Corona Test Results Security & Risk Analysis

wordpress.org/plugins/corona-test-results

🦠 Management of Corona/COVID-19 test results with online check for the tested patients/citizens. Make the quick smear test procedure easier for both y …

10 active installs v1.11.6 PHP 5.6.40+ WP 4.8+ Updated Unknown
corona-viruscovid-19onlineabfragetest-resultstestergebnisse
100
A · Safe
CVEs total0
Unpatched0
Last CVENever
Safety Verdict

Is Corona Test Results Safe to Use in 2026?

Generally Safe

Score 100/100

Corona Test Results has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.

No known CVEs
Risk Assessment

The "corona-test-results" plugin v1.11.6 presents a mixed security posture. While it demonstrates some good practices, such as a high percentage of prepared SQL statements and a reasonable number of capability checks, there are significant areas of concern. The plugin has a considerable attack surface with 5 unprotected AJAX handlers, which is a primary vector for potential exploits. Furthermore, the taint analysis revealed 2 high-severity flows with unsanitized paths, indicating potential vulnerabilities where user-supplied data could be mishandled, leading to security breaches. The absence of any recorded past vulnerabilities might suggest a lack of historical targeting or a recent focus on security, but it does not negate the present risks identified in the static and taint analysis. Overall, while the plugin avoids some common pitfalls, the unprotected entry points and critical taint flows represent immediate security risks that require attention to improve its overall security posture.

Key Concerns

  • Unprotected AJAX handlers
  • High severity taint flows
  • Low output escaping percentage
  • Unsanitized paths in taint flows
Vulnerabilities
None known

Corona Test Results Security Vulnerabilities

No known vulnerabilities — this is a good sign.
Code Analysis
Analyzed Mar 16, 2026

Corona Test Results Code Analysis

Dangerous Functions
0
Raw SQL Queries
3
22 prepared
Unescaped Output
176
130 escaped
Nonce Checks
3
Capability Checks
20
File Operations
3
External Requests
1
Bundled Libraries
0

SQL Query Safety

88% prepared25 total queries

Output Escaping

42% escaped306 total outputs
Data Flows
4 unsanitized

Data Flow Analysis

10 flows4 with unsanitized paths
corona_test_results_settings_page (corona-test-results-admin-settings-general.php:428)
Source (user input) Sink (dangerous op) Sanitizer Transform Unsanitized Sanitized
Attack Surface
5 unprotected

Corona Test Results Attack Surface

Entry Points8
Unprotected5

AJAX Handlers 5

authwp_ajax_corona_test_results_ajax_update_codedatacorona-test-results-admin.php:463
authwp_ajax_corona_test_results_ajax_getcodecorona-test-results-admin.php:1846
authwp_ajax_corona_test_results_ajax_send_certificatecorona-test-results-admin.php:1912
authwp_ajax_corona_test_results_fetch_rowscorona-test-results-admin.php:1968
authwp_ajax_corona_test_results_dismiss_noticecorona-test-results-admin.php:1977

Shortcodes 3

[testresults_errors] corona-test-results-shortcodes.php:57
[testresults_form] corona-test-results-shortcodes.php:150
[testresults_code] corona-test-results-shortcodes.php:228
WordPress Hooks 19
actionadmin_menucorona-test-results-admin-settings-general.php:45
filteruser_has_capcorona-test-results-admin-settings-general.php:368
actionadmin_initcorona-test-results-admin-settings-general.php:372
actionload-options.phpcorona-test-results-admin-settings-general.php:373
actionadmin_enqueue_scriptscorona-test-results-admin-settings-general.php:576
actionadmin_initcorona-test-results-admin-settings.php:224
filterdisplay_post_statescorona-test-results-admin-settings.php:1388
actionadmin_enqueue_scriptscorona-test-results-admin.php:107
actionadmin_menucorona-test-results-admin.php:109
actionadmin_post_corona_test_results_assigncorona-test-results-admin.php:1198
filterphpmailer_initcorona-test-results-admin.php:1881
filterwp_mail_from_namecorona-test-results-admin.php:1892
filterplugin_row_metacorona-test-results-admin.php:2015
filterplugin_row_metacorona-test-results-admin.php:2040
filteruser_has_capcorona-test-results-global.php:138
filterwp_mail_from_namecorona-test-results-global.php:321
filterposts_resultscorona-test-results-shortcodes.php:303
actionupgrader_process_completecorona-test-results.php:48
actioninitcorona-test-results.php:95
Maintenance & Trust

Corona Test Results Maintenance & Trust

Maintenance Signals

WordPress version tested5.9.0
Last updatedUnknown
PHP min version5.6.40
Downloads4K

Community Trust

Rating100/100
Number of ratings4
Active installs10
Developer Profile

Corona Test Results Developer Profile

48DESIGN

2 plugins · 110 total installs

91
trust score
Avg Security Score
96/100
Avg Patch Time
30 days
View full developer profile
Detection Fingerprints

How We Detect Corona Test Results

Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.

Asset Fingerprints

Asset Paths
/wp-content/plugins/corona-test-results/css/style.css/wp-content/plugins/corona-test-results/css/admin-style.css/wp-content/plugins/corona-test-results/js/corona-test-results.js/wp-content/plugins/corona-test-results/js/qrcode.js/wp-content/plugins/corona-test-results/js/admin.js
Script Paths
/wp-content/plugins/corona-test-results/js/corona-test-results.js/wp-content/plugins/corona-test-results/js/qrcode.js/wp-content/plugins/corona-test-results/js/admin.js
Version Parameters
corona-test-results/css/style.css?ver=corona-test-results/css/admin-style.css?ver=corona-test-results/js/corona-test-results.js?ver=corona-test-results/js/qrcode.js?ver=corona-test-results/js/admin.js?ver=

HTML / DOM Fingerprints

CSS Classes
corona-test-results-registration-formcorona-test-results-qr-code-containercorona-test-results-result-containercorona-test-results-admin-formcorona-test-results-settings-page
HTML Comments
<!-- When the premium version is installed, deactivate and remove the free version --><!-- init --><!-- i18n --><!-- admin -->+2 more
Data Attributes
data-corona-test-results-ajax-urldata-corona-test-results-noncedata-corona-test-results-redirect-urldata-corona-test-results-form-id
JS Globals
corona_test_results_ajax_urlcorona_test_results_noncecorona_test_results_admin_settingscorona_test_results_cfg
REST Endpoints
/wp-json/corona-test-results/v1/register/wp-json/corona-test-results/v1/result
Shortcode Output
[corona_test_results_registration][corona_test_results_result_lookup][corona_test_results_qrcode]
FAQ

Frequently Asked Questions about Corona Test Results