Covid-19 Live Tracking Security & Risk Analysis

wordpress.org/plugins/covid-19-live-tracking

Covid-19 plugin is WordPress plugin for live tracking COVID-19 (corona virus) on the world and each country. It supports many types of layout for show …

10 active installs v1.0.0 PHP + WP 5.0+ Updated Apr 15, 2020
coronacorona-viruscovid-19live-trackingvirus
85
A · Safe
CVEs total0
Unpatched0
Last CVENever
Safety Verdict

Is Covid-19 Live Tracking Safe to Use in 2026?

Generally Safe

Score 85/100

Covid-19 Live Tracking has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.

No known CVEs Updated 6yr ago
Risk Assessment

The "covid-19-live-tracking" plugin v1.0.0 exhibits a generally strong security posture based on the provided static analysis. It demonstrates excellent adherence to secure coding practices, with 100% of SQL queries using prepared statements and an impressive 99% of output being properly escaped. The absence of dangerous functions, file operations, and critical or high-severity taint flows further contributes to its positive security profile. The plugin also implements a nonce check and a capability check, which are vital for protecting against common web vulnerabilities.

However, the presence of external HTTP requests, while not inherently problematic, warrants careful consideration as they can introduce risks if the external service is compromised or misconfigured. The plugin also bundles outdated versions of DataTables and Select2, which may contain known vulnerabilities that are not reflected in the plugin's own vulnerability history. While the plugin has no recorded vulnerability history, this could be due to its recency or a lack of comprehensive security auditing.

Overall, the plugin is well-developed from a security perspective, with a small attack surface and good implementation of security best practices. The main areas of potential concern lie with the bundled libraries and the external HTTP requests, which should be monitored for any emerging vulnerabilities or security concerns.

Key Concerns

  • Bundled outdated library: DataTables v1.10.20
  • Bundled outdated library: Select2
  • External HTTP requests detected
Vulnerabilities
None known

Covid-19 Live Tracking Security Vulnerabilities

No known vulnerabilities — this is a good sign.
Version History

Covid-19 Live Tracking Release Timeline

No version history available.
Code Analysis
Analyzed Apr 16, 2026

Covid-19 Live Tracking Code Analysis

Dangerous Functions
0
Raw SQL Queries
0
0 prepared
Unescaped Output
6
458 escaped
Nonce Checks
1
Capability Checks
1
File Operations
0
External Requests
2
Bundled Libraries
2

Bundled Libraries

DataTables1.10.20Select2

Output Escaping

99% escaped464 total outputs
Data Flows · Security
All sanitized

Data Flow Analysis

2 flows
save_params_trigger (admin/class-jmscovid-params.php:592)
Source (user input) Sink (dangerous op) Sanitizer Transform Unsanitized Sanitized
Attack Surface

Covid-19 Live Tracking Attack Surface

Entry Points1
Unprotected0

Shortcodes 1

[jms-covid19] front/class-jmscovid-front.php:28
WordPress Hooks 10
actioninitadmin/class-jmscovid-admin.php:18
actionadmin_menuadmin/class-jmscovid-admin.php:19
actionadmin_enqueue_scriptsadmin/class-jmscovid-admin.php:20
actionjms_check_covid_19admin/class-jmscovid-admin.php:22
actionelementor/elements/categories_registeredadmin/class-jmscovid-elementor.php:25
actionelementor/widgets/widgets_registeredadmin/class-jmscovid-elementor.php:32
actionadmin_initadmin/class-jmscovid-params.php:39
actionwp_enqueue_scriptsfront/class-jmscovid-front.php:25
actionwidgets_initfront/class-jmscovid-front.php:27
filtercron_schedulesjms-covid-19.php:66

Scheduled Events 1

jms_check_covid_19
Maintenance & Trust

Covid-19 Live Tracking Maintenance & Trust

Maintenance Signals

WordPress version tested5.4.19
Last updatedApr 15, 2020
PHP min version
Downloads2K

Community Trust

Rating0/100
Number of ratings0
Active installs10
Developer Profile

Covid-19 Live Tracking Developer Profile

jmsthemes

3 plugins · 30 total installs

84
trust score
Avg Security Score
85/100
Avg Patch Time
30 days
View full developer profile
Detection Fingerprints

How We Detect Covid-19 Live Tracking

Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.

Asset Fingerprints

Asset Paths
/wp-content/plugins/covid-19-live-tracking/css/bootstrap.min.css/wp-content/plugins/covid-19-live-tracking/css/semantic.min.css/wp-content/plugins/covid-19-live-tracking/css/admin.css/wp-content/plugins/covid-19-live-tracking/js/bootstrap.min.js/wp-content/plugins/covid-19-live-tracking/js/semantic.min.js/wp-content/plugins/covid-19-live-tracking/js/admin.min.js/wp-content/plugins/covid-19-live-tracking/css/select2.min.css/wp-content/plugins/covid-19-live-tracking/js/select2.min.js+2 more
Script Paths
/wp-content/plugins/covid-19-live-tracking/js/bootstrap.min.js/wp-content/plugins/covid-19-live-tracking/js/semantic.min.js/wp-content/plugins/covid-19-live-tracking/js/admin.min.js/wp-content/plugins/covid-19-live-tracking/js/select2.min.js/wp-content/plugins/covid-19-live-tracking/js/widgets.min.js
Version Parameters
covid-19-live-tracking/css/bootstrap.min.css?ver=covid-19-live-tracking/css/semantic.min.css?ver=covid-19-live-tracking/css/admin.css?ver=covid-19-live-tracking/js/bootstrap.min.js?ver=covid-19-live-tracking/js/semantic.min.js?ver=covid-19-live-tracking/js/admin.min.js?ver=covid-19-live-tracking/css/select2.min.css?ver=covid-19-live-tracking/js/select2.min.js?ver=covid-19-live-tracking/js/widgets.min.js?ver=covid-19-live-tracking/css/widgets.css?ver=

HTML / DOM Fingerprints

JS Globals
JMS_COVID_19_PLUGIN_PATHJMS_COVID_19_URLJMS_COVID_19_CSS_URLJMS_COVID_19_JS_URLJMS_COVID_19_IMAGES_URLJMS_COVID_19_ADMIN_PATH+1 more
FAQ

Frequently Asked Questions about Covid-19 Live Tracking