[{"data":1,"prerenderedAt":-1},["ShallowReactive",2],{"$fNQnELV9XWpQIm8AIilUv4uKael893uRmA6S7LcZdEfQ":3,"$fAH6ZREfV8hMheQOISho4zwcqyvyePjiUBRslveP3HwE":301,"$fwN09R8Fqn4XQsM0AQFySQzhIca1Pc-84FvkL8mFwx7w":306},{"slug":4,"name":5,"version":6,"author":7,"author_profile":8,"description":9,"short_description":10,"active_installs":11,"downloaded":12,"rating":13,"num_ratings":14,"last_updated":15,"tested_up_to":16,"requires_at_least":17,"requires_php":18,"tags":19,"homepage":23,"download_link":24,"security_score":25,"vuln_count":26,"unpatched_count":26,"last_vuln_date":27,"fetched_at":28,"discovery_status":29,"vulnerabilities":30,"developer":31,"crawl_stats":27,"alternatives":37,"analysis":121,"fingerprints":258},"beautiful-yahoo-weather","Beautiful Yahoo Weather","1.4.2","Mohammad Pishdar","https:\u002F\u002Fprofiles.wordpress.org\u002Ffares_1990\u002F","\u003Cp>The Weather plugin enables you to get up-to-date weather information for your location.The Weather plugin is a dynamically-generated based on WOEID\u003C\u002Fp>\n\u003Ch4>Languages\u003C\u002Fh4>\n\u003Cp>persian english arabic bulgarian catalan chinese-simplified chinese-traditional danish dutch estonian finnish german french greek haitian-creole hindi indonesian italian japanese korean latvian maltese romanian russian spanish swedish turkish ukrainian vietnamese\u003C\u002Fp>\n","The Weather plugin enables you to get up-to-date weather information for your location.The Weather plugin is a dynamically-generated based on WOEID",100,28189,76,12,"2015-11-10T05:13:00.000Z","3.9.40","3.0.1","",[20,21,22],"beautiful","weather","yahoo","http:\u002F\u002Fwww.wp-book.ir\u002F","https:\u002F\u002Fdownloads.wordpress.org\u002Fplugin\u002Fbeautiful-yahoo-weather.zip",85,0,null,"2026-07-22T17:31:50.256Z","no_bundle",[],{"slug":32,"display_name":7,"profile_url":8,"plugin_count":33,"total_installs":11,"avg_security_score":25,"avg_patch_time_days":34,"trust_score":35,"computed_at":36},"fares_1990",1,30,84,"2026-08-29T06:40:24.086Z",[38,56,73,90,105],{"slug":39,"name":40,"version":41,"author":42,"author_profile":43,"description":44,"short_description":45,"active_installs":46,"downloaded":47,"rating":48,"num_ratings":33,"last_updated":49,"tested_up_to":18,"requires_at_least":18,"requires_php":18,"tags":50,"homepage":54,"download_link":55,"security_score":25,"vuln_count":26,"unpatched_count":26,"last_vuln_date":27,"fetched_at":28},"clima","Clima","9","rodrigoart","https:\u002F\u002Fprofiles.wordpress.org\u002Frodrigoart\u002F","\u003Cp>Este plugin te permite traer los datos del clima de yahoo clima, vas a levantar la temperatura pudiendo eleigir entre\u003Cbr \u002F>\nCelcius o farenheit, y la imagen asociada a segun como este el tiempo, lluvia, despejado, nublado, etc. Podes mostrar esto mediante\u003Cbr \u002F>\nun widget o con la funcion \u003Ccode>\u003C?php show_clima();?>\u003C\u002Fcode> Añadido recientemente, podes traer por separado los valores, de temperatura, humedad, maxima, minima, etc. Usando  funciones como \u003Ccode>\u003C?php show_clima(humedad);?>\u003C\u002Fcode> mas info en seccion instalacion.\u003C\u002Fp>\n\u003Cp>This plugin allows you to bring data from yahoo weather climate, you can raise the temperature to between eleigir\u003Cbr \u002F>\nCelsius or Fahrenheit, and the image associated with depending on how this time, rain, clouds, cloudy, etc. You can show by\u003Cbr \u002F>\n     or use the widget. You can show temerature, humydity, wind direction, speed and more using functions like\u003Cbr \u002F>\n     more info in installation section.\u003C\u002Fp>\n","Este plugin te permite traer los datos del clima de yahoo clima, vas a levantar la temperatura pudiendo eleigir entre",50,19738,60,"2014-04-05T15:37:00.000Z",[39,51,52,21,53],"temperatura","temperature","yahoo-weather","http:\u002F\u002Fwww.rodrigoart.com.ar","https:\u002F\u002Fdownloads.wordpress.org\u002Fplugin\u002Fclima.zip",{"slug":53,"name":57,"version":58,"author":59,"author_profile":60,"description":61,"short_description":62,"active_installs":63,"downloaded":64,"rating":26,"num_ratings":26,"last_updated":65,"tested_up_to":66,"requires_at_least":18,"requires_php":18,"tags":67,"homepage":71,"download_link":72,"security_score":25,"vuln_count":26,"unpatched_count":26,"last_vuln_date":27,"fetched_at":28},"Yahoo Weather","1.3.4","magnus0","https:\u002F\u002Fprofiles.wordpress.org\u002Fmagnus0\u002F","\u003Cp>A simple Yahoo Weather widget\u003C\u002Fp>\n","A simple Yahoo Weather widget",20,19283,"2012-01-20T00:31:00.000Z","3.3.2",[68,21,69,70,22],"sidebar","widget","widgets","http:\u002F\u002Fwordpress.org\u002Fextend\u002Fplugins\u002Fyahoo-weather\u002F","https:\u002F\u002Fdownloads.wordpress.org\u002Fplugin\u002Fyahoo-weather.zip",{"slug":74,"name":75,"version":76,"author":77,"author_profile":78,"description":79,"short_description":80,"active_installs":81,"downloaded":82,"rating":26,"num_ratings":26,"last_updated":83,"tested_up_to":84,"requires_at_least":17,"requires_php":18,"tags":85,"homepage":87,"download_link":88,"security_score":25,"vuln_count":26,"unpatched_count":26,"last_vuln_date":27,"fetched_at":89},"clima-freekitime","clima freekitime","1.0","jmsv16","https:\u002F\u002Fprofiles.wordpress.org\u002Fjmsv16\u002F","\u003Cp>muestra el estado del clima de la ciudad que elijas utilizando la api de yahoo! weather, se implementa como funcion en la plantilla, shortcode o widge\u003C\u002Fp>\n\u003Ch3>Readme Generator\u003C\u002Fh3>\n\u003Cp>This Readme file was generated using \u003Ca href='http:\u002F\u002Fsudarmuthu.com\u002Fwordpress\u002Fwp-readme' rel=\"nofollow ugc\">wp-readme\u003C\u002Fa>, which generates readme files for WordPress Plugins.\u003C\u002Fp>\n","muestra el estado del clima de la ciudad que elijas utilizando la api de yahoo! weather, se implementa como funcion en la plantilla, shortcode o widge",10,3775,"2012-09-28T17:47:00.000Z","3.4.2",[86,39,21,53],"api","http:\u002F\u002Fclima.freekitime.com","https:\u002F\u002Fdownloads.wordpress.org\u002Fplugin\u002Fclima-freekitime.zip","2026-04-06T09:54:40.288Z",{"slug":91,"name":92,"version":93,"author":94,"author_profile":95,"description":96,"short_description":97,"active_installs":81,"downloaded":98,"rating":26,"num_ratings":26,"last_updated":99,"tested_up_to":100,"requires_at_least":101,"requires_php":18,"tags":102,"homepage":103,"download_link":104,"security_score":25,"vuln_count":26,"unpatched_count":26,"last_vuln_date":27,"fetched_at":28},"weather-man","Weather Man","1.00.0","binnyva","https:\u002F\u002Fprofiles.wordpress.org\u002Fbinnyva\u002F","\u003Cp>You can add the widget using the Widget page under Appearence.\u003C\u002Fp>\n\u003Ch3>1.00.0\u003C\u002Fh3>\n\u003Cul>\n\u003Cli>Beta release made.\u003C\u002Fli>\n\u003C\u002Ful>\n","Shows the weather as a widget in the sidebar.",5169,"2009-07-13T16:22:00.000Z","2.8","2.6",[86,21,69,22],"http:\u002F\u002Fwww.bin-co.com\u002Ftools\u002Fwordpress\u002Fplugins\u002Fweather-man\u002F","https:\u002F\u002Fdownloads.wordpress.org\u002Fplugin\u002Fweather-man.1.00.0.zip",{"slug":106,"name":107,"version":108,"author":109,"author_profile":110,"description":111,"short_description":112,"active_installs":81,"downloaded":113,"rating":26,"num_ratings":26,"last_updated":114,"tested_up_to":115,"requires_at_least":116,"requires_php":18,"tags":117,"homepage":119,"download_link":120,"security_score":25,"vuln_count":26,"unpatched_count":26,"last_vuln_date":27,"fetched_at":28},"weather-slider","Weather Slider","1.1","mimartinez","https:\u002F\u002Fprofiles.wordpress.org\u002Fmimartinez\u002F","\u003Cp>Lee el tiempo desde Yahoo! Weather, de los códigos de las ciudades insertadas en el formulario, desde \u003Ca href=\"http:\u002F\u002Fweather.yahooapis.com\u002Fforecastrss?p=\" rel=\"nofollow ugc\">weather.yahooapis.com\u003C\u002Fa>. Muestra dos ciudades en cada ítem y se desplaza por el resto automáticamente, con la opción de poder seleccionar un ítem. Cantidad de ciudades y CSS configurables, utiliza la librería \u003Ca href=\"http:\u002F\u002Fcssglobe.com\u002Fpost\u002F4004\u002Feasy-slider-15-the-easiest-jquery-plugin-for-sliding\" rel=\"nofollow ugc\">easySlider\u003C\u002Fa>.\u003C\u002Fp>\n\u003Cp>Adicionar las URLs, ejemplo: \u003Ca href='http:\u002F\u002Fweather.yahooapis.com\u002Fforecastrss?p=POXX0022&u=c' rel=\"nofollow ugc\">http:\u002F\u002Fweather.yahooapis.com\u002Fforecastrss?p=POXX0022&u=c\u003C\u002Fa> , en la \u003Ccode>p\u003C\u002Fcode> de la URL inserta el código de la ciudad de la que quieres el tiempo, puedes sacar el código de la ciudad que desees aquí ( \u003Ca href='http:\u002F\u002Fxoap.weather.com\u002Fweather\u002Fsearch\u002Fsearch?where=' rel=\"nofollow ugc\">xoap.weather.com\u003C\u002Fa> en el parámetro \u003Ccode>where\u003C\u002Fcode> pones el nombre de la ciudad. Por ejemplo para buscar la ciudad de \u003Ca href='http:\u002F\u002Fxoap.weather.com\u002Fweather\u002Fsearch\u002Fsearch?where=Porto' rel=\"nofollow ugc\">Porto\u003C\u002Fa> copias el id(código) de la ciudad que deseas entre todos los resultados), y en la \u003Ccode>u\u003C\u002Fcode>, si quieres grados centígrados coloca \u003Ccode>c\u003C\u002Fcode>, si lo quieres en Fahrenheit coloca \u003Ccode>f\u003C\u002Fcode>. Para alterar la cantidad de ciudades, en \u003Ccode>\u002Fwp-content\u002Fplugins\u002Fweather-slider\u002Fweather-slider.php\u003C\u002Fcode> altere la constante \u003Ccode>CANT_URL\u003C\u002Fcode> para la cantidad deseada.\u003C\u002Fp>\n\u003Ch3>Update Log\u003C\u002Fh3>\n\u003Cul>\n\u003Cli>1.1 – Adding error message connecting with the Yahoo! Weather server\u003C\u002Fli>\n\u003Cli>1.0 – Yahoo! Weather reader\u003C\u002Fli>\n\u003C\u002Ful>\n","Lee el tiempo desde Yahoo! Weather, de los códigos de las ciudades insertadas en el formulario. Muestra en los templates con efecto slider.",6032,"2010-01-21T17:30:00.000Z","2.9.2","2.1",[118,51,52,21,53],"slider","http:\u002F\u002Fwordpress.org\u002Fextend\u002Fplugins\u002Fweather-slider\u002F","https:\u002F\u002Fdownloads.wordpress.org\u002Fplugin\u002Fweather-slider.1.1.zip",{"attackSurface":122,"codeSignals":147,"taintFlows":244,"riskAssessment":245,"analyzedAt":257},{"hooks":123,"ajaxHandlers":139,"restRoutes":140,"shortcodes":141,"cronEvents":146,"entryPointCount":33,"unprotectedCount":26},[124,130,134],{"type":125,"name":126,"callback":127,"file":128,"line":129},"action","admin_menu","baw_create_menu","inc\\options-page.php",2,{"type":125,"name":131,"callback":132,"file":128,"line":133},"admin_init","register_mysettings",13,{"type":125,"name":135,"callback":136,"file":137,"line":138},"widgets_init","anonymous","inc\\widget.php",43,[],[],[142],{"tag":4,"callback":143,"file":144,"line":145},"beautifulyahooweather_func","inc\\shortcode.php",103,[],{"dangerousFunctions":148,"sqlUsage":152,"outputEscaping":154,"fileOperations":33,"externalRequests":26,"nonceChecks":26,"capabilityChecks":26,"bundledLibraries":243},[149],{"fn":150,"file":137,"line":138,"context":151},"create_function","add_action( 'widgets_init', create_function('', 'return register_widget(\"byw\");') );",{"prepared":26,"raw":26,"locations":153},[],{"escaped":155,"rawEcho":156,"locations":157},236,56,[158,161,163,165,166,168,169,170,172,173,174,175,176,178,180,181,183,185,187,188,190,192,193,195,197,199,200,202,204,205,207,208,209,210,211,213,215,216,218,219,220,221,223,225,226,228,229,230,231,233,234,235,236,237,239,241],{"file":128,"line":159,"context":160},40,"raw output",{"file":128,"line":162,"context":160},961,{"file":144,"line":164,"context":160},51,{"file":144,"line":164,"context":160},{"file":144,"line":167,"context":160},54,{"file":144,"line":167,"context":160},{"file":144,"line":167,"context":160},{"file":144,"line":171,"context":160},55,{"file":144,"line":171,"context":160},{"file":144,"line":171,"context":160},{"file":144,"line":156,"context":160},{"file":144,"line":156,"context":160},{"file":144,"line":177,"context":160},57,{"file":144,"line":179,"context":160},58,{"file":144,"line":48,"context":160},{"file":144,"line":182,"context":160},61,{"file":144,"line":184,"context":160},64,{"file":144,"line":186,"context":160},65,{"file":144,"line":186,"context":160},{"file":144,"line":189,"context":160},68,{"file":144,"line":191,"context":160},69,{"file":144,"line":191,"context":160},{"file":144,"line":194,"context":160},72,{"file":144,"line":196,"context":160},73,{"file":144,"line":198,"context":160},75,{"file":144,"line":13,"context":160},{"file":144,"line":201,"context":160},80,{"file":144,"line":203,"context":160},81,{"file":144,"line":203,"context":160},{"file":144,"line":206,"context":160},83,{"file":144,"line":25,"context":160},{"file":144,"line":25,"context":160},{"file":144,"line":25,"context":160},{"file":144,"line":25,"context":160},{"file":144,"line":212,"context":160},87,{"file":144,"line":214,"context":160},88,{"file":144,"line":214,"context":160},{"file":144,"line":217,"context":160},92,{"file":144,"line":217,"context":160},{"file":144,"line":217,"context":160},{"file":144,"line":217,"context":160},{"file":144,"line":222,"context":160},94,{"file":144,"line":224,"context":160},95,{"file":144,"line":224,"context":160},{"file":144,"line":227,"context":160},99,{"file":144,"line":227,"context":160},{"file":144,"line":227,"context":160},{"file":144,"line":227,"context":160},{"file":137,"line":232,"context":160},15,{"file":137,"line":232,"context":160},{"file":137,"line":232,"context":160},{"file":137,"line":232,"context":160},{"file":137,"line":34,"context":160},{"file":137,"line":238,"context":160},34,{"file":137,"line":240,"context":160},37,{"file":137,"line":242,"context":160},39,[],[],{"summary":246,"deductions":247},"The 'beautiful-yahoo-weather' plugin v1.4.2 exhibits a generally good security posture with no recorded historical vulnerabilities and a commendable approach to SQL queries, utilizing prepared statements exclusively. The static analysis reveals a minimal attack surface, with only one shortcode entry point and no unprotected AJAX handlers or REST API routes. Furthermore, the absence of external HTTP requests and the limited file operations suggest a contained functionality that reduces the likelihood of external manipulation.\n\nHowever, there are notable concerns. The presence of the `create_function` dangerous function is a significant red flag, as it can be exploited for code injection if not handled with extreme care and robust sanitization, which is not evident from the provided data. While the majority of output is properly escaped (81%), a substantial portion (19%) remains unescaped, potentially opening the door to cross-site scripting (XSS) vulnerabilities. The complete absence of nonce checks and capability checks on the identified entry points is another critical weakness, allowing unauthenticated or unauthorized users to potentially trigger shortcode functionality, which could be leveraged in conjunction with other vulnerabilities.\n\nOverall, the plugin's clean vulnerability history is a positive indicator of developer diligence. Nevertheless, the identified static code issues—specifically `create_function` and the lack of nonce\u002Fcapability checks—present tangible risks that warrant attention. The partially unescaped output further contributes to the overall risk profile. While the plugin demonstrates strengths in SQL security and a limited attack surface, these specific code-level weaknesses detract from its security.",[248,250,253,255],{"reason":249,"points":232},"Dangerous function 'create_function' used",{"reason":251,"points":252},"Unescaped output present (19%)",8,{"reason":254,"points":81},"No nonce checks on entry points",{"reason":256,"points":81},"No capability checks on entry points","2026-03-16T20:37:08.137Z",{"wat":259,"direct":267},{"assetPaths":260,"generatorPatterns":262,"scriptPaths":263,"versionParams":264},[261],"\u002Fwp-content\u002Fplugins\u002Fbeautiful-yahoo-weather\u002Finc\u002Flang.php",[],[],[265,266],"beautiful-yahoo-weather\u002Fstyle.css?ver=","beautiful-yahoo-weather\u002Fjs\u002Fscript.js?ver=",{"cssClasses":268,"htmlComments":279,"htmlAttributes":280,"restEndpoints":290,"jsGlobals":291,"shortcodeOutput":294},[269,270,271,272,273,274,275,276,277,278],"weather-wid","now-weather","t-now-weather","c-now-weather","c-t-now-weather","w-c-t-now-weather","b-now-weather","today","ht-today","lt-today",[],[281,282,283,284,285,286,287,288,289],"direction:","background-color:","font-size:","color:","font-family:","height:","width:","float:","text-align:",[],[292,293],"window.weather","window.byw_options",[295,296,297,298,299,300],"\u003Cdiv class=\"weather-wid\"","\u003Cimg style=\"margin-bottom: -10px; float:","\u003Cdiv class=\"c-now-weather\"","\u003Cspan class=\"w-c-t-now-weather\"","\u003Cspan class=\"b-now-weather\"","\u003Cdiv class=\"today\"",{"error":302,"url":303,"statusCode":304,"statusMessage":305,"message":305},true,"http:\u002F\u002Flocalhost\u002Fapi\u002Fplugins\u002Fbeautiful-yahoo-weather\u002Fbundle",404,"no bundle for this plugin yet",{"slug":4,"current_version":6,"total_versions":33,"versions":307},[308],{"version":309,"download_url":310,"svn_tag_url":311,"released_at":27,"has_diff":312,"diff_files_changed":313,"diff_lines":27,"trac_diff_url":27,"vulnerabilities":314,"is_current":312},"1.3","https:\u002F\u002Fdownloads.wordpress.org\u002Fplugin\u002Fbeautiful-yahoo-weather.1.3.zip","https:\u002F\u002Fplugins.svn.wordpress.org\u002Fbeautiful-yahoo-weather\u002Ftags\u002F1.3\u002F",false,[],[]]