
Air Quality Plugin Security & Risk Analysis
wordpress.org/plugins/air-qualityThis plugin was made mainly to display air quality from closest air pollution detector
Is Air Quality Plugin Safe to Use in 2026?
Generally Safe
Score 85/100Air Quality Plugin has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.
The "air-quality" plugin v0.40 exhibits a mixed security posture. On the positive side, it has a clean vulnerability history with no known CVEs, uses prepared statements for all SQL queries, and implements nonce and capability checks. There are no observed critical or high severity taint flows, nor are there any dangerous functions or file operations in the code.
However, there are notable concerns related to its attack surface and output escaping. Two out of three AJAX handlers lack authentication checks, presenting a significant risk of unauthorized access or execution of plugin functions. Furthermore, a substantial majority of output (79%) is not properly escaped, indicating a high likelihood of cross-site scripting (XSS) vulnerabilities. The presence of an external HTTP request also warrants attention, although its specific impact is unknown without further analysis.
While the lack of historical vulnerabilities and secure SQL practices are strengths, the combination of unprotected AJAX endpoints and widespread unescaped output creates a substantial security risk. The plugin needs significant improvements in input validation and output sanitization to achieve a secure state.
Key Concerns
- Unprotected AJAX handlers
- Insufficient output escaping
Air Quality Plugin Security Vulnerabilities
Air Quality Plugin Code Analysis
Output Escaping
Data Flow Analysis
Air Quality Plugin Attack Surface
AJAX Handlers 3
WordPress Hooks 3
Maintenance & Trust
Air Quality Plugin Maintenance & Trust
Maintenance Signals
Community Trust
Air Quality Plugin Alternatives
AirQuality CHMU
airquality-chmu
Tento plugin slouží k zobrazení environmentálních dat z Českého hydrometeorologického ústavu.
Weather Atlas Widget
weather-atlas
The Weather Widget with the Most Active Installations. Highly customizable, simple & beautiful. Detailed current weather, hourly & daily forecasts
wp-forecast
wp-forecast
wp-forecast is a highly customizable plugin for wordpress, showing weather-data from open-meteo.com and/or openweathermap.com.
Health Endpoint
health-endpoint
Creates a /health endpoint that returns a 200 OK HTTP status code while WordPress is performing correctly.
Remove Site Health From Dashboard
remove-site-heath-from-dashboard
Removes the Site Health from the Dashboard introduced in WP 5.4
Air Quality Plugin Developer Profile
1 plugin · 30 total installs
How We Detect Air Quality Plugin
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/air-quality/css/style-widget.cssair-quality/css/style-widget.css?ver=HTML / DOM Fingerprints
pk_aqp_air_quality_widgetname="longitude"name="latitude"name="weather-info"name="longitude-default"name="latitude-default"name="google-maps-key"+3 more