Weather Widget & Forecast by Meteoprog Security & Risk Analysis

wordpress.org/plugins/meteoprog-weather-informers

Add live local weather widgets and forecasts to WordPress. Gutenberg, Elementor, shortcodes. Free, unlimited, no API limits.

30 active installs v1.0.3 PHP 7.0+ WP 4.9+ Updated Dec 13, 2025
forecastlocal-weatherweatherweather-forecastweather-widget
100
A · Safe
CVEs total0
Unpatched0
Last CVENever
Safety Verdict

Is Weather Widget & Forecast by Meteoprog Safe to Use in 2026?

Generally Safe

Score 100/100

Weather Widget & Forecast by Meteoprog has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.

No known CVEs Updated 5mo ago
Risk Assessment

The "meteoprog-weather-informers" plugin v1.0.3 exhibits a generally good security posture, with no known vulnerabilities in its history and a promising static analysis report. The plugin demonstrates strong adherence to security best practices by implementing nonce checks and capability checks for its identified entry points, which consist of two shortcodes. A high percentage of its output (87%) is properly escaped, mitigating the risk of Cross-Site Scripting (XSS) vulnerabilities. The absence of critical or high-severity taint flows further reinforces its secure design.

However, there are areas that warrant attention. The most significant concern lies in the handling of SQL queries, as 100% of the four identified queries are not using prepared statements. This practice opens the door to SQL injection vulnerabilities, especially if any of the input feeding these queries can be influenced by external actors. While the plugin has a clean vulnerability history, this lack of prepared statements represents a latent risk that could be exploited. The presence of an external HTTP request also introduces a potential attack vector, though its nature and sanitization are not detailed in the provided data.

In conclusion, "meteoprog-weather-informers" v1.0.3 is well-developed in many security aspects, particularly regarding authentication and output sanitization. Its clean vulnerability record is a positive indicator. The primary weakness is the non-use of prepared statements for SQL queries, which should be addressed to ensure robust protection against SQL injection.

Key Concerns

  • 100% of SQL queries are not prepared
Vulnerabilities
None known

Weather Widget & Forecast by Meteoprog Security Vulnerabilities

No known vulnerabilities — this is a good sign.
Version History

Weather Widget & Forecast by Meteoprog Release Timeline

v1.0.3Current
v1.0.2
v1.0.1
Code Analysis
Analyzed Mar 16, 2026

Weather Widget & Forecast by Meteoprog Code Analysis

Dangerous Functions
0
Raw SQL Queries
4
0 prepared
Unescaped Output
13
84 escaped
Nonce Checks
4
Capability Checks
5
File Operations
0
External Requests
1
Bundled Libraries
0

SQL Query Safety

0% prepared4 total queries

Output Escaping

87% escaped97 total outputs
Data Flows · Security
All sanitized

Data Flow Analysis

3 flows
save_api_key (includes\class-meteoprog-informers-admin.php:169)
Source (user input) Sink (dangerous op) Sanitizer Transform Unsanitized Sanitized
Attack Surface

Weather Widget & Forecast by Meteoprog Attack Surface

Entry Points2
Unprotected0

Shortcodes 2

[meteoprog_informer] includes\class-meteoprog-informers-frontend.php:69
[su_meteoprog_informer] includes\integrations\integration-shortcodes-ultimate.php:134
WordPress Hooks 27
actionadmin_menuincludes\class-meteoprog-informers-admin.php:67
actionadmin_initincludes\class-meteoprog-informers-admin.php:68
actionadmin_post_meteoprog_save_api_keyincludes\class-meteoprog-informers-admin.php:70
actionadmin_post_meteoprog_refreshincludes\class-meteoprog-informers-admin.php:71
actionadmin_post_meteoprog_save_defaultincludes\class-meteoprog-informers-admin.php:72
actionadmin_enqueue_scriptsincludes\class-meteoprog-informers-admin.php:74
actioninitincludes\class-meteoprog-informers-block.php:74
actionenqueue_block_editor_assetsincludes\class-meteoprog-informers-block.php:75
actionrest_api_initincludes\class-meteoprog-informers-block.php:76
actionelementor/editor/after_enqueue_stylesincludes\class-meteoprog-informers-elementor.php:69
actionwp_enqueue_scriptsincludes\class-meteoprog-informers-elementor.php:72
actionelementor/initincludes\class-meteoprog-informers-elementor.php:75
actionelementor/widgets/registerincludes\class-meteoprog-informers-elementor.php:95
actionelementor/widgets/widgets_registeredincludes\class-meteoprog-informers-elementor.php:98
actionelementor/elements/categories_registeredincludes\class-meteoprog-informers-elementor.php:101
filterthe_contentincludes\class-meteoprog-informers-frontend.php:72
filterwidget_textincludes\class-meteoprog-informers-frontend.php:75
actioninitincludes\class-meteoprog-informers-frontend.php:78
actionwp_headincludes\class-meteoprog-informers-frontend.php:81
filterwp_resource_hintsincludes\class-meteoprog-informers-frontend.php:84
actionwidgets_initincludes\class-meteoprog-informers-widget.php:124
actioninitincludes\integrations\integration-shortcodes-ultimate.php:131
filtersu/data/shortcodesincludes\integrations\integration-shortcodes-ultimate.php:228
actionplugins_loadedmeteoprog-weather-informers.php:129
actionadmin_initmeteoprog-weather-informers.php:136
actionadmin_menumeteoprog-weather-informers.php:157
actionadmin_headmeteoprog-weather-informers.php:165
Maintenance & Trust

Weather Widget & Forecast by Meteoprog Maintenance & Trust

Maintenance Signals

WordPress version tested6.9.4
Last updatedDec 13, 2025
PHP min version7.0
Downloads445

Community Trust

Rating100/100
Number of ratings1
Active installs30
Developer Profile

Weather Widget & Forecast by Meteoprog Developer Profile

meteoprog

1 plugin · 30 total installs

94
trust score
Avg Security Score
100/100
Avg Patch Time
30 days
View full developer profile
Detection Fingerprints

How We Detect Weather Widget & Forecast by Meteoprog

Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.

Asset Fingerprints

Asset Paths
/wp-content/plugins/meteoprog-weather-informers/assets/css/backend-styles.css/wp-content/plugins/meteoprog-weather-informers/assets/js/backend.js/wp-content/plugins/meteoprog-weather-informers/assets/css/frontend-styles.css
Script Paths
/wp-content/plugins/meteoprog-weather-informers/assets/js/backend.js
Version Parameters
meteoprog-weather-informers/assets/css/backend-styles.css?ver=meteoprog-weather-informers/assets/js/backend.js?ver=meteoprog-weather-informers/assets/css/frontend-styles.css?ver=

HTML / DOM Fingerprints

CSS Classes
meteoprog-widget-containermeteoprog-widget-wrapmeteoprog-settings-wrap
Data Attributes
data-meteoprog-api-keydata-meteoprog-informer-id
JS Globals
meteoprog_admin_params
Shortcode Output
[meteoprog-weather-informer]
FAQ

Frequently Asked Questions about Weather Widget & Forecast by Meteoprog