Corona Bangladesh Live Security & Risk Analysis

wordpress.org/plugins/covid-19-bangladesh-live

Corona Bangladesh Live is a plugin where you can get all update of Bangladesh & all over the world.

30 active installs v1.6.0 PHP 7.4+ WP 6.1+ Updated Feb 25, 2025
coronacorona-bangladeshcorona-bangladesh-livecovid-19covid-19-bd
92
A · Safe
CVEs total0
Unpatched0
Last CVENever
Safety Verdict

Is Corona Bangladesh Live Safe to Use in 2026?

Generally Safe

Score 92/100

Corona Bangladesh Live has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.

No known CVEs Updated 1yr ago
Risk Assessment

The 'covid-19-bangladesh-live' plugin v1.6.0 exhibits a mixed security posture. On the positive side, there are no known CVEs associated with this plugin, and the static analysis shows no dangerous functions, no direct SQL queries (all are prepared), and no identified taint flows with unsanitized paths. This suggests a generally good coding practice regarding core security principles.

However, significant concerns arise from the lack of input sanitization and authorization checks. The static analysis reveals a complete absence of nonce checks and capability checks. Coupled with the fact that 15% of outputs are not properly escaped, this presents a considerable risk of Cross-Site Scripting (XSS) and potential privilege escalation or unauthorized data manipulation if any of the identified entry points (shortcodes) are exploited. The presence of file operations and external HTTP requests also increases the potential attack surface if these actions are not properly secured against malicious input.

Overall, while the plugin avoids common pitfalls like unpatched vulnerabilities and raw SQL, the lack of fundamental security checks on its entry points is a serious weakness. The absence of any recorded vulnerabilities in its history might suggest it hasn't been a target or that previous issues were not publicly disclosed, but this does not mitigate the identified risks in the current version.

Key Concerns

  • Missing Nonce Checks
  • Missing Capability Checks
  • Insufficient Output Escaping
  • File operations present
  • External HTTP requests present
Vulnerabilities
None known

Corona Bangladesh Live Security Vulnerabilities

No known vulnerabilities — this is a good sign.
Version History

Corona Bangladesh Live Release Timeline

v1.1.0
v1.0.2
Code Analysis
Analyzed Mar 16, 2026

Corona Bangladesh Live Code Analysis

Dangerous Functions
0
Raw SQL Queries
0
0 prepared
Unescaped Output
52
9 escaped
Nonce Checks
0
Capability Checks
0
File Operations
6
External Requests
3
Bundled Libraries
0

Output Escaping

15% escaped61 total outputs
Attack Surface

Corona Bangladesh Live Attack Surface

Entry Points3
Unprotected0

Shortcodes 3

[cbdl_widget_1] shortcode.php:3
[cbdl_widget_2] shortcode.php:4
[cbdl_widget_3] shortcode.php:5
WordPress Hooks 2
actionwp_enqueue_scriptscovid-19-bd-live.php:55
actionwidgets_initcovid-19-bd-live.php:63
Maintenance & Trust

Corona Bangladesh Live Maintenance & Trust

Maintenance Signals

WordPress version tested6.7.5
Last updatedFeb 25, 2025
PHP min version7.4
Downloads9K

Community Trust

Rating100/100
Number of ratings2
Active installs30
Developer Profile

Corona Bangladesh Live Developer Profile

Amdadul Haq

2 plugins · 40 total installs

88
trust score
Avg Security Score
92/100
Avg Patch Time
30 days
View full developer profile
Detection Fingerprints

How We Detect Corona Bangladesh Live

Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.

Asset Fingerprints

Asset Paths
/wp-content/plugins/covid-19-bangladesh-live/public/css/SolaimanLipi.min.css/wp-content/plugins/covid-19-bangladesh-live/public/css/widget1.min.css/wp-content/plugins/covid-19-bangladesh-live/public/css/widget2.min.css/wp-content/plugins/covid-19-bangladesh-live/public/css/widget3.min.css/wp-content/plugins/covid-19-bangladesh-live/public/js/widget.min.js
Script Paths
/wp-content/plugins/covid-19-bangladesh-live/public/js/widget.min.js

HTML / DOM Fingerprints

CSS Classes
statistics_bdbody_bdbody_worldsutrostatistics_world
JS Globals
cbdl_enToBncbdl_getBNStatsDatacbdl_getBNDistrictsDatacbdl_getWorldData
Shortcode Output
<div class="statistics_bd"><div class="body body_bd"><div class="content"><div class="text">আক্রান্ত</div>
FAQ

Frequently Asked Questions about Corona Bangladesh Live