DR SARA COVID Security & Risk Analysis

wordpress.org/plugins/sara-covid

The main propose of this plugin is to view COVID-19 case statistics in worldwide. you can easily install the plugin and use the shortcode to view the …

10 active installs v1.4 PHP 5.2.4+ WP 2.5+ Updated Mar 10, 2026
coronacoronaviruscovidcovid-19nepal
100
A · Safe
CVEs total0
Unpatched0
Last CVENever
Safety Verdict

Is DR SARA COVID Safe to Use in 2026?

Generally Safe

Score 100/100

DR SARA COVID has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.

No known CVEs Updated 2mo ago
Risk Assessment

The "sara-covid" plugin v1.4 exhibits a generally good security posture based on the provided static analysis. The code demonstrates strong adherence to secure coding practices, with a high percentage of properly escaped output and 100% of SQL queries utilizing prepared statements. The absence of dangerous functions, file operations, and known vulnerabilities in its history are positive indicators. However, there are a few areas that warrant attention. The presence of external HTTP requests without explicit mention of security controls or validation could potentially introduce risks if the external endpoints are compromised or manipulated. Furthermore, the lack of nonce checks and capability checks on the identified entry points (shortcodes) represents a potential weakness, as it could allow for unauthorized execution of plugin functionality if these shortcodes are accessible and exploitable in certain contexts. While the attack surface is small, these checks are fundamental for robust security. Overall, the plugin is well-constructed, but the absence of essential security checks on its entry points and the nature of external HTTP requests prevent it from achieving a perfect security score.

Key Concerns

  • Shortcodes lack nonce checks
  • Shortcodes lack capability checks
  • External HTTP requests found
Vulnerabilities
None known

DR SARA COVID Security Vulnerabilities

No known vulnerabilities — this is a good sign.
Version History

DR SARA COVID Release Timeline

v1.5
Code Analysis
Analyzed Apr 16, 2026

DR SARA COVID Code Analysis

Dangerous Functions
0
Raw SQL Queries
0
0 prepared
Unescaped Output
2
106 escaped
Nonce Checks
0
Capability Checks
0
File Operations
0
External Requests
2
Bundled Libraries
0

Output Escaping

98% escaped108 total outputs
Attack Surface

DR SARA COVID Attack Surface

Entry Points2
Unprotected0

Shortcodes 2

[dr-sara-covid-display] admin/dr-sara-covid.php:2
[dr-sara-covid-display] trunk/admin/dr-sara-covid.php:2
WordPress Hooks 22
actionadmin_menuadmin/back.php:2
actionadmin_initadmin/back.php:7
filterthe_contentadmin/class-dr-sara-covid-admin.php:109
actionadmin_menuadmin/class-dr-sara-covid-admin.php:113
actionadmin_initadmin/class-dr-sara-covid-admin.php:125
actionadmin_initadmin/class-dr-sara-covid-admin.php:191
actionplugins_loadedincludes/class-dr-sara-covid.php:142
actionadmin_enqueue_scriptsincludes/class-dr-sara-covid.php:157
actionadmin_enqueue_scriptsincludes/class-dr-sara-covid.php:158
actionwp_enqueue_scriptsincludes/class-dr-sara-covid.php:173
actionwp_enqueue_scriptsincludes/class-dr-sara-covid.php:174
actionadmin_menutrunk/admin/back.php:2
actionadmin_inittrunk/admin/back.php:7
filterthe_contenttrunk/admin/class-dr-sara-covid-admin.php:109
actionadmin_menutrunk/admin/class-dr-sara-covid-admin.php:113
actionadmin_inittrunk/admin/class-dr-sara-covid-admin.php:125
actionadmin_inittrunk/admin/class-dr-sara-covid-admin.php:191
actionplugins_loadedtrunk/includes/class-dr-sara-covid.php:142
actionadmin_enqueue_scriptstrunk/includes/class-dr-sara-covid.php:157
actionadmin_enqueue_scriptstrunk/includes/class-dr-sara-covid.php:158
actionwp_enqueue_scriptstrunk/includes/class-dr-sara-covid.php:173
actionwp_enqueue_scriptstrunk/includes/class-dr-sara-covid.php:174
Maintenance & Trust

DR SARA COVID Maintenance & Trust

Maintenance Signals

WordPress version tested5.4.19
Last updatedMar 10, 2026
PHP min version5.2.4
Downloads5K

Community Trust

Rating100/100
Number of ratings4
Active installs10
Developer Profile

DR SARA COVID Developer Profile

Ravi Khadka

5 plugins · 20 total installs

94
trust score
Avg Security Score
100/100
Avg Patch Time
30 days
View full developer profile
Detection Fingerprints

How We Detect DR SARA COVID

Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.

Asset Fingerprints

Asset Paths
/wp-content/plugins/sara-covid/assets/css/style.css/wp-content/plugins/sara-covid/assets/js/main.js
Script Paths
/wp-content/plugins/sara-covid/assets/js/main.js
Version Parameters
sara-covid/style.css?ver=sara-covid/main.js?ver=

HTML / DOM Fingerprints

CSS Classes
sara-covid-containercovid-tablecountry-data-rowchart-container
HTML Comments
<!-- SARA COVID Plugin --><!-- End SARA COVID Plugin --><!-- SARA COVID Chart --><!-- End SARA COVID Chart -->+2 more
Data Attributes
data-plugin="sara-covid"data-countrydata-casesdata-deathsdata-recovereddata-active
JS Globals
window.saraCovidDatavar saraCovidData
REST Endpoints
/wp-json/sara-covid/v1/data
Shortcode Output
[sara_covid_stats][sara_covid_chart][sara_covid_country]
FAQ

Frequently Asked Questions about DR SARA COVID