
Lucky Wheel Giveaway Security & Risk Analysis
wordpress.org/plugins/wp-lucky-wheelCollect customer's emails by spinning the lucky wheel game to get discount coupons.
Is Lucky Wheel Giveaway Safe to Use in 2026?
Generally Safe
Score 97/100Lucky Wheel Giveaway has a strong security track record. Known vulnerabilities have been patched promptly.
The wp-lucky-wheel plugin v1.0.23 demonstrates a generally strong security posture in its static analysis, with all SQL queries using prepared statements and all output being properly escaped. The presence of 11 nonce checks and 5 capability checks further indicates an effort to secure its functionalities. However, a notable concern arises from the static analysis revealing one unprotected REST API route. This unprotected entry point, despite its low count within the overall attack surface, represents a direct pathway for unauthorized access or manipulation if not properly secured at the application level.
The vulnerability history is also a mixed bag. While there are no currently unpatched CVEs, the plugin does have one past high-severity vulnerability of the 'Code Injection' type. This historical incident is concerning as it suggests the potential for severe security flaws in the past, even if addressed. The taint analysis shows two flows with unsanitized paths, although these are not classified as critical or high severity. This, combined with the single unprotected REST API endpoint, indicates areas for improvement in input validation and access control.
In conclusion, wp-lucky-wheel v1.0.23 benefits from good practices in data handling and output sanitization. The absence of dangerous functions and its use of prepared statements are positive indicators. However, the single unprotected REST API route is a significant weakness that must be addressed. The history of a high-severity code injection vulnerability, even if patched, warrants continued vigilance. The two unsanitized path flows in the taint analysis also suggest that while severe issues may not be present in this version, further scrutiny of input handling could be beneficial.
Key Concerns
- Unprotected REST API route
- Past high severity 'Code Injection' vulnerability
- Flows with unsanitized paths (not critical/high)
Lucky Wheel Giveaway Security Vulnerabilities
CVEs by Year
Severity Breakdown
1 total CVE
Lucky Wheel Giveaway <= 1.0.22 - Authenticated (Administrator+) Remote Code Execution via 'conditional_tags' Parameter
Lucky Wheel Giveaway Code Analysis
Bundled Libraries
Output Escaping
Data Flow Analysis
Lucky Wheel Giveaway Attack Surface
AJAX Handlers 3
REST API Routes 1
WordPress Hooks 37
Maintenance & Trust
Lucky Wheel Giveaway Maintenance & Trust
Maintenance Signals
Community Trust
Lucky Wheel Giveaway Alternatives
Lucky Wheel for WooCommerce – Spin a Sale
woo-lucky-wheel
Engage customers with a fun spin-the-wheel game! Collect emails and reward them with discount coupons instantly.
Spin Wheel – Interactive spinning wheel that offers coupons
spin-wheel
The Spin Wheel plugin allows you to engage your visitors with an interactive spinning wheel that offers coupons and other rewards.
Giveaway Lottery for WooCommerce
giveaway-lottery
Sell tickets, run giveaways, raffles, lotteries, and lucky draws in WooCommerce to boost engagement, sales, and customer loyalty.
Lucky Wheel Exit Intent Pop Up, Upsell Pop Up – Rafflys
rafflys-lucky-wheel
Increase your email opt-in rates and conversions with our fully customizable, exit intent popup, Lucky Wheel.
MC4WP: Mailchimp for WordPress
mailchimp-for-wp
The #1 Mailchimp plugin for WordPress. Allows you to add a multitude of newsletter sign-up methods to your site.
Lucky Wheel Giveaway Developer Profile
58 plugins · 167K total installs
How We Detect Lucky Wheel Giveaway
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/wp-lucky-wheel/includes/support.php/wp-content/plugins/wp-lucky-wheel/includes/includes.phpwp-lucky-wheel/wp-lucky-wheel.php?ver=HTML / DOM Fingerprints
vi-uidata-wplwl_iddata-wplwl_noncedata-wplwl_spindata-wplwl_wheel_configdata-wplwl_wheel_settingsdata-wplwl_winnerswp_lucky_wheel_frontend_params/wp-json/wp-lucky-wheel/v1/spin/wp-json/wp-lucky-wheel/v1/collect/wp-json/wp-lucky-wheel/v1/claim[lucky-wheel][lucky-wheel id=][lucky-wheel url=]