Corona Stats Live – Corona Virus COVID-19 Live Stats for WordPress Lite Security & Risk Analysis

wordpress.org/plugins/corona-stats-live

Corona Stats Live - is a WordPress plugin exclusively developed to provide upto date corona virus stats. You can take full advantage of this plugin to …

10 active installs v1.2.0 PHP + WP 3.0.0+ Updated Jun 4, 2020
corona-viruscorona-virus-livecorona-virus-live-trackerscovid-19-live-statscovid19
85
A · Safe
CVEs total0
Unpatched0
Last CVENever
Safety Verdict

Is Corona Stats Live – Corona Virus COVID-19 Live Stats for WordPress Lite Safe to Use in 2026?

Generally Safe

Score 85/100

Corona Stats Live – Corona Virus COVID-19 Live Stats for WordPress Lite has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.

No known CVEs Updated 5yr ago
Risk Assessment

The "corona-stats-live" plugin v1.2.0 exhibits a generally positive security posture based on the static analysis. It shows no known vulnerabilities (CVEs), which is a significant strength. The absence of dangerous functions, raw SQL queries, file operations, and external HTTP requests (though it makes two, their nature isn't specified but assumed benign given no taint analysis findings) are also good indicators. The plugin also utilizes prepared statements for its SQL queries, which is a best practice for preventing SQL injection. However, there are areas of concern. A significant portion (31%) of output escaping is missing, which could lead to Cross-Site Scripting (XSS) vulnerabilities if the plugin handles user-supplied data that is then displayed without proper sanitization. The lack of nonce checks and capability checks across all entry points (AJAX, REST API, shortcodes) is a notable weakness, potentially allowing unauthorized actions if the plugin's functionalities are exploitable. The bundled DataTables library, while common, should be kept updated to prevent known vulnerabilities within the library itself.

Key Concerns

  • Missing output escaping
  • Missing nonce checks on entry points
  • Missing capability checks on entry points
  • Bundled potentially outdated library (DataTables)
Vulnerabilities
None known

Corona Stats Live – Corona Virus COVID-19 Live Stats for WordPress Lite Security Vulnerabilities

No known vulnerabilities — this is a good sign.
Code Analysis
Analyzed Mar 17, 2026

Corona Stats Live – Corona Virus COVID-19 Live Stats for WordPress Lite Code Analysis

Dangerous Functions
0
Raw SQL Queries
0
0 prepared
Unescaped Output
31
70 escaped
Nonce Checks
0
Capability Checks
0
File Operations
0
External Requests
2
Bundled Libraries
1

Bundled Libraries

DataTables

Output Escaping

69% escaped101 total outputs
Attack Surface

Corona Stats Live – Corona Virus COVID-19 Live Stats for WordPress Lite Attack Surface

Entry Points7
Unprotected0

Shortcodes 7

[csl_covid_table] csl-corona-stats.php:48
[csl_covid_stats] csl-corona-stats.php:49
[csl_covid_widget] csl-corona-stats.php:50
[csl_covid_sidebar] csl-corona-stats.php:51
[csl_covid_topten] csl-corona-stats.php:52
[csl_covid_chart] csl-corona-stats.php:53
[csl_covid_donutchart] csl-corona-stats.php:54
WordPress Hooks 3
actionwp_enqueue_scriptscsl-corona-stats.php:55
actionwp_enqueue_scriptscsl-corona-stats.php:56
actionplugins_loadedcsl-corona-stats.php:57
Maintenance & Trust

Corona Stats Live – Corona Virus COVID-19 Live Stats for WordPress Lite Maintenance & Trust

Maintenance Signals

WordPress version tested5.4.19
Last updatedJun 4, 2020
PHP min version
Downloads2K

Community Trust

Rating100/100
Number of ratings3
Active installs10
Developer Profile

Corona Stats Live – Corona Virus COVID-19 Live Stats for WordPress Lite Developer Profile

Hafeez Ansari

1 plugin · 10 total installs

84
trust score
Avg Security Score
85/100
Avg Patch Time
30 days
View full developer profile
Detection Fingerprints

How We Detect Corona Stats Live – Corona Virus COVID-19 Live Stats for WordPress Lite

Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.

Asset Fingerprints

Asset Paths
/wp-content/plugins/corona-stats-live/css/bootstrap.min.css/wp-content/plugins/corona-stats-live/css/Chart.min.css/wp-content/plugins/corona-stats-live/css/jquery.dataTables.css/wp-content/plugins/corona-stats-live/css/csl-styles.css/wp-content/plugins/corona-stats-live/js/Chart.min.js/wp-content/plugins/corona-stats-live/js/jquery.dataTables.js/wp-content/plugins/corona-stats-live/js/Chart.bundle.js/wp-content/plugins/corona-stats-live/js/utils.js+1 more
Script Paths
/wp-content/plugins/corona-stats-live/js/Chart.min.js/wp-content/plugins/corona-stats-live/js/jquery.dataTables.js/wp-content/plugins/corona-stats-live/js/Chart.bundle.js/wp-content/plugins/corona-stats-live/js/utils.js/wp-content/plugins/corona-stats-live/js/csl-custom.js
Version Parameters
corona-stats-live/css/bootstrap.min.css?ver=corona-stats-live/css/Chart.min.css?ver=corona-stats-live/css/jquery.dataTables.css?ver=corona-stats-live/css/csl-styles.css?ver=corona-stats-live/js/Chart.min.js?ver=corona-stats-live/js/jquery.dataTables.js?ver=corona-stats-live/js/Chart.bundle.js?ver=corona-stats-live/js/utils.js?ver=corona-stats-live/js/csl-custom.js?ver=

HTML / DOM Fingerprints

Shortcode Output
[csl_covid_table][csl_covid_stats][csl_covid_widget][csl_covid_sidebar]
FAQ

Frequently Asked Questions about Corona Stats Live – Corona Virus COVID-19 Live Stats for WordPress Lite