Corona Update Security & Risk Analysis

wordpress.org/plugins/corona-update

Corona Update WordPress Plugin to show corona current cases and more information about COVID-19. You will be able to show the relevant information: ca …

30 active installs v1.6.0 PHP 5.6+ WP 5.1+ Updated Aug 23, 2021
coronacoronaviruscovid-19live-updatestatistic
85
A · Safe
CVEs total0
Unpatched0
Last CVENever
Safety Verdict

Is Corona Update Safe to Use in 2026?

Generally Safe

Score 85/100

Corona Update has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.

No known CVEs Updated 4yr ago
Risk Assessment

The "corona-update" v1.6.0 plugin exhibits a generally positive security posture based on the provided static analysis. The absence of any known CVEs and the fact that all SQL queries utilize prepared statements are strong indicators of good development practices. Furthermore, the plugin doesn't appear to make external HTTP requests or perform file operations, which are common vectors for vulnerabilities. The limited attack surface, with only two shortcodes and no unprotected entry points, also contributes to a lower risk profile. The high percentage of properly escaped output is another positive sign, mitigating potential cross-site scripting (XSS) risks.

However, a few areas warrant attention. The lack of nonce checks and capability checks across its entry points is a significant concern. While the static analysis reports no unprotected AJAX handlers or REST API routes, the absence of these fundamental security measures means that if any such handlers or routes were to be introduced in future versions or through misconfiguration, they would be immediately vulnerable to unauthorized actions or privilege escalation. The single file operation, though not explicitly flagged as dangerous, could represent a potential risk if not handled with utmost care, especially if it involves user-supplied input.

In conclusion, "corona-update" v1.6.0 has a relatively strong security foundation, particularly in its SQL handling and the absence of known vulnerabilities. The primary weakness lies in the missing nonce and capability checks, which, while not currently exploited, represent a latent risk that could be easily triggered. The plugin development has generally followed secure coding principles for SQL and output escaping, but the oversight in authentication and authorization checks for its entry points suggests room for improvement to achieve a truly robust security posture.

Key Concerns

  • Missing nonce checks
  • Missing capability checks
  • Presence of file operations
Vulnerabilities
None known

Corona Update Security Vulnerabilities

No known vulnerabilities — this is a good sign.
Code Analysis
Analyzed Mar 16, 2026

Corona Update Code Analysis

Dangerous Functions
0
Raw SQL Queries
0
0 prepared
Unescaped Output
22
146 escaped
Nonce Checks
0
Capability Checks
0
File Operations
1
External Requests
0
Bundled Libraries
0

Output Escaping

87% escaped168 total outputs
Attack Surface

Corona Update Attack Surface

Entry Points2
Unprotected0

Shortcodes 2

[corona_statistic] inc\statistic-shortcode.php:20
[corona_statistic_together] inc\statistic-shortcode.php:21
WordPress Hooks 8
actionadmin_menuadmin\inc\admin-menu.php:20
actionadmin_initadmin\inc\admin-menu.php:21
filtercoronaupdate_get_settings_optadmin\settings-fields\fields.php:53
actionadmin_enqueue_scriptsadmin\settings-fields\fields.php:55
actionwp_enqueue_scriptscorona-update.php:81
actioninitcorona-update.php:90
actionwp_footerinc\awareness-popup.php:26
actionwidgets_initinc\statistic-widget.php:104
Maintenance & Trust

Corona Update Maintenance & Trust

Maintenance Signals

WordPress version tested5.6.17
Last updatedAug 23, 2021
PHP min version5.6
Downloads9K

Community Trust

Rating100/100
Number of ratings2
Active installs30
Developer Profile

Corona Update Developer Profile

themelooks

11 plugins · 3K total installs

91
trust score
Avg Security Score
96/100
Avg Patch Time
20 days
View full developer profile
Detection Fingerprints

How We Detect Corona Update

Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.

Asset Fingerprints

Asset Paths
/wp-content/plugins/corona-update/assets/css/style.css/wp-content/plugins/corona-update/assets/js/script.js/wp-content/plugins/corona-update/admin/assets/css/font-awesome.min.css/wp-content/plugins/corona-update/admin/assets/css/fields.css/wp-content/plugins/corona-update/admin/assets/js/fields.js
Script Paths
/wp-content/plugins/corona-update/assets/js/script.js
Version Parameters
coronaupdate-style?ver=coronaupdate-script?ver=font-awesome?ver=coronaupdate-settings-field?ver=coronaupdate-settings-field?ver=

HTML / DOM Fingerprints

CSS Classes
awareness-popup-wrapper
HTML Comments
<!--
Data Attributes
style="background-color:style="color:style="color:
FAQ

Frequently Asked Questions about Corona Update