
EasyWeather widget Security & Risk Analysis
wordpress.org/plugins/easyweather-widgetSimple and lightweight widget for displaying weather data and forecast from Weather Underground (www.wunderground.com).
Is EasyWeather widget Safe to Use in 2026?
Generally Safe
Score 85/100EasyWeather widget has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.
The Easyweather Widget plugin v1.0 exhibits a mixed security posture. On one hand, the absence of known CVEs and a clean taint analysis suggest a historically low impact from severe vulnerabilities. The use of prepared statements for all SQL queries is a significant strength, mitigating common SQL injection risks. However, several concerning practices are present in the static analysis. The plugin utilizes the `create_function` PHP construct, which is deprecated and can be a source of security issues if not handled with extreme care, especially in how user-supplied data might influence its execution. Furthermore, a very low percentage of output is properly escaped, indicating a high risk of Cross-Site Scripting (XSS) vulnerabilities, where malicious code could be injected into the front-end of a WordPress site. The lack of any capability checks or nonce checks, combined with a seemingly zero attack surface in terms of entry points, is unusual and might imply the plugin's functionality is very limited or relies entirely on other mechanisms for security, which is not ideal. The historical lack of vulnerabilities is positive, but the current code analysis reveals significant weaknesses that require immediate attention, particularly concerning output escaping and the use of `create_function`.
Key Concerns
- Use of deprecated 'create_function'
- Low percentage of properly escaped output
- No nonce checks on entry points
- No capability checks on entry points
EasyWeather widget Security Vulnerabilities
EasyWeather widget Code Analysis
Dangerous Functions Found
Output Escaping
EasyWeather widget Attack Surface
WordPress Hooks 1
Maintenance & Trust
EasyWeather widget Maintenance & Trust
Maintenance Signals
Community Trust
EasyWeather widget Alternatives
Weather Underground
wunderground
Get accurate and beautiful weather forecasts powered by Wunderground.com
Wettervorhersage
wettervorhersage
Get the new and amazing weather forecast widget, select location and colors, responsive widget.
Danielme Weather Widget
danielme-weather
A Wordpress widget that shows weather information based on SimpleWeather.js and WeatherIcons css.
Easy Maintenance
easy-maintenance
The most lightweight WordPress solution for quick maintenances.
Lightweight Slider
lightweight-slider
Lightweight image slider.
EasyWeather widget Developer Profile
1 plugin · 20 total installs
How We Detect EasyWeather widget
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/easyweather-widget/icons//wp-content/plugins/easyweather-widget/weather-data-.phpHTML / DOM Fingerprints
<table style="border-width: 0px" width="100%">
<tr>
<td colspan="3" style="text-align: center; font-size:20px"><b></b></td>
</tr>
<tr>
<td colspan="3" style="font-size:10px; text-align: center"></td>
</tr>
<tr>
<td style="text-align: center; vertical-align: middle; font-size: 25px; font-weight: bold"></td>
<td colspan="2"><center><img src="