Corona Virus Data Security & Risk Analysis

wordpress.org/plugins/corona-virus-data

This plugin displays the Coronavirus case data through shortcodes [cov2019] [cov2019all] or [cov2019map] in your WordPress post or page.

1K active installs v1.4.3 PHP 7.2+ WP 3.0.1+ Updated May 22, 2024
corona-viruscoronaviruscovid-19ncov19%e5%86%a0%e7%8a%b6%e7%97%85%e6%af%92
92
A · Safe
CVEs total0
Unpatched0
Last CVENever
Safety Verdict

Is Corona Virus Data Safe to Use in 2026?

Generally Safe

Score 92/100

Corona Virus Data has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.

No known CVEs Updated 1yr ago
Risk Assessment

The 'corona-virus-data' plugin v1.4.3 exhibits a generally good security posture with no reported vulnerabilities or critical security findings in the static analysis.

The code analysis reveals a clean slate regarding dangerous functions, SQL injection, file operations, and external requests, all of which are positive indicators.

However, a significant concern arises from the lack of proper output escaping, with only 36% of identified outputs being correctly sanitized. This leaves a substantial portion of data displayed to users potentially vulnerable to cross-site scripting (XSS) attacks, especially when considering the 12 shortcodes which serve as entry points. While there are no direct indications of unsanitized taint flows or unprotected entry points in the provided data, the insufficient output escaping is a critical weakness that needs immediate attention. The absence of any historical vulnerabilities might suggest good development practices or simply a lack of prior scrutiny. Nevertheless, the current state points to a plugin that has strengths in many areas but is notably weak in output sanitization, presenting a moderate risk.

Key Concerns

  • Low output escaping percentage
Vulnerabilities
None known

Corona Virus Data Security Vulnerabilities

No known vulnerabilities — this is a good sign.
Code Analysis
Analyzed Mar 16, 2026

Corona Virus Data Code Analysis

Dangerous Functions
0
Raw SQL Queries
0
0 prepared
Unescaped Output
7
4 escaped
Nonce Checks
0
Capability Checks
0
File Operations
0
External Requests
0
Bundled Libraries
0

Output Escaping

36% escaped11 total outputs
Attack Surface

Corona Virus Data Attack Surface

Entry Points12
Unprotected0

Shortcodes 12

[cov2019] includes\class-corona-virus-data.php:241
[cov2019contry] includes\class-corona-virus-data.php:261
[cov2019all] includes\class-corona-virus-data.php:275
[cov2019map] includes\class-corona-virus-data.php:290
[cov2019history] includes\class-corona-virus-data.php:303
[cov2019historyc] includes\class-corona-virus-data.php:316
[cov2019namerica] includes\class-corona-virus-data.php:336
[cov2019samerica] includes\class-corona-virus-data.php:356
[cov2019europe] includes\class-corona-virus-data.php:376
[cov2019asia] includes\class-corona-virus-data.php:396
[cov2019oceania] includes\class-corona-virus-data.php:416
[cov2019africa] includes\class-corona-virus-data.php:436
WordPress Hooks 8
actionadmin_menuadmin\class-corona-virus-data-admin.php:92
actionadmin_initadmin\class-corona-virus-data-admin.php:93
actionplugins_loadedincludes\class-corona-virus-data.php:128
actionadmin_enqueue_scriptsincludes\class-corona-virus-data.php:140
actionadmin_enqueue_scriptsincludes\class-corona-virus-data.php:141
actionwp_enqueue_scriptsincludes\class-corona-virus-data.php:153
actionwp_enqueue_scriptsincludes\class-corona-virus-data.php:154
actionwp_headincludes\class-corona-virus-data.php:219
Maintenance & Trust

Corona Virus Data Maintenance & Trust

Maintenance Signals

WordPress version tested6.6.5
Last updatedMay 22, 2024
PHP min version7.2
Downloads69K

Community Trust

Rating94/100
Number of ratings13
Active installs1K
Developer Profile

Corona Virus Data Developer Profile

Duke Yin

1 plugin · 1K total installs

88
trust score
Avg Security Score
92/100
Avg Patch Time
30 days
View full developer profile
Detection Fingerprints

How We Detect Corona Virus Data

Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.

Asset Fingerprints

Asset Paths
/wp-content/plugins/corona-virus-data/css/corona-virus-data-admin.css/wp-content/plugins/corona-virus-data/js/corona-virus-data-admin.js/wp-content/plugins/corona-virus-data/js/corona-virus-data.js
Script Paths
/wp-content/plugins/corona-virus-data/js/corona-virus-data.js
Version Parameters
corona-virus-data/css/corona-virus-data-admin.css?ver=corona-virus-data/js/corona-virus-data-admin.js?ver=corona-virus-data/js/corona-virus-data.js?ver=

HTML / DOM Fingerprints

CSS Classes
cov2019-data-table
HTML Comments
<!-- Corona Virus Data Widget Start --><!-- Corona Virus Data Widget End --><!-- Corona Virus Data All Data Widget Start --><!-- Corona Virus Data All Data Widget End -->
Data Attributes
data-map-token
JS Globals
corona_virus_data_object
Shortcode Output
[cov2019][cov2019all]
FAQ

Frequently Asked Questions about Corona Virus Data