Ultimate Spin Wheel – Gamify Your Store & Boost Sales Security & Risk Analysis

wordpress.org/plugins/ultimate-spin-wheel

Boost sales and capture leads with engaging spin-to-win popups. Reduce cart abandonment and increase conversions with customizable discount wheels.

0 active installs v2.0.4 PHP 7.4+ WP 6.1+ Updated Mar 14, 2026
coupon-wheeldiscount-wheelprize-wheelspin-wheelwoocommerce
100
A · Safe
CVEs total0
Unpatched0
Last CVENever
Safety Verdict

Is Ultimate Spin Wheel – Gamify Your Store & Boost Sales Safe to Use in 2026?

Generally Safe

Score 100/100

Ultimate Spin Wheel – Gamify Your Store & Boost Sales has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.

No known CVEs Updated 20d ago
Risk Assessment

The 'ultimate-spin-wheel' v2.0.4 plugin exhibits a generally good security posture based on the provided static analysis and vulnerability history. The vast majority of SQL queries utilize prepared statements, and output escaping is consistently applied, indicating a strong adherence to secure coding practices. The plugin also demonstrates a responsible approach to WordPress security by including nonce and capability checks on most of its entry points. Furthermore, the absence of any recorded CVEs or past vulnerabilities is a positive indicator of its historical security reliability and the development team's likely commitment to addressing potential issues.

Key Concerns

  • AJAX handler without authentication check
Vulnerabilities
None known

Ultimate Spin Wheel – Gamify Your Store & Boost Sales Security Vulnerabilities

No known vulnerabilities — this is a good sign.
Code Analysis
Analyzed Mar 17, 2026

Ultimate Spin Wheel – Gamify Your Store & Boost Sales Code Analysis

Dangerous Functions
0
Raw SQL Queries
10
76 prepared
Unescaped Output
8
391 escaped
Nonce Checks
27
Capability Checks
20
File Operations
3
External Requests
2
Bundled Libraries
0

SQL Query Safety

88% prepared86 total queries

Output Escaping

98% escaped399 total outputs
Data Flows
All sanitized

Data Flow Analysis

7 flows
dci_sdk_insights (dci\insights.php:567)
Source (user input) Sink (dangerous op) Sanitizer Transform Unsanitized Sanitized
Attack Surface
1 unprotected

Ultimate Spin Wheel – Gamify Your Store & Boost Sales Attack Surface

Entry Points26
Unprotected1

AJAX Handlers 26

authwp_ajax_dci_sdk_insightsdci\insights.php:40
authwp_ajax_dci_sdk_dismiss_noticedci\insights.php:41
authwp_ajax_dci_sdk_insights_deactivate_feedbackdci\insights.php:42
authwp_ajax_uspw_duplicate_campaignincludes\core\class-campaigns.php:29
authwp_ajax_ultimate_spin_wheel_get_entriesincludes\core\class-entries.php:22
authwp_ajax_ultimate_spin_wheel_delete_entryincludes\core\class-entries.php:23
authwp_ajax_ultimate_spin_wheel_bulk_delete_entriesincludes\core\class-entries.php:24
authwp_ajax_ultimate_spin_wheel_export_entriesincludes\core\class-entries.php:25
authwp_ajax_ultimate_spin_wheel_clear_cacheincludes\core\class-entries.php:26
authwp_ajax_ultimate_spin_wheel_update_entry_statusincludes\core\class-entries.php:28
authwp_ajax_ultimate_spin_wheel_block_identityincludes\core\class-entries.php:30
authwp_ajax_ultimate_spin_wheel_unblock_identityincludes\core\class-entries.php:31
authwp_ajax_ultimate_spin_wheel_reportsincludes\core\class-reports.php:17
noprivwp_ajax_ultimate_spin_wheel_reportsincludes\core\class-reports.php:18
authwp_ajax_ultimate_spin_wheel_get_global_settingsincludes\core\class-settings.php:17
authwp_ajax_ultimate_spin_wheel_update_global_settingsincludes\core\class-settings.php:18
authwp_ajax_ultimate_spin_wheel_sc_imp_countincludes\core\class-spin-wheel.php:21
noprivwp_ajax_ultimate_spin_wheel_sc_imp_countincludes\core\class-spin-wheel.php:22
authwp_ajax_ultimate_spin_wheel_spinnedincludes\core\class-spin-wheel.php:24
noprivwp_ajax_ultimate_spin_wheel_spinnedincludes\core\class-spin-wheel.php:25
authwp_ajax_ultimate_spin_wheel_check_identityincludes\core\class-spin-wheel.php:27
noprivwp_ajax_ultimate_spin_wheel_check_identityincludes\core\class-spin-wheel.php:28
authwp_ajax_ultimate_spin_wheel_process_spinincludes\core\class-spin-wheel.php:30
noprivwp_ajax_ultimate_spin_wheel_process_spinincludes\core\class-spin-wheel.php:31
authwp_ajax_rc_sdk_insightsincludes\feedbacks\notice.php:46
authwp_ajax_rc_sdk_dismiss_noticeincludes\feedbacks\notice.php:47
WordPress Hooks 25
actionadmin_enqueue_scriptsdci\insights.php:207
actionadmin_noticesdci\insights.php:215
actionadmin_noticesdci\insights.php:227
actionin_admin_headerdci\insights.php:233
actionadmin_enqueue_scriptsdci\insights.php:261
actionin_admin_headerdci\insights.php:270
actionadmin_menuincludes\admin\class-menu.php:28
actionwp_dashboard_setupincludes\class-admin-feeds.php:21
actionwp_loadedincludes\core\class-spin-wheel.php:33
actionwpincludes\core\class-spin-wheel.php:34
actionwp_enqueue_scriptsincludes\core\class-spin-wheel.php:39
actionwp_headincludes\core\class-spin-wheel.php:40
actionwp_footerincludes\core\class-spin-wheel.php:41
actionadmin_enqueue_scriptsincludes\feedbacks\notice.php:125
actionadmin_noticesincludes\feedbacks\notice.php:128
actionadmin_enqueue_scriptsplugin.php:259
actionadmin_enqueue_scriptsplugin.php:260
actionadmin_enqueue_scriptsplugin.php:261
actionedit_form_after_titleplugin.php:262
filteradmin_body_classplugin.php:263
actionadd_meta_boxesplugin.php:264
filterscreen_layout_columnsplugin.php:265
actioninitultimate-spin-wheel.php:77
actionadmin_initultimate-spin-wheel.php:186
actionadmin_initultimate-spin-wheel.php:217
Maintenance & Trust

Ultimate Spin Wheel – Gamify Your Store & Boost Sales Maintenance & Trust

Maintenance Signals

WordPress version tested6.9.4
Last updatedMar 14, 2026
PHP min version7.4
Downloads480

Community Trust

Rating0/100
Number of ratings0
Active installs0
Developer Profile

Ultimate Spin Wheel – Gamify Your Store & Boost Sales Developer Profile

wowDevs

7 plugins · 2K total installs

99
trust score
Avg Security Score
98/100
Avg Patch Time
6 days
View full developer profile
Detection Fingerprints

How We Detect Ultimate Spin Wheel – Gamify Your Store & Boost Sales

Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.

Asset Fingerprints

Asset Paths
/wp-content/plugins/ultimate-spin-wheel/dci/assets/css/dci.css/wp-content/plugins/ultimate-spin-wheel/includes/feedbacks/assets/rc.css
Version Parameters
ultimate-spin-wheel/dci/assets/css/dci.css?ver=ultimate-spin-wheel/includes/feedbacks/assets/rc.css?ver=

HTML / DOM Fingerprints

Data Attributes
data-dci-sdk-versiondata-dci-plugin-iddata-dci-plugin-namedata-dci-plugin-icondata-dci-api-endpointdata-dci-slug+5 more
JS Globals
dci_dynamic_initrc_dynamic_init
REST Endpoints
/wp-json/dci/v1/data-insights
FAQ

Frequently Asked Questions about Ultimate Spin Wheel – Gamify Your Store & Boost Sales