WP Optin Wheel – Gamified Optin Email Marketing Tool for WordPress and WooCommerce Security & Risk Analysis

wordpress.org/plugins/wp-optin-wheel

Grow your sales and email list by offering your visitors a chance to win a prize through spinning the wheel of fortune.

1K active installs v1.5.2 PHP 5.6+ WP 4.1+ Updated Dec 11, 2025
fortunegamificationoptinspin-wheelwheel
99
A · Safe
CVEs total2
Unpatched0
Last CVEApr 1, 2025
Safety Verdict

Is WP Optin Wheel – Gamified Optin Email Marketing Tool for WordPress and WooCommerce Safe to Use in 2026?

Generally Safe

Score 99/100

WP Optin Wheel – Gamified Optin Email Marketing Tool for WordPress and WooCommerce has a strong security track record. Known vulnerabilities have been patched promptly.

2 known CVEsLast CVE: Apr 1, 2025Updated 3mo ago
Risk Assessment

The "wp-optin-wheel" v1.5.2 plugin exhibits a mixed security posture. On the positive side, static analysis reveals a remarkably small attack surface with no identified AJAX handlers, REST API routes, shortcodes, or cron events that lack authentication or permission checks. Furthermore, the code demonstrates good practices with a high percentage of properly escaped output and a solid number of nonce and capability checks. The absence of critical or high severity taint flows is also a strong indicator of secure coding in this regard. However, the plugin's history of two medium severity CVEs, including Server-Side Request Forgery (SSRF) and Storage of Sensitive Data in a Mechanism without Access Control, warrants significant caution. While these vulnerabilities are listed as currently unpatched (though the provided 'last vulnerability' date appears to be in the future), past occurrences of such vulnerabilities suggest potential underlying architectural weaknesses or recurring coding errors that could be exploited if not meticulously addressed in newer versions. The existence of these past vulnerabilities, even if resolved in the specific version analyzed, points to a history of exploitable flaws.

Key Concerns

  • Two medium severity CVEs with SSRF and sensitive data storage
Vulnerabilities
2

WP Optin Wheel – Gamified Optin Email Marketing Tool for WordPress and WooCommerce Security Vulnerabilities

CVEs by Year

1 CVE in 2023
2023
1 CVE in 2025
2025
Patched Has unpatched

Severity Breakdown

Medium
2

2 total CVEs

CVE-2025-31824medium · 5.5Server-Side Request Forgery (SSRF)

WP Optin Wheel <= 1.4.7 - Authenticated (Admin+) Server-Side Request Forgery

Apr 1, 2025 Patched in 1.4.8 (17d)
CVE-2023-51408medium · 5.3Storage of Sensitive Data in a Mechanism without Access Control

WP Optin Wheel <= 1.4.2 - Sensitive Information Exposure via Log File

Dec 27, 2023 Patched in 1.4.3 (27d)
Code Analysis
Analyzed Mar 16, 2026

WP Optin Wheel – Gamified Optin Email Marketing Tool for WordPress and WooCommerce Code Analysis

Dangerous Functions
0
Raw SQL Queries
1
2 prepared
Unescaped Output
17
267 escaped
Nonce Checks
10
Capability Checks
10
File Operations
6
External Requests
2
Bundled Libraries
0

SQL Query Safety

67% prepared3 total queries

Output Escaping

94% escaped284 total outputs
Attack Surface

WP Optin Wheel – Gamified Optin Email Marketing Tool for WordPress and WooCommerce Attack Surface

Entry Points0
Unprotected0
WordPress Hooks 17
actioninitclass-wheel-of-fortune.php:42
actionplugins_loadedclass-wheel-of-fortune.php:44
filterwp_privacy_personal_data_exportersclass-wheel-of-fortune.php:47
filterwp_privacy_personal_data_erasersclass-wheel-of-fortune.php:48
actionadmin_initclass-wheel-of-fortune.php:49
actionwp_footercode\controllers\class-public-controller.php:39
filterrocket_lrc_exclusionscode\controllers\class-public-controller.php:45
actionadmin_menucore\common\class-admin.php:30
actionadmin_initcore\common\class-admin.php:33
actionadmin_enqueue_scriptscore\common\class-admin.php:36
actionadmin_enqueue_scriptscore\common\class-admin.php:37
actionadmin_initcore\common\class-admin.php:38
actionadmin_noticescore\common\class-admin.php:39
actionwp_enqueue_scriptscore\common\class-frontend.php:12
actionwp_enqueue_scriptscore\common\class-frontend.php:13
actionplugins_loadedcore\common\managers\class-language-manager.php:21
filterthe_editorcore\models\class-editor-option.php:19
Maintenance & Trust

WP Optin Wheel – Gamified Optin Email Marketing Tool for WordPress and WooCommerce Maintenance & Trust

Maintenance Signals

WordPress version tested6.9.4
Last updatedDec 11, 2025
PHP min version5.6
Downloads130K

Community Trust

Rating98/100
Number of ratings81
Active installs1K
Developer Profile

WP Optin Wheel – Gamified Optin Email Marketing Tool for WordPress and WooCommerce Developer Profile

Wombat Plugins

4 plugins · 61K total installs

78
trust score
Avg Security Score
99/100
Avg Patch Time
192 days
View full developer profile
Detection Fingerprints

How We Detect WP Optin Wheel – Gamified Optin Email Marketing Tool for WordPress and WooCommerce

Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.

Asset Fingerprints

Asset Paths
/wp-content/plugins/wp-optin-wheel/public/js/public.min.js/wp-content/plugins/wp-optin-wheel/public/css/public.min.css/wp-content/plugins/wp-optin-wheel/public/css/theme-vintage.css/wp-content/plugins/wp-optin-wheel/public/css/theme-deep-purple.css/wp-content/plugins/wp-optin-wheel/public/css/theme-yellow.css/wp-content/plugins/wp-optin-wheel/public/css/theme-red.css/wp-content/plugins/wp-optin-wheel/public/css/theme-orange.css/wp-content/plugins/wp-optin-wheel/public/css/theme-purple.css+1 more
Script Paths
/wp-content/plugins/wp-optin-wheel/public/js/public.min.js
Version Parameters
wp-optin-wheel/public/js/public.min.js?ver=wp-optin-wheel/public/css/public.min.css?ver=wp-optin-wheel/public/css/theme-vintage.css?ver=wp-optin-wheel/public/css/theme-deep-purple.css?ver=wp-optin-wheel/public/css/theme-yellow.css?ver=wp-optin-wheel/public/css/theme-red.css?ver=wp-optin-wheel/public/css/theme-orange.css?ver=wp-optin-wheel/public/css/theme-purple.css?ver=wp-optin-wheel/public/css/theme-green.css?ver=

HTML / DOM Fingerprints

CSS Classes
wof-wheels
HTML Comments
Exclude from WP Rocket's "Automatic Lazy Rendering" feature as that gives problems.
Data Attributes
data-wof-iddata-wof-themedata-wof-winning-titledata-wof-winning-textdata-wof-losing-titledata-wof-losing-text+7 more
JS Globals
wofVars
REST Endpoints
/wp-json/wof-lite/v1/add-email-to-list/wp-json/wof-lite/v1/play
FAQ

Frequently Asked Questions about WP Optin Wheel – Gamified Optin Email Marketing Tool for WordPress and WooCommerce