
Wheelluck Security & Risk Analysis
wordpress.org/plugins/wheelluckAdds a link to the WordPress admin menu and loads a JavaScript file from CDN with user consent during installation.
Is Wheelluck Safe to Use in 2026?
Generally Safe
Score 100/100Wheelluck has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.
The "wheelluck" plugin version 1.0.2 demonstrates a strong security posture based on the provided static analysis. There are no identified direct entry points like AJAX handlers, REST API routes, shortcodes, or cron events that are exposed without authentication checks, which significantly reduces the attack surface. Furthermore, the code exhibits excellent security practices with all SQL queries using prepared statements and all output properly escaped. The absence of dangerous functions, file operations, and taint flows with unsanitized paths further reinforces this positive assessment. The presence of a nonce check and capability check, even with zero entry points, suggests an awareness of security principles. The plugin's vulnerability history is also clean, with no known CVEs, indicating a stable and likely well-maintained codebase. The only notable external interaction is a single HTTP request, which, without further context, poses a low immediate risk, especially given the overall robust security of the code. The strengths lie in the lack of exploitable code paths and adherence to best practices. The primary weakness, if one can be called that, is the limited attack surface and code signals, making it difficult to draw definitive conclusions about complex security interactions, though this also contributes to its strong security by default.
Wheelluck Security Vulnerabilities
Wheelluck Code Analysis
Output Escaping
Wheelluck Attack Surface
WordPress Hooks 6
Maintenance & Trust
Wheelluck Maintenance & Trust
Maintenance Signals
Community Trust
Wheelluck Alternatives
Dealicious – Smart Discounts & Rewards for WooCommerce
dealicious-smart-discounts-rewards-for-woocommerce
Dealicious is a WooCommerce plugin that helps store owners engage customers and boost sales with smart discounts and reward features.
Icegram Engage – Popups, Optins, CTAs & lot more…
icegram
Create popups, opt-in forms, and call-to-action messages to capture leads and engage visitors on your WordPress site.
GamiPress – Gamification plugin to reward points, achievements, badges & ranks in WordPress
gamipress
Boost your gamification marketing & reward your users with points, achievements, badges & ranks to increase your site activity & loyalty!
Smart Popup by Supsystic
popup-by-supsystic
Create targeted popups for lead capture, event notifications, announcements, and promotions — shown at the right time without disrupting your visitors …
HashBar – Announcement, Notification Bar & Popup Campaign
hashbar-wp-notification-bar
Create Announcement Bars, Notification Bars & Popup Campaigns with countdown timers, A/B testing, smart targeting & analytics.
Wheelluck Developer Profile
1 plugin · 0 total installs
How We Detect Wheelluck
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/wheelluck/includes/js/admin.jswheelluck/style.css?ver=wheelluck/script.js?ver=HTML / DOM Fingerprints
wl-dashboardwl-contentwl-headerwl-btnwl-section-titlewl-profilewl-avatardata-wheelluck-idWheelluck