
top3jps_ajax_frontend_editor_handler (inc/frontend-editor/receiver.php:18)
Source (user input) Sink (dangerous op) Sanitizer Transform Unsanitized Sanitized
Attack Surface
3 unprotected

Top 3 Lottery Jackpots Attack Surface

Entry Points4
Unprotected3

AJAX Handlers 3

authwp_ajax_top3jps_count_clicksinc/countclicks.php:50
noprivwp_ajax_top3jps_count_clicksinc/countclicks.php:51
authwp_ajax_top3jps_ajax_frontend_editor_handlerinc/frontend-editor/receiver.php:62

Shortcodes 1

[top3jackpots] inc/shortcodes.php:92
WordPress Hooks 11
actionadmin_footerinc/frontend-editor/template.php:140
actionwp_footerinc/frontend-editor/template.php:142
actioninitinc/frontend-editor/template.php:146
actioninitinc/receiver.php:82
actionwp_footerinc/shortcodes.php:87
actionwp_footerinc/shortcodes.php:88
actionadmin_bar_menuinc/topmenu.php:31
actiontop3jps_deactivationinc/updates.php:36
actiontop3jps_cron_update_jackpots_actioninc/updates.php:181
actionadmin_noticesindex.php:81
actionadmin_initindex.php:84

Scheduled Events 2

top3jps_cron_update_jackpots_action
top3jps_cron_update_jackpots_action
Maintenance & Trust

Top 3 Lottery Jackpots Maintenance & Trust

Maintenance Signals

WordPress version tested5.3.21
Last updatedOct 27, 2019
PHP min version
Downloads2K

Community Trust

Rating100/100
Number of ratings1
Active installs10
Developer Profile

Top 3 Lottery Jackpots Developer Profile

Maxton

1 plugin · 10 total installs

84
trust score
Avg Security Score
85/100
Avg Patch Time
30 days
View full developer profile
Detection Fingerprints

How We Detect Top 3 Lottery Jackpots

Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.

Asset Fingerprints

Asset Paths
/wp-content/plugins/top-3-jackpots/inc/frontend-editor/styles.css/wp-content/plugins/top-3-jackpots/inc/frontend-editor/functions.js
Script Paths
/wp-content/plugins/top-3-jackpots/inc/frontend-editor/functions.js
Version Parameters
top-3-jackpots/inc/frontend-editor/styles.css?ver=top-3-jackpots/inc/frontend-editor/functions.js?ver=

HTML / DOM Fingerprints

CSS Classes
top3jps-settings-editortop3jps-settings-editor-header-1top3jps-settings-headertop3jps-hide-editortop3jps-settings-editor-header-2top3jps-general-tab-toggletop3jps-settings-tab-toggletop3jps-toggle-active+11 more
Data Attributes
data-target
JS Globals
TOP_3_JP_ROOT_URL
Shortcode Output
[top3jackpots]
FAQ

Frequently Asked Questions about Top 3 Lottery Jackpots