
METAR plugin Security & Risk Analysis
wordpress.org/plugins/metar-widgetA simple widget to display the current METAR code (Pilot weather code) for a chosen ICAO station.
Is METAR plugin Safe to Use in 2026?
Generally Safe
Score 85/100METAR plugin has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.
The metar-widget plugin v0.1 presents a concerning security posture primarily due to a complete lack of output escaping. While the static analysis indicates no direct SQL injection vulnerabilities, dangerous functions, or external HTTP requests, the absence of output escaping on all 5 identified outputs creates a significant risk of Cross-Site Scripting (XSS) vulnerabilities. Any data processed and displayed by this plugin, if not properly sanitized by the WordPress core or other plugins, could be injected with malicious JavaScript. Furthermore, the plugin demonstrates a lack of fundamental security practices such as capability checks and nonce checks, which are crucial for protecting against unauthorized actions and CSRF attacks, especially if the plugin were to gain more entry points in future updates. The absence of any recorded vulnerability history is a positive indicator of past development, but it cannot compensate for the present critical security flaws identified in the code analysis. The plugin's strengths lie in its limited attack surface and apparent avoidance of direct database manipulation, but these are overshadowed by the high likelihood of XSS vulnerabilities due to unescaped output.
Key Concerns
- No output escaping found
- Missing capability checks
- Missing nonce checks
METAR plugin Security Vulnerabilities
METAR plugin Code Analysis
Output Escaping
METAR plugin Attack Surface
WordPress Hooks 1
Maintenance & Trust
METAR plugin Maintenance & Trust
Maintenance Signals
Community Trust
METAR plugin Alternatives
TAF plugin
taf-widget
A simple widget to display the current TAF (Terminal aerodrome forecast) code for a chosen ICAO station.
US Weather Widget – WillyWeather
us-weather-widget-willyweather
US weather widgets for Wordpress, with the latest data sourced from NOAA. Custom designs to suit any website.
Aviation Weather from NOAA
aviation-weather-from-noaa
Aviation weather data from NOAA's Aviation Digital Data Service (ADDS)
taf-metar-widget
wp-taf-metar-widget
This Widget allows you to show the TAF or METAR (aviation weather) information for any airport directly to your WordPress WebSite.
AviationWeather Plugin
aviationweather-widget
A simple widget to display current METAR and TAF for the chosen ICAO Station.
METAR plugin Developer Profile
2 plugins · 20 total installs
How We Detect METAR plugin
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
HTML / DOM Fingerprints
widget-wrapperwidget-titleid