South African COVID19 Banner Security & Risk Analysis

wordpress.org/plugins/corona-virus-covid19-banner

Comply with new South African Covid-19 regulations requiring all websites ending in .ZA to show a link to the official government page.

60 active installs v0.4.6 PHP + WP 3.0.1+ Updated Jun 15, 2020
corona-viruscoronaviruscovid-19covid19
85
A · Safe
CVEs total0
Unpatched0
Last CVENever
Safety Verdict

Is South African COVID19 Banner Safe to Use in 2026?

Generally Safe

Score 85/100

South African COVID19 Banner has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.

No known CVEs Updated 5yr ago
Risk Assessment

The plugin 'corona-virus-covid19-banner' version 0.4.6 exhibits a strong security posture based on the provided static analysis. There are no identified entry points such as AJAX handlers, REST API routes, shortcodes, or cron events that are accessible to attackers, and importantly, none of these potential entry points are unprotected. The code also demonstrates good practices by avoiding dangerous functions, performing all SQL queries using prepared statements, and with a very high percentage (91%) of output properly escaped. The absence of file operations and external HTTP requests further minimizes the attack surface. Taint analysis shows no identified flows with unsanitized paths, indicating no direct vulnerabilities related to data manipulation originating from user input.

The vulnerability history is also clean, with no recorded CVEs of any severity. This, combined with the static analysis findings, suggests that the developers have a good understanding of secure coding practices. However, it is important to note the absence of nonce checks and capability checks. While the limited attack surface mitigates the immediate risk, if any entry points were to be introduced in future versions or discovered, the lack of these fundamental WordPress security mechanisms could become a concern.

Overall, the plugin appears to be very secure in its current state. The lack of identified vulnerabilities and the robust static analysis findings are significant strengths. The only potential areas for improvement lie in the implementation of nonce and capability checks, which are standard security practices for WordPress plugins, especially as the plugin evolves.

Key Concerns

  • No nonce checks implemented
  • No capability checks implemented
Vulnerabilities
None known

South African COVID19 Banner Security Vulnerabilities

No known vulnerabilities — this is a good sign.
Code Analysis
Analyzed Mar 16, 2026

South African COVID19 Banner Code Analysis

Dangerous Functions
0
Raw SQL Queries
0
0 prepared
Unescaped Output
3
29 escaped
Nonce Checks
0
Capability Checks
0
File Operations
0
External Requests
0
Bundled Libraries
0

Output Escaping

91% escaped32 total outputs
Attack Surface

South African COVID19 Banner Attack Surface

Entry Points0
Unprotected0
WordPress Hooks 4
actionwp_enqueue_scriptscorona-virus-covid19-banner.php:17
actionwp_headcorona-virus-covid19-banner.php:50
actionadmin_menucorona-virus-covid19-banner.php:88
actionadmin_initcorona-virus-covid19-banner.php:98
Maintenance & Trust

South African COVID19 Banner Maintenance & Trust

Maintenance Signals

WordPress version tested5.4.19
Last updatedJun 15, 2020
PHP min version
Downloads4K

Community Trust

Rating100/100
Number of ratings1
Active installs60
Developer Profile

South African COVID19 Banner Developer Profile

bridgementdevops

1 plugin · 60 total installs

84
trust score
Avg Security Score
85/100
Avg Patch Time
30 days
View full developer profile
Detection Fingerprints

How We Detect South African COVID19 Banner

Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.

Asset Fingerprints

Asset Paths
/wp-content/plugins/corona-virus-covid19-banner/corona-virus-covid19-banner.css/wp-content/plugins/corona-virus-covid19-banner/img/coat.png/wp-content/plugins/corona-virus-covid19-banner/corona-virus-covid19-banner.js
Script Paths
https://fonts.googleapis.com/css2?family=Roboto:wght@300&display=swap
Version Parameters
corona-virus-covid19-banner.css?ver=corona-virus-covid19-banner.js?ver=

HTML / DOM Fingerprints

CSS Classes
covid-bannercovid-textcovid-headercovid-bodycovid-footer
Data Attributes
data-covid-banner-options
JS Globals
scriptParams
FAQ

Frequently Asked Questions about South African COVID19 Banner