COVID19 – Coronavirus Outbreak Data Security & Risk Analysis

wordpress.org/plugins/ce-corona

Coronavirus disease (COVID-19) is an infectious disease caused by a new virus.

200 active installs v0.7.0 PHP 5.6+ WP 3.5+ Updated Aug 13, 2023
coronacoronaviruscovid19
85
A · Safe
CVEs total0
Unpatched0
Last CVENever
Safety Verdict

Is COVID19 – Coronavirus Outbreak Data Safe to Use in 2026?

Generally Safe

Score 85/100

COVID19 – Coronavirus Outbreak Data has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.

No known CVEs Updated 2yr ago
Risk Assessment

The "ce-corona" v0.7.0 plugin presents a generally positive security posture based on the provided static analysis. The absence of any known CVEs in its history, coupled with the lack of detected dangerous functions, raw SQL queries, or external HTTP requests, suggests a focus on secure coding practices. Furthermore, the plugin exhibits no detected taint flows, indicating that untrusted data is not being mishandled in ways that could lead to exploitation.

However, there are notable areas for improvement. The most significant concern is the low percentage of properly escaped output (25%). This means a substantial portion of dynamic content displayed to users may be vulnerable to Cross-Site Scripting (XSS) attacks, allowing an attacker to inject malicious scripts into web pages viewed by other users. Additionally, the complete absence of nonce and capability checks across all entry points (AJAX handlers, REST API routes, and shortcodes) is a critical weakness. This allows any authenticated user, regardless of their role or permissions, to potentially trigger plugin functionalities, opening the door to unauthorized actions or information disclosure.

While the vulnerability history is clean, this can sometimes indicate a lack of past scrutiny or a plugin that hasn't been extensively tested for vulnerabilities. The strengths lie in the foundation of avoiding common pitfalls like raw SQL and dangerous functions. The weaknesses, particularly the unescaped output and lack of authorization checks, represent significant security risks that need to be addressed to improve the plugin's overall security.

Key Concerns

  • Unescaped output detected
  • Missing nonce checks on all entry points
  • Missing capability checks on all entry points
Vulnerabilities
None known

COVID19 – Coronavirus Outbreak Data Security Vulnerabilities

No known vulnerabilities — this is a good sign.
Code Analysis
Analyzed Mar 16, 2026

COVID19 – Coronavirus Outbreak Data Code Analysis

Dangerous Functions
0
Raw SQL Queries
0
0 prepared
Unescaped Output
63
21 escaped
Nonce Checks
0
Capability Checks
0
File Operations
0
External Requests
0
Bundled Libraries
0

Output Escaping

25% escaped84 total outputs
Attack Surface

COVID19 – Coronavirus Outbreak Data Attack Surface

Entry Points3
Unprotected0

Shortcodes 3

[ce_corona] classes\admin\shortcode.php:15
[cec_corona] classes\admin\shortcode.php:16
[cec_graph] classes\admin\shortcode.php:17
WordPress Hooks 3
actionelementor/editor/before_enqueue_scriptsclasses\core\elementor.php:117
actionelementor/frontend/after_register_scriptsclasses\core\elementor.php:118
actionelementor/widgets/widgets_registeredclasses\core\elementor.php:121
Maintenance & Trust

COVID19 – Coronavirus Outbreak Data Maintenance & Trust

Maintenance Signals

WordPress version tested5.7.15
Last updatedAug 13, 2023
PHP min version5.6
Downloads24K

Community Trust

Rating100/100
Number of ratings16
Active installs200
Developer Profile

COVID19 – Coronavirus Outbreak Data Developer Profile

PriyoMukul

2 plugins · 210 total installs

84
trust score
Avg Security Score
85/100
Avg Patch Time
30 days
View full developer profile
Detection Fingerprints

How We Detect COVID19 – Coronavirus Outbreak Data

Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.

Asset Fingerprints

Asset Paths
/wp-content/plugins/ce-corona/assets/css/ce-corona-global.css/wp-content/plugins/ce-corona/assets/css/ce-corona-admin.css/wp-content/plugins/ce-corona/assets/css/corona-fonts.css/wp-content/plugins/ce-corona/assets/js/corona-admin.js/wp-content/plugins/ce-corona/assets/css/corona.css/wp-content/plugins/ce-corona/assets/css/corona-wp-widget.css/wp-content/plugins/ce-corona/assets/js/jquery-countTo.js/wp-content/plugins/ce-corona/assets/js/widget.js+6 more
Script Paths
/wp-content/plugins/ce-corona/assets/js/corona-admin.js/wp-content/plugins/ce-corona/assets/js/jquery-countTo.js/wp-content/plugins/ce-corona/assets/js/widget.js/wp-content/plugins/ce-corona/assets/js/corona.js/wp-content/plugins/ce-corona/assets/js/ce-numberformat.js/wp-content/plugins/ce-corona/assets/js/countrywise.js+1 more
Version Parameters
ce-corona/assets/css/ce-corona-global.css?ver=ce-corona/assets/css/ce-corona-admin.css?ver=ce-corona/assets/css/corona-fonts.css?ver=ce-corona/assets/js/corona-admin.js?ver=ce-corona/assets/css/corona.css?ver=ce-corona/assets/css/corona-wp-widget.css?ver=ce-corona/assets/js/jquery-countTo.js?ver=ce-corona/assets/js/widget.js?ver=ce-corona/assets/js/corona.js?ver=ce-corona/assets/css/corona-countrywise.css?ver=ce-corona/assets/js/ce-numberformat.js?ver=ce-corona/assets/js/countrywise.js?ver=ce-corona/assets/css/cegraph.css?ver=ce-corona/assets/js/cegraph.js?ver=

HTML / DOM Fingerprints

CSS Classes
ce-corona-widget
JS Globals
CeCoronaDataTable
FAQ

Frequently Asked Questions about COVID19 – Coronavirus Outbreak Data