
Covid-19 Corona Virus Report Security & Risk Analysis
wordpress.org/plugins/covid-19-corona-virus-reportThis plugin will display summary of COVID-19 Corona Virus with search filter and pagination.
Is Covid-19 Corona Virus Report Safe to Use in 2026?
Generally Safe
Score 92/100Covid-19 Corona Virus Report has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.
The "covid-19-corona-virus-report" plugin v1.0 exhibits a mixed security posture. While it boasts a very small attack surface with only one shortcode and no AJAX handlers, REST API routes, or cron events exposed, its code analysis reveals significant security concerns, primarily related to output sanitization. The absence of any output escaping on the 9 identified outputs is a major red flag, indicating a high potential for cross-site scripting (XSS) vulnerabilities. Furthermore, the lack of nonce checks and capability checks on its single entry point (the shortcode) means that even without a direct AJAX or REST API vulnerability, an attacker could potentially trigger the shortcode's functionality without proper authorization, though the absence of taint analysis findings limits the immediate severity of this. The plugin's vulnerability history is clean, with no recorded CVEs, which is a positive indicator, suggesting that past development might have been diligent or that the plugin is simply not a target of widespread vulnerability discovery. However, this lack of history doesn't negate the immediate risks identified in the current static analysis, particularly the unescaped output. In conclusion, while the plugin has strengths in its limited attack surface and lack of known vulnerabilities, the critical deficiency in output escaping presents a clear and present danger that requires immediate attention to prevent potential XSS attacks.
Key Concerns
- Output escaping missing on all outputs
- No nonce checks on entry points
- No capability checks on entry points
Covid-19 Corona Virus Report Security Vulnerabilities
Covid-19 Corona Virus Report Release Timeline
Covid-19 Corona Virus Report Code Analysis
Bundled Libraries
Output Escaping
Covid-19 Corona Virus Report Attack Surface
Shortcodes 1
WordPress Hooks 1
Maintenance & Trust
Covid-19 Corona Virus Report Maintenance & Trust
Maintenance Signals
Community Trust
Covid-19 Corona Virus Report Alternatives
Coronavirus Update
yatko-coronavirus
Coronavirus Update: WordPress Plugin and Widget with coronavirus tracker. Cases by country and by state. Free COVID-19 live update for WordPress.
Corona Virus Data
corona-virus-data
This plugin displays the Coronavirus case data through shortcodes [cov2019] [cov2019all] or [cov2019map] in your WordPress post or page.
Simple Website Banner
corona-virus-covid-19-banner
This is a very simple plugin with a sole purpose of allowing you to inform your visitors of an upcoming event, updated store hours, or other important …
South African COVID19 Banner
corona-virus-covid19-banner
Comply with new South African Covid-19 regulations requiring all websites ending in .ZA to show a link to the official government page.
COVID-19 Float Button
covid-19-float-button
Creates a floating button with a link to a read more page.
Covid-19 Corona Virus Report Developer Profile
5 plugins · 70 total installs
How We Detect Covid-19 Corona Virus Report
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/covid-19-corona-virus-report/js/jquery.dataTables.min.js/wp-content/plugins/covid-19-corona-virus-report/js/dataTables.responsive.min.js/wp-content/plugins/covid-19-corona-virus-report/css/jquery.dataTables.min.css/wp-content/plugins/covid-19-corona-virus-report/css/responsive.dataTables.min.css/wp-content/plugins/covid-19-corona-virus-report/js/custom.js/wp-content/plugins/covid-19-corona-virus-report/js/jquery.dataTables.min.js/wp-content/plugins/covid-19-corona-virus-report/js/dataTables.responsive.min.js/wp-content/plugins/covid-19-corona-virus-report/js/custom.jsHTML / DOM Fingerprints
displaynowrap<table id="covid19" class="display nowrap" cellspacing="0" width="100%">