
Zuta Lucky Wheel Security & Risk Analysis
wordpress.org/plugins/zuta-lucky-wheelTurn visitors into subscribers with a professional, realistic Lucky Wheel popup. Capture leads and boost engagement with gamification.
Is Zuta Lucky Wheel Safe to Use in 2026?
Generally Safe
Score 100/100Zuta Lucky Wheel has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.
The zuta-lucky-wheel plugin version 1.0.0 exhibits a mixed security posture. On the positive side, the plugin demonstrates good practices by utilizing prepared statements for all SQL queries and properly escaping all output, which significantly mitigates common web vulnerabilities. It also shows an absence of known CVEs and a history free of past vulnerabilities, suggesting a generally secure development approach. However, there are notable concerns related to its attack surface and taint analysis. The presence of two AJAX handlers without authentication checks presents a direct avenue for potential unauthorized actions if these handlers are not inherently protected by WordPress's internal capabilities or other means not evident in the provided data. Furthermore, the taint analysis revealed three flows with unsanitized paths, identified as high severity. While not classified as critical, these high-severity unsanitized paths, particularly when combined with unprotected entry points, represent a significant risk that could lead to various exploits if not addressed.
Key Concerns
- AJAX handlers without auth checks
- High severity unsanitized paths
Zuta Lucky Wheel Security Vulnerabilities
Zuta Lucky Wheel Release Timeline
Zuta Lucky Wheel Code Analysis
SQL Query Safety
Output Escaping
Data Flow Analysis
Zuta Lucky Wheel Attack Surface
AJAX Handlers 11
Shortcodes 1
WordPress Hooks 10
Maintenance & Trust
Zuta Lucky Wheel Maintenance & Trust
Maintenance Signals
Community Trust
Zuta Lucky Wheel Alternatives
WebToffee eCommerce Marketing Automation – Email marketing, Popups, Email customizer
decorator-woocommerce-email-customizer
Create and send marketing emails and campaigns. Enable email automations, Popups, spin-a-wheel, sign-up forms, and more. Customize WooCommerce emails.
Hello Bar Popup Builder: Design Engaging Popups on WordPress
hellobar
Easily add a Popup to your WordPress site with the official HelloBar WordPress plugin.
WP Live Social-Proof
wp-real-time-social-proof
The best animated, live, social-proof plugin for WooCommerce, Easy Digital Downloads or webinars and subscriptions to compel buyer action.
Useinfluence
useinfluence
UseInfluence uses 'Social Proof Notifications' to give a conversion BOOST to your website's traffic. Our realtime notifications puts a …
Splash Popup for WooCommerce
splash-popup-for-woocommerce
If you want to show welcome messages, links, or promos, Splash Popup for WooCommerce is a simple way to boost engagement.
Zuta Lucky Wheel Developer Profile
1 plugin · 0 total installs
How We Detect Zuta Lucky Wheel
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/zuta-lucky-wheel/assets/css/style.css/wp-content/plugins/zuta-lucky-wheel/assets/js/wheel.js/wp-content/plugins/zuta-lucky-wheel/assets/js/wheel-admin.js/wp-content/plugins/zuta-lucky-wheel/assets/js/vue.js/wp-content/plugins/zuta-lucky-wheel/assets/js/vue-resource.js/wp-content/plugins/zuta-lucky-wheel/assets/js/wheel.js/wp-content/plugins/zuta-lucky-wheel/assets/js/wheel-admin.js/wp-content/plugins/zuta-lucky-wheel/assets/js/vue.js/wp-content/plugins/zuta-lucky-wheel/assets/js/vue-resource.jszuta-lucky-wheel/assets/css/style.css?ver=zuta-lucky-wheel/assets/js/wheel.js?ver=zuta-lucky-wheel/assets/js/wheel-admin.js?ver=zuta-lucky-wheel/assets/js/vue.js?ver=zuta-lucky-wheel/assets/js/vue-resource.js?ver=HTML / DOM Fingerprints
lucky-wheel-canvaszuta-lucky-wheel-container<!-- Lucky Wheel Shortcode --><!-- zuta-lucky-wheel admin page --><!-- Lucky Wheel Settings --><!-- Design Setup -->+6 moredata-wheel-iddata-spin-targetdata-wheel-configdata-wheel-optionsdata-wheel-dataZUTALW_DATAZUTALW_OPTIONSZUTALW_CONFIGZUTALW_WHEEL_DATAZUTALW_WHEEL_IDZUTALW_SPIN_TARGET+3 more/wp-json/zuta-lucky-wheel/v1/spin/wp-json/zuta-lucky-wheel/v1/save-config/wp-json/zuta-lucky-wheel/v1/get-config[zuta_lucky_wheel<div class="zuta-lucky-wheel-container"><div id="lucky-wheel-canvas"></div>