Covid-19 Corona Virus Report Security & Risk Analysis

wordpress.org/plugins/covid-19-corona-virus-report

This plugin will display summary of COVID-19 Corona Virus with search filter and pagination.

10 active installs v1.0 PHP + WP 4.0+ Updated Apr 9, 2025
coronacountrycovid-19worldwide
92
A · Safe
CVEs total0
Unpatched0
Last CVENever
Download
Safety Verdict

Is Covid-19 Corona Virus Report Safe to Use in 2026?

Generally Safe

Score 92/100

Covid-19 Corona Virus Report has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.

No known CVEs Updated 1yr ago
Risk Assessment

The "covid-19-corona-virus-report" plugin v1.0 exhibits a mixed security posture. While it boasts a very small attack surface with only one shortcode and no AJAX handlers, REST API routes, or cron events exposed, its code analysis reveals significant security concerns, primarily related to output sanitization. The absence of any output escaping on the 9 identified outputs is a major red flag, indicating a high potential for cross-site scripting (XSS) vulnerabilities. Furthermore, the lack of nonce checks and capability checks on its single entry point (the shortcode) means that even without a direct AJAX or REST API vulnerability, an attacker could potentially trigger the shortcode's functionality without proper authorization, though the absence of taint analysis findings limits the immediate severity of this. The plugin's vulnerability history is clean, with no recorded CVEs, which is a positive indicator, suggesting that past development might have been diligent or that the plugin is simply not a target of widespread vulnerability discovery. However, this lack of history doesn't negate the immediate risks identified in the current static analysis, particularly the unescaped output. In conclusion, while the plugin has strengths in its limited attack surface and lack of known vulnerabilities, the critical deficiency in output escaping presents a clear and present danger that requires immediate attention to prevent potential XSS attacks.

Key Concerns

  • Output escaping missing on all outputs
  • No nonce checks on entry points
  • No capability checks on entry points
Vulnerabilities
None known

Covid-19 Corona Virus Report Security Vulnerabilities

No known vulnerabilities — this is a good sign.
Version History

Covid-19 Corona Virus Report Release Timeline

No version history available.
Code Analysis
Analyzed Apr 16, 2026

Covid-19 Corona Virus Report Code Analysis

Dangerous Functions
0
Raw SQL Queries
0
0 prepared
Unescaped Output
9
0 escaped
Nonce Checks
0
Capability Checks
0
File Operations
0
External Requests
1
Bundled Libraries
1

Bundled Libraries

DataTables

Output Escaping

0% escaped9 total outputs
Attack Surface

Covid-19 Corona Virus Report Attack Surface

Entry Points1
Unprotected0

Shortcodes 1

[CVUPDATES_COVID19_Reports] covid19-corona-virus-reports.php:61
WordPress Hooks 1
actionwp_enqueue_scriptscovid19-corona-virus-reports.php:71
Maintenance & Trust

Covid-19 Corona Virus Report Maintenance & Trust

Maintenance Signals

WordPress version tested6.7.5
Last updatedApr 9, 2025
PHP min version
Downloads2K

Community Trust

Rating0/100
Number of ratings0
Active installs10
Developer Profile

Covid-19 Corona Virus Report Developer Profile

kinjaldalwadi

5 plugins · 70 total installs

88
trust score
Avg Security Score
92/100
Avg Patch Time
30 days
View full developer profile
Detection Fingerprints

How We Detect Covid-19 Corona Virus Report

Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.

Asset Fingerprints

Asset Paths
/wp-content/plugins/covid-19-corona-virus-report/js/jquery.dataTables.min.js/wp-content/plugins/covid-19-corona-virus-report/js/dataTables.responsive.min.js/wp-content/plugins/covid-19-corona-virus-report/css/jquery.dataTables.min.css/wp-content/plugins/covid-19-corona-virus-report/css/responsive.dataTables.min.css/wp-content/plugins/covid-19-corona-virus-report/js/custom.js
Script Paths
/wp-content/plugins/covid-19-corona-virus-report/js/jquery.dataTables.min.js/wp-content/plugins/covid-19-corona-virus-report/js/dataTables.responsive.min.js/wp-content/plugins/covid-19-corona-virus-report/js/custom.js

HTML / DOM Fingerprints

CSS Classes
displaynowrap
Shortcode Output
<table id="covid19" class="display nowrap" cellspacing="0" width="100%">
FAQ

Frequently Asked Questions about Covid-19 Corona Virus Report