COVID-19 Corona Virus Live Stats & Updates For WordPress Lite Security & Risk Analysis

wordpress.org/plugins/covid-19-corona-virus-live-stats-updates-lite

COVID-19 Corona Virus Live Stats & Updates is plugin for show update related to Corona Virus. This plugin have every thing you need related to Cor …

10 active installs v1.2 PHP + WP 3.0.0+ Updated Apr 23, 2020
corona-viruscorona-virus-livecorona-virus-live-trackerscovid19-live-stats
85
A · Safe
CVEs total0
Unpatched0
Last CVENever
Safety Verdict

Is COVID-19 Corona Virus Live Stats & Updates For WordPress Lite Safe to Use in 2026?

Generally Safe

Score 85/100

COVID-19 Corona Virus Live Stats & Updates For WordPress Lite has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.

No known CVEs Updated 6yr ago
Risk Assessment

The plugin "covid-19-corona-virus-live-stats-updates-lite" v1.2 exhibits a mixed security posture. On the positive side, there are no recorded vulnerabilities in its history, suggesting a generally stable and well-maintained codebase. The static analysis reveals a limited attack surface with no AJAX handlers, REST API routes, shortcodes, or cron events that are directly exposed. Furthermore, all SQL queries are executed using prepared statements, which is an excellent practice for preventing SQL injection. The code also demonstrates a strong emphasis on output escaping, with 82% of outputs being properly handled.

However, there are several areas that warrant concern. The taint analysis identified one flow with an unsanitized path, which, while not classified as critical or high severity in this specific instance, indicates a potential for insecure handling of data that could be manipulated. The complete lack of nonce checks and capability checks across all entry points (even though the entry points are zero) is a significant weakness. This means that if any new entry points were introduced or if the analysis missed some, there would be no built-in protection against unauthorized actions. Additionally, the plugin makes external HTTP requests, which could be exploited if not handled securely and can sometimes be vectors for introducing vulnerabilities.

Overall, the plugin has good practices regarding SQL and output sanitization and a clean vulnerability history. Nevertheless, the identified taint flow, the complete absence of nonce and capability checks, and the reliance on external HTTP requests present potential security risks that should be addressed. While the current lack of exploitable vulnerabilities is reassuring, the absence of fundamental security checks leaves room for future issues, especially if the plugin is updated or expanded upon.

Key Concerns

  • Taint flow with unsanitized path
  • No nonce checks found
  • No capability checks found
  • External HTTP requests present
  • Bundled library DataTables may be outdated
Vulnerabilities
None known

COVID-19 Corona Virus Live Stats & Updates For WordPress Lite Security Vulnerabilities

No known vulnerabilities — this is a good sign.
Version History

COVID-19 Corona Virus Live Stats & Updates For WordPress Lite Release Timeline

v1.2Current
v1.1
v1.0
Code Analysis
Analyzed Apr 16, 2026

COVID-19 Corona Virus Live Stats & Updates For WordPress Lite Code Analysis

Dangerous Functions
0
Raw SQL Queries
0
0 prepared
Unescaped Output
38
177 escaped
Nonce Checks
0
Capability Checks
0
File Operations
0
External Requests
6
Bundled Libraries
1

Bundled Libraries

DataTables

Output Escaping

82% escaped215 total outputs
Data Flows · Security
1 unsanitized

Data Flow Analysis

1 flows1 with unsanitized paths
<wss-covid19-settings> (admin-pages/wss-covid19-settings.php:0)
Source (user input) Sink (dangerous op) Sanitizer Transform Unsanitized Sanitized
Attack Surface

COVID-19 Corona Virus Live Stats & Updates For WordPress Lite Attack Surface

Entry Points0
Unprotected0
Maintenance & Trust

COVID-19 Corona Virus Live Stats & Updates For WordPress Lite Maintenance & Trust

Maintenance Signals

WordPress version tested5.4.19
Last updatedApr 23, 2020
PHP min version
Downloads3K

Community Trust

Rating0/100
Number of ratings0
Active installs10
Developer Profile

COVID-19 Corona Virus Live Stats & Updates For WordPress Lite Developer Profile

khubbaib

2 plugins · 20 total installs

84
trust score
Avg Security Score
85/100
Avg Patch Time
30 days
View full developer profile
Detection Fingerprints

How We Detect COVID-19 Corona Virus Live Stats & Updates For WordPress Lite

Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.

Asset Fingerprints

Asset Paths
/wp-content/plugins/covid-19-corona-virus-live-stats-updates-lite/assets/css/main.css/wp-content/plugins/covid-19-corona-virus-live-stats-updates-lite/assets/js/main.js
Script Paths
/wp-content/plugins/covid-19-corona-virus-live-stats-updates-lite/assets/js/main.js
Version Parameters
covid-19-corona-virus-live-stats-updates-lite/assets/css/main.css?ver=covid-19-corona-virus-live-stats-updates-lite/assets/js/main.js?ver=

HTML / DOM Fingerprints

CSS Classes
wss-covid19-text
Data Attributes
wss_covid19_global_datawss_covid19_labelwss_covid19_modewss_covid19_colorswss_covid19_country_datawss_covid19_default_country_data+5 more
Shortcode Output
[covid19-global-updates][covid19-country-updates][covid19-state-updates][covid19-list-countries]
FAQ

Frequently Asked Questions about COVID-19 Corona Virus Live Stats & Updates For WordPress Lite