
AirQuality CHMU Security & Risk Analysis
wordpress.org/plugins/airquality-chmuTento plugin slouží k zobrazení environmentálních dat z Českého hydrometeorologického ústavu.
Is AirQuality CHMU Safe to Use in 2026?
Generally Safe
Score 100/100AirQuality CHMU has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.
The "airquality-chmu" v1.0 plugin exhibits a mixed security posture. On the positive side, it has no recorded vulnerability history, no dangerous functions, and all SQL queries are properly prepared. It also avoids file operations and external HTTP requests. However, there are significant concerns regarding output escaping and a lack of proper authorization checks. With 100% of outputs unescaped, this presents a high risk of Cross-Site Scripting (XSS) vulnerabilities, allowing attackers to inject malicious scripts into the WordPress dashboard or front-end content. Furthermore, the complete absence of nonce checks and capability checks on any entry points, including the shortcode, means that any user, regardless of their role or permissions, could potentially trigger unintended actions or access sensitive information through the plugin's functionality. The presence of bundled libraries like Select2 also introduces a potential risk if they are outdated or contain known vulnerabilities, though this is not explicitly detailed in the provided data.
Key Concerns
- Unescaped output
- Missing nonce checks
- Missing capability checks
AirQuality CHMU Security Vulnerabilities
AirQuality CHMU Code Analysis
Bundled Libraries
Output Escaping
AirQuality CHMU Attack Surface
Shortcodes 1
WordPress Hooks 5
Scheduled Events 1
Maintenance & Trust
AirQuality CHMU Maintenance & Trust
Maintenance Signals
Community Trust
AirQuality CHMU Alternatives
Air Quality Plugin
air-quality
This plugin was made mainly to display air quality from closest air pollution detector
Weather Atlas Widget
weather-atlas
The Weather Widget with the Most Active Installations. Highly customizable, simple & beautiful. Detailed current weather, hourly & daily forecasts
wp-forecast
wp-forecast
wp-forecast is a highly customizable plugin for wordpress, showing weather-data from open-meteo.com and/or openweathermap.com.
Health Endpoint
health-endpoint
Creates a /health endpoint that returns a 200 OK HTTP status code while WordPress is performing correctly.
Remove Site Health From Dashboard
remove-site-heath-from-dashboard
Removes the Site Health from the Dashboard introduced in WP 5.4
AirQuality CHMU Developer Profile
1 plugin · 0 total installs
How We Detect AirQuality CHMU
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/airquality-chmu/lib/select2.min.css/wp-content/plugins/airquality-chmu/lib/select2.min.js/wp-content/plugins/airquality-chmu/lib/select2.min.jsHTML / DOM Fingerprints
chmu textové pole name="chmu_station"name="chmu_show_name="chmu_legend_"value="1"name="chmu_widget"jQuery<h3>Město: <strong>Kvalita ovzduší</strong>: Last update: Data jsou čerpána z ČHMÚ