COVID19TRACKER Security & Risk Analysis
wordpress.org/plugins/covid19-real-time-trackerCOVID19TRACKER displays real time covid19 data on your widget, using the lmao.ninja API. IMPORTANT: This plugin relays on an external service by send …
Is COVID19TRACKER Safe to Use in 2026?
Generally Safe
Score 85/100COVID19TRACKER has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.
The "covid19-real-time-tracker" v1.0.0 plugin exhibits a generally positive security posture based on the provided static analysis. The absence of any identified CVEs, both historically and currently, along with a clean taint analysis, suggests a low likelihood of known, exploitable vulnerabilities. The code also demonstrates good practices in its handling of SQL queries, utilizing prepared statements exclusively, and avoiding file operations. However, there are notable areas of concern. The plugin has a low number of identified output escaping points (32), with a significant portion (53%) not being properly escaped. This leaves it vulnerable to Cross-Site Scripting (XSS) attacks if any user-supplied data is ever rendered directly to the browser without proper sanitization. Furthermore, the complete lack of nonce checks and capability checks, coupled with an absence of protected entry points in AJAX, REST API, and shortcodes, creates a broad attack surface that could be exploited if any new functionality is added without these crucial security layers. The two external HTTP requests also represent potential vectors for man-in-the-middle attacks or server-side request forgery (SSRF) if not handled with extreme care and validation.
Key Concerns
- Low output escaping rate
- No nonce checks
- No capability checks
- External HTTP requests
COVID19TRACKER Security Vulnerabilities
COVID19TRACKER Code Analysis
Output Escaping
COVID19TRACKER Attack Surface
WordPress Hooks 1
Maintenance & Trust
COVID19TRACKER Maintenance & Trust
Maintenance Signals
Community Trust
COVID19TRACKER Alternatives
South African COVID19 Banner
corona-virus-covid19-banner
Comply with new South African Covid-19 regulations requiring all websites ending in .ZA to show a link to the official government page.
VirusWeather Covid-19 Coronavirus
virusweather
Personalized by IP address PNG banner shows local covid-19 A.I. calculated threat level and live coronavirus stats for 10000+ local areas world-wide
Corona Stats Live – Corona Virus COVID-19 Live Stats for WordPress Lite
corona-stats-live
Corona Stats Live - is a WordPress plugin exclusively developed to provide upto date corona virus stats. You can take full advantage of this plugin to …
Coronavirus Info
coronavirus-info
This plugin displays the COVID-19 real-time data, top-headline news and finance impact, quantitative geographical mapping and forecasting in the whole …
Zone Pandemic Covid19
zone-pandemic-covid-19
This plugin provides shortcode and widgets that can displays the latest data of the covid19 in the whole world.
COVID19TRACKER Developer Profile
1 plugin · 10 total installs
How We Detect COVID19TRACKER
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/covid19-real-time-tracker/css/style.css/wp-content/plugins/covid19-real-time-tracker/js/script.jscovid19-real-time-tracker/css/style.css?ver=covid19-real-time-tracker/js/script.js?ver=HTML / DOM Fingerprints
covid19-tracker-widget-titlecovid19-tracker-country-datacovid19-tracker-worldwide-datadata-countrydata-show-worldwide[covid19_tracker][covid19_tracker country="US" show_worldwide="true"]