
Gweather Security & Risk Analysis
wordpress.org/plugins/gweatherWith the gweather plugin you can display and embed Google Weather Feeds in your Wordpress posts and pages.
Is Gweather Safe to Use in 2026?
Generally Safe
Score 85/100Gweather has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.
The "gweather" plugin v1.10 exhibits a generally strong security posture based on the provided static analysis and vulnerability history. The code analysis reveals no dangerous functions, all SQL queries are properly prepared, and all output is correctly escaped. This indicates good development practices in handling sensitive operations and data presentation. Furthermore, the plugin has no recorded vulnerabilities (CVEs) of any severity, which suggests a history of secure development and maintenance.
While the plugin demonstrates strengths in core security areas, there are a few areas that warrant attention. The presence of two file operations, without further context, could potentially pose a risk if not handled securely, although no unsanitized paths were identified in the taint analysis. The absence of nonce checks and capability checks, while not directly leading to identified vulnerabilities in this version, represents a potential area for future exploitation if the attack surface were to expand or if other vulnerabilities were introduced. The single shortcode entry point is also noteworthy; while currently unprotected, it remains a potential vector if its functionality were to be extended in a way that handles user input.
In conclusion, "gweather" v1.10 appears to be a secure plugin at this time, with a clean vulnerability history and robust coding practices in critical areas. The primary areas for improvement lie in ensuring the secure implementation of file operations and considering the addition of nonce and capability checks for its existing and any future entry points to further harden its security posture.
Key Concerns
- File operations present without explicit checks
- Shortcode entry point lacks nonce checks
- Code lacks capability checks for entry points
Gweather Security Vulnerabilities
Gweather Release Timeline
Gweather Code Analysis
Gweather Attack Surface
Shortcodes 1
Maintenance & Trust
Gweather Maintenance & Trust
Maintenance Signals
Community Trust
Gweather Alternatives
Yahoo Currency
yahoo-currency
With the yahoo currency plugin you can display a feed of Yahoo Currency Exchange rates.
Omnifeed
omnifeed
With Omnifeed plugin you can display and embed RSS/ATOM feeds in your Wordpress posts and pages.
Disable Feeds
disable-feeds
Disables all RSS/Atom/RDF feeds on your WordPress site.
Disable Feeds WP
disable-feeds-wp
Disables all RSS/Atom/RDF feeds on your WordPress site.
FeedWordPress
feedwordpress
FeedWordPress syndicates content from feeds you choose into your WordPress weblog.
Gweather Developer Profile
2 plugins · 20 total installs
How We Detect Gweather
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
HTML / DOM Fingerprints
gweatherwp-link start of gweather content by gweather plugin v1.00 - http://www.citynews.co.za End of gweather content data-citydata-countrydata-tempdata-credit<table class="gweather"><th colspan='4'><strong>Current conditions for °C°F