Das Wetter von wetter.com Security & Risk Analysis

wordpress.org/plugins/das-wetter-von-wettercom

Das Wetter Plugin für Wordpress von wetter.com zeigt aktuelle Wetterinformationen für die Stadt deiner Wahl an. Das Plugin ist leicht zu installieren …

50 active installs v1.1 PHP + WP 3.0+ Updated May 3, 2017
forecastmeteovorhersageweatherwetter
85
A · Safe
CVEs total0
Unpatched0
Last CVENever
Safety Verdict

Is Das Wetter von wetter.com Safe to Use in 2026?

Generally Safe

Score 85/100

Das Wetter von wetter.com has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.

No known CVEs Updated 8yr ago
Risk Assessment

The plugin 'das-wetter-von-wettercom' v1.1 exhibits a generally strong security posture in several key areas, indicating good development practices. The absence of known CVEs and a history of vulnerabilities suggests a stable and well-maintained codebase. Static analysis reveals a commendable lack of direct SQL injection risks, with all queries utilizing prepared statements, and no dangerous functions or file operations being present. The plugin also has a limited attack surface with no apparent AJAX handlers, REST API routes, or shortcodes that could be easily exploited.

However, there are significant areas of concern that detract from its overall security. The most critical finding is the presence of two taint flows with unsanitized paths, indicating potential for attackers to manipulate file paths or other input that could lead to unexpected or malicious behavior. Furthermore, the very low percentage of properly escaped output (9%) is a serious red flag. This suggests a high risk of cross-site scripting (XSS) vulnerabilities, where malicious scripts could be injected into the website through plugin outputs. The lack of capability checks on any entry points is also a concern, meaning that even if an entry point existed, it would not be protected by WordPress's role-based access control.

In conclusion, while the plugin demonstrates strengths in avoiding common vulnerabilities like SQL injection and having a small attack surface, the identified taint flows and especially the widespread unescaped output present substantial risks. These issues require immediate attention to prevent potential security breaches.

Key Concerns

  • Taint flows with unsanitized paths found
  • Low percentage of properly escaped output (XSS risk)
  • No capability checks on entry points
Vulnerabilities
None known

Das Wetter von wetter.com Security Vulnerabilities

No known vulnerabilities — this is a good sign.
Code Analysis
Analyzed Mar 16, 2026

Das Wetter von wetter.com Code Analysis

Dangerous Functions
0
Raw SQL Queries
0
0 prepared
Unescaped Output
32
3 escaped
Nonce Checks
1
Capability Checks
0
File Operations
0
External Requests
2
Bundled Libraries
0

Output Escaping

9% escaped35 total outputs
Data Flows
2 unsanitized

Data Flow Analysis

2 flows2 with unsanitized paths
wettercom_config (wettercomAdmin.php:34)
Source (user input) Sink (dangerous op) Sanitizer Transform Unsanitized Sanitized
Attack Surface

Das Wetter von wetter.com Attack Surface

Entry Points0
Unprotected0
WordPress Hooks 4
actionwidgets_initwettercom.php:23
actionadmin_noticeswettercomAdmin.php:15
actionadmin_initwettercomAdmin.php:21
actionadmin_menuwettercomAdmin.php:26
Maintenance & Trust

Das Wetter von wetter.com Maintenance & Trust

Maintenance Signals

WordPress version tested4.7.32
Last updatedMay 3, 2017
PHP min version
Downloads9K

Community Trust

Rating30/100
Number of ratings2
Active installs50
Developer Profile

Das Wetter von wetter.com Developer Profile

wettercom

1 plugin · 50 total installs

84
trust score
Avg Security Score
85/100
Avg Patch Time
30 days
View full developer profile
Detection Fingerprints

How We Detect Das Wetter von wetter.com

Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.

Asset Fingerprints

Asset Paths
/wp-content/plugins/das-wetter-von-wettercom/widget.css
Version Parameters
das-wetter-von-wettercom/widget.css?ver=

HTML / DOM Fingerprints

CSS Classes
wettercomWidget
Shortcode Output
<a href="http://www.wetter.com/Das Wetter für
FAQ

Frequently Asked Questions about Das Wetter von wetter.com