
Aviation Weather from NOAA Security & Risk Analysis
wordpress.org/plugins/aviation-weather-from-noaaAviation weather data from NOAA's Aviation Digital Data Service (ADDS)
Is Aviation Weather from NOAA Safe to Use in 2026?
Use With Caution
Score 61/100Aviation Weather from NOAA has 1 unpatched vulnerability. Evaluate alternatives or apply available mitigations.
The aviation-weather-from-noaa plugin exhibits a mixed security posture. While it demonstrates good practices in areas like SQL query preparation and output escaping, significant concerns arise from its attack surface and vulnerability history. The presence of three unprotected AJAX handlers presents a notable risk, as these can be exploited by unauthenticated users. The plugin's vulnerability history, specifically a high-severity path traversal vulnerability discovered in the recent past and still unpatched, is a critical red flag. This indicates a potential for attackers to manipulate file paths, leading to unauthorized access to sensitive data or even system compromise. Although taint analysis shows no unsanitized paths in the current version, the recurring nature of path-related vulnerabilities is concerning and suggests potential for reintroduction. The plugin has a moderate attack surface with several entry points, a portion of which lack proper authorization. The strengths lie in its use of prepared statements for SQL and generally good output escaping, which mitigate some common web vulnerabilities. However, the unpatched high-severity vulnerability and the unprotected AJAX endpoints create a clear and present danger.
Key Concerns
- Unpatched high severity CVE
- Unprotected AJAX handlers
- No capability checks
- File operations present
- External HTTP requests present
Aviation Weather from NOAA Security Vulnerabilities
CVEs by Year
Severity Breakdown
1 total CVE
Aviation Weather from NOAA <= 0.7.2 - Authenticated (Subscriber+) Arbitrary File Deletion
Aviation Weather from NOAA Code Analysis
SQL Query Safety
Output Escaping
Data Flow Analysis
Aviation Weather from NOAA Attack Surface
AJAX Handlers 5
Shortcodes 1
WordPress Hooks 12
Maintenance & Trust
Aviation Weather from NOAA Maintenance & Trust
Maintenance Signals
Community Trust
Aviation Weather from NOAA Alternatives
Aviation Weather Briefing
aviation-weather-briefing
Display the most important Aviation Weather information such as METAR,TAF,Significant Weather and Upper Winds and Temperature.
taf-metar-widget
wp-taf-metar-widget
This Widget allows you to show the TAF or METAR (aviation weather) information for any airport directly to your WordPress WebSite.
AviationWeather Plugin
aviationweather-widget
A simple widget to display current METAR and TAF for the chosen ICAO Station.
METAR plugin
metar-widget
A simple widget to display the current METAR code (Pilot weather code) for a chosen ICAO station.
TAF plugin
taf-widget
A simple widget to display the current TAF (Terminal aerodrome forecast) code for a chosen ICAO station.
Aviation Weather from NOAA Developer Profile
1 plugin · 100 total installs
How We Detect Aviation Weather from NOAA
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/aviation-weather-from-noaa/css/loading.gif/wp-content/plugins/aviation-weather-from-noaa/css/widget.css/wp-content/plugins/aviation-weather-from-noaa/js/widget.js/wp-content/plugins/aviation-weather-from-noaa/js/widget.js/wp-content/plugins/aviation-weather-from-noaa/css/widget.css?ver=/wp-content/plugins/aviation-weather-from-noaa/js/widget.js?ver=HTML / DOM Fingerprints
adds-weather-wrapperdata-instanceAWFN_ShortcodeAdds_Weather_Widgetwidget_ajax_object/wp-json/aviation-weather-from-noaa/v1/stations[adds_weather