Australian Weather Widget – WillyWeather Security & Risk Analysis

wordpress.org/plugins/australian-weather-widget-willyweather

Australian weather widgets for Wordpress, with the latest data sourced from the Bureau of Meteorology (BoM). Custom designs to suit any website.

200 active installs v1.5 PHP + WP 3.6.1+ Updated Oct 16, 2017
bom-widgetbureau-of-meteorologyweather-forecastweather-widgetwillyweather-widget
85
A · Safe
CVEs total0
Unpatched0
Last CVENever
Safety Verdict

Is Australian Weather Widget – WillyWeather Safe to Use in 2026?

Generally Safe

Score 85/100

Australian Weather Widget – WillyWeather has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.

No known CVEs Updated 8yr ago
Risk Assessment

The "australian-weather-widget-willyweather" plugin v1.5 exhibits a strong security posture based on the provided static analysis and vulnerability history. The absence of any identified AJAX handlers, REST API routes, shortcodes, or cron events with unprotected entry points suggests a minimal attack surface. Furthermore, the code signals indicate good development practices, with no dangerous functions, all SQL queries using prepared statements, and a high percentage of properly escaped output. The lack of file operations and external HTTP requests also contributes positively to its security profile. The plugin's vulnerability history is clean, with no recorded CVEs of any severity, indicating a well-maintained and secure codebase over time. However, the complete absence of nonce checks and capability checks across its attack surface, if any were present, represents a potential area for concern. While the current static analysis shows no direct vulnerabilities stemming from this, it could become a weakness if new entry points were introduced or if a more complex interaction model existed that was not captured. Overall, the plugin appears robust and secure given the current data, with its main potential weakness being a lack of explicit authorization checks on any (currently non-existent) dynamic components.

Key Concerns

  • No nonce checks detected
  • No capability checks detected
  • 72% of output escaped, some unescaped output exists
Vulnerabilities
None known

Australian Weather Widget – WillyWeather Security Vulnerabilities

No known vulnerabilities — this is a good sign.
Code Analysis
Analyzed Mar 16, 2026

Australian Weather Widget – WillyWeather Code Analysis

Dangerous Functions
0
Raw SQL Queries
0
0 prepared
Unescaped Output
7
18 escaped
Nonce Checks
0
Capability Checks
0
File Operations
0
External Requests
0
Bundled Libraries
0

Output Escaping

72% escaped25 total outputs
Attack Surface

Australian Weather Widget – WillyWeather Attack Surface

Entry Points0
Unprotected0
WordPress Hooks 1
actionwidgets_initwillyweather.php:198
Maintenance & Trust

Australian Weather Widget – WillyWeather Maintenance & Trust

Maintenance Signals

WordPress version tested4.8.28
Last updatedOct 16, 2017
PHP min version
Downloads9K

Community Trust

Rating98/100
Number of ratings7
Active installs200
Developer Profile

Australian Weather Widget – WillyWeather Developer Profile

WillyWeather

2 plugins · 400 total installs

84
trust score
Avg Security Score
85/100
Avg Patch Time
30 days
View full developer profile
Detection Fingerprints

How We Detect Australian Weather Widget – WillyWeather

Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.

Asset Fingerprints

Asset Paths
/wp-content/plugins/australian-weather-widget-willyweather/willyweather.css/wp-content/plugins/australian-weather-widget-willyweather/willyweather.js
Script Paths
/wp-content/plugins/australian-weather-widget-willyweather/willyweather.js

HTML / DOM Fingerprints

CSS Classes
ww-activity-indicatorww-widget-styleww-widget-locationww-widget-weather-typesww-widget-colourww-widget-widthww-widget-width-slider
Data Attributes
data-ww-name="ww-widget-id"data-ww-name="ww-widget-code"data-ww-name="ww-widget-html"data-ww-name="ww-widget-tabOrder"data-widthdata-min+3 more
JS Globals
jQuery.fn.getWillyWeatherWidgetjQuery.fn.buildWidthTool
FAQ

Frequently Asked Questions about Australian Weather Widget – WillyWeather