Lua is smaller, easier to embed interface / interact with (e.g. it's way less ceremony to expose a native function to Lua than to Python), and tends to be faster, especially when jumping back and forth between the engine and the scripting. Embedding / scripting (within a larger program) is the original use-case of Lua, not so Python.
I believe it's also much easier to secure / sandbox (remove bits you don't want script writers to have access to) as well, the stdlib is smaller and I think it has less interactions between modules.
Python embedding / scripting tends to be more common for software where the securing / restriction aspect is smaller but flexibility & larger embeds are necessary e.g. 3D, CAD and other "production pipeline" software tends to be scripted with Python.
Yes. C code that embeds the Lua VM has total control over which functions are exposed to the Lua code. It's possible to create a VM that, for example, has no access to the filesystem.
AFAIK it's not possible to do that if you embed Python. Dangerous functions like `open` are always available and sandboxing facilities have to try and prevent untrusted code from getting a reference to them. Unfortunately, there are numerous ways to work around these restrictions and obtain access to dangerous functions, e.g. via `__builtins__`.
Another reason running untrusted Lua code is considered fairly safe is that the VM is well-engineered and has a history of very few bugs [0]. However, the latest 5.4.0 release seems to have more bugs than older releases.
It might still possible for untrusted Lua code to use 100% CPU and hang a program, or to read data from the embedding process using a Spectre-style attack (although even that's unlikely because the Lua VM is an interpreter rather than a JIT compiler). However, it's quite possible to secure an embedded Lua VM to prevent it from doing things like accessing arbitrary files.
There's also luajit, but I don't know how common it is vs "just Lua". My impression was that luajit was used pretty often though.
Here are some benefits of Lua over Python. It's really powerful language (anonymous functions, closures, tail-call optimization, full lexical scoping, coroutines...) that supports many paradigms, and yet it is tiny and elegant. There are few surprises and everything is explicit.
Runtime is easily embeddable, which means it will be more readily available on exotic platforms. The interpreter is much faster than Python. C code is effortless to call into with FFI and resulting code looks just like normal Lua.
Not everything is roses. I prefer readability and less verbosity of Python. The 1-indexing needs some getting used to. Batteries are not included (to be more portable), so there are dozens of implementations of basic things like serialization, OO classes and table copying. Most online material (wiki) was written very long ago and it's full of language proposals that never succeeded. Some valuable resources can be found in documentation of hosting frameworks (Defold, Solar2D, Roblox, ComputerCraft, WoW).
Using Lua is generally done because it is easy to embed inside a host-application. While it is possible to embed Python, Perl, or other languages, they're relatively heavyweight and not so commonly used in that case.
In my own application I always felt annoyed that mutt didn't have "real" scripting. Just an ad-hoc configuration that made lots of things possible, but neglected some basics (such as loops and similar).
Configuring a mail-client in Lua was a nice exercise, but eventually I moved on to pay for gsuite rather than self-hosting a mailserver of my own so it became a "done" project. Definitely a useful learning experience though, experimenting with user-interface, embedded scripting, and going through lots of learning relating to MIME-handling & etc.
https://github.com/lumail/lumail/
Honestly I'd probably write something in perl/go/similar to just walk over a remote IMAP mailbox:
* Search for messages that are unread, or which don't have a given tag.
* Process each one.
* Mark as read, or add a tag.
(I actually did something like that recently for processing DMARC reports.)
Python is a large, complex language with an exceedingly complicated data model built on a runtime where the core interpreter is about ~4 MB, which is also a pretty slow interpreter (mostly due to the exceedingly complicated data model). Python is certainly not hard to embed on an API level, but somewhat annoying to package up for a build. Python is very hard to sandbox, whereas Lua is basically sandboxed by default. Startup time is on the order of ~100-200 ms.
If I use Python instead of Lua to make a game, I will not be able to update my game state and render all my images at 60hz.
If I use Python instead of Lua to write programs that do many tasks at the same time, I will have to write "await" a thousand times instead of 0 times.
It’s simpler to connect lua to your c/c++ datastructures than it is to connect Python, and it’s more complicated to write little things in Python.
Sometimes it’s easier to grab a pencil and scribble a little note on a piece of paper. Sometimes it’s a lot more useful to type a note into your phone or computer than to deal with paper.
Example: Specialised handling for different customer types and you don't want to manage all the rules in the RDBMS but would rather run a separate script for each customer type and have this script in a plain text format and version managed using Git.