
Weather Widget & Forecast by Meteoprog Security & Risk Analysis
wordpress.org/plugins/meteoprog-weather-informersAdd live local weather widgets and forecasts to WordPress. Gutenberg, Elementor, shortcodes. Free, unlimited, no API limits.
Is Weather Widget & Forecast by Meteoprog Safe to Use in 2026?
Generally Safe
Score 100/100Weather Widget & Forecast by Meteoprog has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.
The "meteoprog-weather-informers" plugin v1.0.3 exhibits a generally good security posture, with no known vulnerabilities in its history and a promising static analysis report. The plugin demonstrates strong adherence to security best practices by implementing nonce checks and capability checks for its identified entry points, which consist of two shortcodes. A high percentage of its output (87%) is properly escaped, mitigating the risk of Cross-Site Scripting (XSS) vulnerabilities. The absence of critical or high-severity taint flows further reinforces its secure design.
However, there are areas that warrant attention. The most significant concern lies in the handling of SQL queries, as 100% of the four identified queries are not using prepared statements. This practice opens the door to SQL injection vulnerabilities, especially if any of the input feeding these queries can be influenced by external actors. While the plugin has a clean vulnerability history, this lack of prepared statements represents a latent risk that could be exploited. The presence of an external HTTP request also introduces a potential attack vector, though its nature and sanitization are not detailed in the provided data.
In conclusion, "meteoprog-weather-informers" v1.0.3 is well-developed in many security aspects, particularly regarding authentication and output sanitization. Its clean vulnerability record is a positive indicator. The primary weakness is the non-use of prepared statements for SQL queries, which should be addressed to ensure robust protection against SQL injection.
Key Concerns
- 100% of SQL queries are not prepared
Weather Widget & Forecast by Meteoprog Security Vulnerabilities
Weather Widget & Forecast by Meteoprog Release Timeline
Weather Widget & Forecast by Meteoprog Code Analysis
SQL Query Safety
Output Escaping
Data Flow Analysis
Weather Widget & Forecast by Meteoprog Attack Surface
Shortcodes 2
WordPress Hooks 27
Maintenance & Trust
Weather Widget & Forecast by Meteoprog Maintenance & Trust
Maintenance Signals
Community Trust
Weather Widget & Forecast by Meteoprog Alternatives
Global Weather Pro: Accurate Local Forecasts
global-weather-pro
Global Weather Pro is a powerful and easy-to-use WordPress plugin that delivers true hyper-local weather forecasts via two distinct weather widgets.
Free Weather
free-weather
Add a free 6-day weather forecast widget to your site. Clean design, accurate data — perfect for blogs, news, or travel websites.
Australian Weather Widget – WillyWeather
australian-weather-widget-willyweather
Australian weather widgets for Wordpress, with the latest data sourced from the Bureau of Meteorology (BoM). Custom designs to suit any website.
US Weather Widget – WillyWeather
us-weather-widget-willyweather
US weather widgets for Wordpress, with the latest data sourced from NOAA. Custom designs to suit any website.
Weather Forecast Widget
weather-forecast-widget
"Weather Forecast Widget" displays current weather and hourly/daily forecasts in a widget using a shortcode.
Weather Widget & Forecast by Meteoprog Developer Profile
1 plugin · 30 total installs
How We Detect Weather Widget & Forecast by Meteoprog
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/meteoprog-weather-informers/assets/css/backend-styles.css/wp-content/plugins/meteoprog-weather-informers/assets/js/backend.js/wp-content/plugins/meteoprog-weather-informers/assets/css/frontend-styles.css/wp-content/plugins/meteoprog-weather-informers/assets/js/backend.jsmeteoprog-weather-informers/assets/css/backend-styles.css?ver=meteoprog-weather-informers/assets/js/backend.js?ver=meteoprog-weather-informers/assets/css/frontend-styles.css?ver=HTML / DOM Fingerprints
meteoprog-widget-containermeteoprog-widget-wrapmeteoprog-settings-wrapdata-meteoprog-api-keydata-meteoprog-informer-idmeteoprog_admin_params[meteoprog-weather-informer]