
Coronavirus Update Security & Risk Analysis
wordpress.org/plugins/yatko-coronavirusCoronavirus Update: WordPress Plugin and Widget with coronavirus tracker. Cases by country and by state. Free COVID-19 live update for WordPress.
Is Coronavirus Update Safe to Use in 2026?
Generally Safe
Score 85/100Coronavirus Update has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.
The "yatko-coronavirus" plugin, version 1.1.2, presents significant security concerns despite a lack of recorded vulnerabilities. The static analysis reveals two unprotected AJAX handlers, which represent a substantial attack surface. Without proper authentication or capability checks on these entry points, any unauthenticated user could potentially trigger unintended functionality, leading to various exploits. The low percentage of properly escaped output (42%) further exacerbates this risk, as it increases the likelihood of cross-site scripting (XSS) vulnerabilities if user-supplied data is processed and displayed without adequate sanitization.
The plugin's code signals do indicate some positive security practices, such as the complete use of prepared statements for SQL queries, which mitigates SQL injection risks. However, this strength is overshadowed by the critical weaknesses in handling AJAX requests and output escaping. The absence of any known vulnerabilities or CVEs in its history is noteworthy, but it does not guarantee future security, especially given the identified insecure code patterns. The lack of taint analysis data is a gap, but the direct exposure of AJAX handlers and poor output sanitization are sufficient indicators of risk.
In conclusion, the "yatko-coronavirus" plugin has a concerning security posture due to its unprotected AJAX handlers and insufficient output escaping. While it demonstrates good practices in SQL query handling and has no recorded vulnerability history, these strengths are outweighed by the high potential for exploitation through its exposed entry points and XSS vulnerabilities. It is strongly recommended that these security flaws be addressed promptly.
Key Concerns
- Unprotected AJAX handlers (2)
- Insufficient output escaping (58%)
- Missing nonce checks on AJAX
- Missing capability checks on AJAX
Coronavirus Update Security Vulnerabilities
Coronavirus Update Code Analysis
Output Escaping
Coronavirus Update Attack Surface
AJAX Handlers 2
WordPress Hooks 2
Maintenance & Trust
Coronavirus Update Maintenance & Trust
Maintenance Signals
Community Trust
Coronavirus Update Alternatives
Corona Virus Data
corona-virus-data
This plugin displays the Coronavirus case data through shortcodes [cov2019] [cov2019all] or [cov2019map] in your WordPress post or page.
South African COVID19 Banner
corona-virus-covid19-banner
Comply with new South African Covid-19 regulations requiring all websites ending in .ZA to show a link to the official government page.
VirusWeather Covid-19 Coronavirus
virusweather
Personalized by IP address PNG banner shows local covid-19 A.I. calculated threat level and live coronavirus stats for 10000+ local areas world-wide
COVID-19
covid-19
Campaign to raise public awareness about the importance of questions and answers about coronavirus disease (COVID-19).
Zone Pandemic Covid19
zone-pandemic-covid-19
This plugin provides shortcode and widgets that can displays the latest data of the covid19 in the whole world.
Coronavirus Update Developer Profile
6 plugins · 60 total installs
How We Detect Coronavirus Update
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/yatko-coronavirus/assets/styles/feed.css/wp-content/plugins/yatko-coronavirus/assets/js/feed.js/wp-content/plugins/yatko-coronavirus/assets/js/feed.jsHTML / DOM Fingerprints
data-regionxhr/wp-json/quarantine/v1/feed