
DobsonDev Weather Security & Risk Analysis
wordpress.org/plugins/dobsondev-weatherAdds a modern weather app to your site. The weather app is avaliable as both a widget and a shortcode.
Is DobsonDev Weather Safe to Use in 2026?
Generally Safe
Score 85/100DobsonDev Weather has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.
The "dobsondev-weather" v1.0 plugin presents a mixed security posture. On the positive side, it has no known vulnerabilities (CVEs) recorded, utilizes prepared statements for all its SQL queries, and has a small attack surface consisting of a single shortcode. There are no identified taint flows, indicating no obvious routes for malicious data to compromise the system in this regard. The plugin also avoids making external HTTP requests and does not bundle any libraries. However, significant security concerns arise from the lack of capability checks and nonce validation. The static analysis reveals zero capability checks and zero nonce checks, which is a major weakness. Furthermore, only 25% of its output is properly escaped, leaving a high probability for Cross-Site Scripting (XSS) vulnerabilities to be exploited through its shortcode. The presence of file operations without clear sanitization or context also warrants investigation.
Key Concerns
- Output escaping is insufficient (only 25%)
- No nonce checks implemented
- No capability checks implemented
- File operations present without evident sanitization
DobsonDev Weather Security Vulnerabilities
DobsonDev Weather Code Analysis
Output Escaping
DobsonDev Weather Attack Surface
Shortcodes 1
WordPress Hooks 4
Maintenance & Trust
DobsonDev Weather Maintenance & Trust
Maintenance Signals
Community Trust
DobsonDev Weather Alternatives
Location Weather – WordPress Weather Forecast, AQI, Temperature and Weather Widget
location-weather
Customizable WordPress Weather Forecast plugin to display Current Temperature, Hourly & Daily Forecasts, up to 16-Day, Air Quality, & Live Weather Map
Weather Atlas Widget
weather-atlas
The Weather Widget with the Most Active Installations. Highly customizable, simple & beautiful. Detailed current weather, hourly & daily forecasts
AWPLife Weather Effects
weather-effect
Add animated falling effects like snow, rain, autumn leaves, and seasonal decorations to your website.
wp-forecast
wp-forecast
wp-forecast is a highly customizable plugin for wordpress, showing weather-data from open-meteo.com and/or openweathermap.com.
Weather Underground
wunderground
Get accurate and beautiful weather forecasts powered by Wunderground.com
DobsonDev Weather Developer Profile
2 plugins · 110 total installs
How We Detect DobsonDev Weather
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/dobsondev-weather/dobsondev-weather-app.cssHTML / DOM Fingerprints
dobsondev-weather-appcurrent-weathertempcitycurrent-weather-iconthree-day-forecastdayname="dobsondev_weather_api_key"name="dobsondev_weather_widget"