
National Weather Service Alerts Security & Risk Analysis
wordpress.org/plugins/national-weather-service-alertsEasily add official National Weather Service alerts to your website.
Is National Weather Service Alerts Safe to Use in 2026?
Use With Caution
Score 61/100National Weather Service Alerts has 1 unpatched vulnerability. Evaluate alternatives or apply available mitigations.
The "national-weather-service-alerts" plugin exhibits significant security weaknesses despite some positive signs. The static analysis reveals a substantial attack surface with 4 out of 5 entry points lacking authentication checks, which is a critical concern. Furthermore, the complete absence of prepared statements for SQL queries and a very low percentage (19%) of properly escaped output indicate a high risk of SQL injection and cross-site scripting (XSS) vulnerabilities. The taint analysis, while not flagging critical or high-severity issues, did identify flows with unsanitized paths, which could potentially be exploited if combined with other weaknesses.
The vulnerability history is particularly concerning. The presence of one known high-severity CVE, which is currently unpatched, directly points to a "PHP Remote File Inclusion" vulnerability. This, coupled with the plugin's lack of robust input validation and output sanitization, suggests a history of exploitable flaws. While the plugin doesn't bundle libraries or use dangerous functions, the identified weaknesses in authentication, data handling, and the historical exploitability create a precarious security posture.
In conclusion, while the absence of dangerous functions and bundled libraries is a minor positive, the plugin's overall security is poor. The high number of unprotected entry points, raw SQL queries, insufficient output escaping, and a recent high-severity unpatched vulnerability present a substantial risk to WordPress sites using this plugin. The current unpatched vulnerability is a critical indicator of immediate danger.
Key Concerns
- Unpatched High Severity CVE
- 4 AJAX handlers without auth checks
- 100% of SQL queries without prepared statements
- Low percentage of properly escaped output (19%)
- Flows with unsanitized paths identified
- No capability checks
National Weather Service Alerts Security Vulnerabilities
CVEs by Year
Severity Breakdown
1 total CVE
National Weather Service Alerts <= 1.3.5 - Unauthenticated Local File Inclusion
National Weather Service Alerts Code Analysis
SQL Query Safety
Output Escaping
Data Flow Analysis
National Weather Service Alerts Attack Surface
AJAX Handlers 4
Shortcodes 1
WordPress Hooks 14
Maintenance & Trust
National Weather Service Alerts Maintenance & Trust
Maintenance Signals
Community Trust
National Weather Service Alerts Alternatives
SiteGuard WP Plugin
siteguard
SiteGurad WP Plugin is the plugin specialized for the protection against the attack to the management page and login.
VK Blocks
vk-blocks
This is a plugin that extends Gutenberg's blocks.
Customize WordPress Emails and Alerts – Better Notifications for WP
bnfw
Supercharge your WordPress email notifications using a WYSIWYG editor and shortcodes. Default and new notifications available. Add-ons available.
Notification – Custom Notifications and Alerts for WordPress
notification
Take full control of WordPress emails and notifications. Replace default messages, add custom triggers, and send alerts via email, webhook, Slack, and …
WP Notification Bars
wp-notification-bars
Create custom notification and alert bar for marketing promotions, alerts, increasing click throughs to other pages and so much more.
National Weather Service Alerts Developer Profile
1 plugin · 100 total installs
How We Detect National Weather Service Alerts
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/national-weather-service-alerts/css/nws-alerts.css/wp-content/plugins/national-weather-service-alerts/js/nws-alerts.js/wp-content/plugins/national-weather-service-alerts/js/nws-alerts-widget.js/wp-content/plugins/national-weather-service-alerts/css/nws-alerts-admin.cssnational-weather-service-alerts/css/nws-alerts.css?ver=national-weather-service-alerts/js/nws-alerts.js?ver=national-weather-service-alerts/js/nws-alerts-widget.js?ver=national-weather-service-alerts/css/nws-alerts-admin.css?ver=HTML / DOM Fingerprints
nws-alerts-widget-titlenws-alerts-widget-zip-errornws-alerts-widget-zip-requirednws-alerts-widget-location-errornws-alerts-widget-forecast-errornws-alerts-widget-alert-errornws-alerts-widget-alert-headlinenws-alerts-widget-alert-description+13 moredata-nws-alerts-zipdata-nws-alerts-zip-placeholderdata-nws-alerts-location-placeholderdata-nws-alerts-forecast-placeholderdata-nws-alerts-alert-placeholderdata-nws-alerts-widget-id+5 moreajaxurl/wp-json/nws-alerts/v1/alerts[nws_alerts]