
WP Optin Wheel – Gamified Optin Email Marketing Tool for WordPress and WooCommerce Security & Risk Analysis
wordpress.org/plugins/wp-optin-wheelGrow your sales and email list by offering your visitors a chance to win a prize through spinning the wheel of fortune.
Is WP Optin Wheel – Gamified Optin Email Marketing Tool for WordPress and WooCommerce Safe to Use in 2026?
Generally Safe
Score 99/100WP Optin Wheel – Gamified Optin Email Marketing Tool for WordPress and WooCommerce has a strong security track record. Known vulnerabilities have been patched promptly.
The "wp-optin-wheel" v1.5.2 plugin exhibits a mixed security posture. On the positive side, static analysis reveals a remarkably small attack surface with no identified AJAX handlers, REST API routes, shortcodes, or cron events that lack authentication or permission checks. Furthermore, the code demonstrates good practices with a high percentage of properly escaped output and a solid number of nonce and capability checks. The absence of critical or high severity taint flows is also a strong indicator of secure coding in this regard. However, the plugin's history of two medium severity CVEs, including Server-Side Request Forgery (SSRF) and Storage of Sensitive Data in a Mechanism without Access Control, warrants significant caution. While these vulnerabilities are listed as currently unpatched (though the provided 'last vulnerability' date appears to be in the future), past occurrences of such vulnerabilities suggest potential underlying architectural weaknesses or recurring coding errors that could be exploited if not meticulously addressed in newer versions. The existence of these past vulnerabilities, even if resolved in the specific version analyzed, points to a history of exploitable flaws.
Key Concerns
- Two medium severity CVEs with SSRF and sensitive data storage
WP Optin Wheel – Gamified Optin Email Marketing Tool for WordPress and WooCommerce Security Vulnerabilities
CVEs by Year
Severity Breakdown
2 total CVEs
WP Optin Wheel <= 1.4.7 - Authenticated (Admin+) Server-Side Request Forgery
WP Optin Wheel <= 1.4.2 - Sensitive Information Exposure via Log File
WP Optin Wheel – Gamified Optin Email Marketing Tool for WordPress and WooCommerce Code Analysis
SQL Query Safety
Output Escaping
WP Optin Wheel – Gamified Optin Email Marketing Tool for WordPress and WooCommerce Attack Surface
WordPress Hooks 17
Maintenance & Trust
WP Optin Wheel – Gamified Optin Email Marketing Tool for WordPress and WooCommerce Maintenance & Trust
Maintenance Signals
Community Trust
WP Optin Wheel – Gamified Optin Email Marketing Tool for WordPress and WooCommerce Alternatives
Lucky Wheel for WooCommerce – Spin a Sale
woo-lucky-wheel
Engage customers with a fun spin-the-wheel game! Collect emails and reward them with discount coupons instantly.
Lucky Wheel Giveaway
wp-lucky-wheel
Collect customer's emails by spinning the lucky wheel game to get discount coupons.
Spin Wheel – Interactive spinning wheel that offers coupons
spin-wheel
The Spin Wheel plugin allows you to engage your visitors with an interactive spinning wheel that offers coupons and other rewards.
Spin Wheel Pop Up
crazyrocket-pop-ups
Wheel and gamified popups for WooCommerce! Grow your email list and sales.
WebEquipe Spin & Win Wheel
webequipe-spin-win-wheel
Spin-to-win for WordPress – engage visitors, capture emails, and deliver coupons to boost signups and sales.
WP Optin Wheel – Gamified Optin Email Marketing Tool for WordPress and WooCommerce Developer Profile
4 plugins · 61K total installs
How We Detect WP Optin Wheel – Gamified Optin Email Marketing Tool for WordPress and WooCommerce
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/wp-optin-wheel/public/js/public.min.js/wp-content/plugins/wp-optin-wheel/public/css/public.min.css/wp-content/plugins/wp-optin-wheel/public/css/theme-vintage.css/wp-content/plugins/wp-optin-wheel/public/css/theme-deep-purple.css/wp-content/plugins/wp-optin-wheel/public/css/theme-yellow.css/wp-content/plugins/wp-optin-wheel/public/css/theme-red.css/wp-content/plugins/wp-optin-wheel/public/css/theme-orange.css/wp-content/plugins/wp-optin-wheel/public/css/theme-purple.css+1 more/wp-content/plugins/wp-optin-wheel/public/js/public.min.jswp-optin-wheel/public/js/public.min.js?ver=wp-optin-wheel/public/css/public.min.css?ver=wp-optin-wheel/public/css/theme-vintage.css?ver=wp-optin-wheel/public/css/theme-deep-purple.css?ver=wp-optin-wheel/public/css/theme-yellow.css?ver=wp-optin-wheel/public/css/theme-red.css?ver=wp-optin-wheel/public/css/theme-orange.css?ver=wp-optin-wheel/public/css/theme-purple.css?ver=wp-optin-wheel/public/css/theme-green.css?ver=HTML / DOM Fingerprints
wof-wheelsExclude from WP Rocket's "Automatic Lazy Rendering" feature as that gives problems.data-wof-iddata-wof-themedata-wof-winning-titledata-wof-winning-textdata-wof-losing-titledata-wof-losing-text+7 morewofVars/wp-json/wof-lite/v1/add-email-to-list/wp-json/wof-lite/v1/play