Free Weather Security & Risk Analysis

wordpress.org/plugins/free-weather

Add a free 6-day weather forecast widget to your site. Clean design, accurate data — perfect for blogs, news, or travel websites.

300 active installs v1.0.0 PHP + WP 4.0.1+ Updated May 8, 2025
free-weatherweatherweather-forecastweather-pluginweather-widget
100
A · Safe
CVEs total0
Unpatched0
Last CVENever
Safety Verdict

Is Free Weather Safe to Use in 2026?

Generally Safe

Score 100/100

Free Weather has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.

No known CVEs Updated 11mo ago
Risk Assessment

The 'free-weather' plugin v1.0.0 exhibits a generally strong security posture based on the static analysis and vulnerability history. The code demonstrates good practices by utilizing prepared statements for all SQL queries and properly escaping almost all output. The absence of dangerous functions, file operations, and external HTTP requests further contributes to a reduced attack surface. Furthermore, the plugin has no recorded vulnerabilities, including CVEs, which is a significant positive indicator. The limited attack surface, consisting of a single shortcode with no apparent authentication checks, is a concern but mitigated by the lack of identified vulnerabilities in this area. The absence of taint analysis results also suggests no critical or high-severity issues were detected, further reinforcing the positive assessment.

Key Concerns

  • Shortcode without auth checks
  • Missing nonce checks
  • Missing capability checks
  • Slightly unescaped output
Vulnerabilities
None known

Free Weather Security Vulnerabilities

No known vulnerabilities — this is a good sign.
Code Analysis
Analyzed Mar 16, 2026

Free Weather Code Analysis

Dangerous Functions
0
Raw SQL Queries
0
0 prepared
Unescaped Output
3
150 escaped
Nonce Checks
0
Capability Checks
0
File Operations
0
External Requests
0
Bundled Libraries
0

Output Escaping

98% escaped153 total outputs
Attack Surface

Free Weather Attack Surface

Entry Points1
Unprotected0

Shortcodes 1

[weather] free-weather.php:442
WordPress Hooks 13
actionwidgets_initfree-weather.php:392
actionadmin_menufree-weather.php:457
actionadmin_initfree-weather.php:548
actionplugins_loadedfree-weather.php:561
actioninitfree-weather.php:602
actionenqueue_block_assetsfree-weather.php:613
actionenqueue_block_editor_assetsfree-weather.php:620
actioninitfree-weather.php:671
actionplugins_loadedincludes\class-weather.php:142
actionadmin_enqueue_scriptsincludes\class-weather.php:157
actionadmin_enqueue_scriptsincludes\class-weather.php:158
actionwp_enqueue_scriptsincludes\class-weather.php:173
actionwp_enqueue_scriptsincludes\class-weather.php:174
Maintenance & Trust

Free Weather Maintenance & Trust

Maintenance Signals

WordPress version tested6.8.5
Last updatedMay 8, 2025
PHP min version
Downloads4K

Community Trust

Rating0/100
Number of ratings0
Active installs300
Developer Profile

Free Weather Developer Profile

weather25

1 plugin · 300 total installs

94
trust score
Avg Security Score
100/100
Avg Patch Time
30 days
View full developer profile
Detection Fingerprints

How We Detect Free Weather

Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.

Asset Fingerprints

HTML / DOM Fingerprints

FAQ

Frequently Asked Questions about Free Weather