Prakiraan cuaca Security & Risk Analysis

wordpress.org/plugins/prakiraan-cuaca

This plugin supports you to receive earthquake information and weather forecasts for Jakarta and its surroundings

10 active installs v1.0.3 PHP + WP 4.4+ Updated Jul 29, 2023
commentsspam
85
A · Safe
CVEs total0
Unpatched0
Last CVENever
Safety Verdict

Is Prakiraan cuaca Safe to Use in 2026?

Generally Safe

Score 85/100

Prakiraan cuaca has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.

No known CVEs Updated 2yr ago
Risk Assessment

The 'prakiraan-cuaca' v1.0.3 plugin exhibits a generally strong security posture based on the provided static analysis and vulnerability history. The absence of known CVEs and a clean vulnerability history suggest a well-maintained and secure plugin over time. The code analysis reveals a minimal attack surface with only one shortcode and no AJAX handlers, REST API routes, or cron events that could be easily exploited. The plugin also demonstrates good practices in SQL query handling and output escaping, with all SQL queries using prepared statements and a high percentage of outputs being properly escaped. There are no identified dangerous functions, file operations, or external HTTP requests that pose an immediate risk. However, the plugin completely lacks nonce and capability checks, which represents a significant concern. While the current attack surface is small, any future addition of AJAX, REST API, or even more complex shortcode functionality without proper authentication and authorization mechanisms could open the door to serious vulnerabilities. The absence of taint analysis data makes it impossible to assess risks related to data sanitization and flow.

Key Concerns

  • Missing nonce checks
  • Missing capability checks
Vulnerabilities
None known

Prakiraan cuaca Security Vulnerabilities

No known vulnerabilities — this is a good sign.
Code Analysis
Analyzed Mar 17, 2026

Prakiraan cuaca Code Analysis

Dangerous Functions
0
Raw SQL Queries
0
0 prepared
Unescaped Output
1
5 escaped
Nonce Checks
0
Capability Checks
0
File Operations
0
External Requests
1
Bundled Libraries
0

Output Escaping

83% escaped6 total outputs
Attack Surface

Prakiraan cuaca Attack Surface

Entry Points1
Unprotected0

Shortcodes 1

[prakiraan-cuaca] includes\class-prakiraan-cuaca-dan-info-gempa.php:88
WordPress Hooks 5
actionplugins_loadedincludes\class-prakiraan-cuaca-dan-info-gempa.php:68
actionadmin_enqueue_scriptsincludes\class-prakiraan-cuaca-dan-info-gempa.php:76
actionadmin_enqueue_scriptsincludes\class-prakiraan-cuaca-dan-info-gempa.php:77
actionwp_enqueue_scriptsincludes\class-prakiraan-cuaca-dan-info-gempa.php:85
actionwp_enqueue_scriptsincludes\class-prakiraan-cuaca-dan-info-gempa.php:86
Maintenance & Trust

Prakiraan cuaca Maintenance & Trust

Maintenance Signals

WordPress version tested6.2.9
Last updatedJul 29, 2023
PHP min version
Downloads2K

Community Trust

Rating100/100
Number of ratings1
Active installs10
Developer Profile

Prakiraan cuaca Developer Profile

Helmi

3 plugins · 30 total installs

91
trust score
Avg Security Score
95/100
Avg Patch Time
30 days
View full developer profile
Detection Fingerprints

How We Detect Prakiraan cuaca

Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.

Asset Fingerprints

Asset Paths
/wp-content/plugins/prakiraan-cuaca-dan-info-gempa/admin/css/prakiraan-cuaca-dan-info-gempa-admin.css/wp-content/plugins/prakiraan-cuaca-dan-info-gempa/admin/js/prakiraan-cuaca-dan-info-gempa-admin.js/wp-content/plugins/prakiraan-cuaca-dan-info-gempa/public/css/prakiraan-cuaca-dan-info-gempa-public.css/wp-content/plugins/prakiraan-cuaca-dan-info-gempa/public/js/prakiraan-cuaca-dan-info-gempa-public.js
Script Paths
jquery
Version Parameters
prakiraan-cuaca-dan-info-gempa-adminprakiraan-cuaca-dan-info-gempa-public

HTML / DOM Fingerprints

Shortcode Output
[prakiraan_cuaca]
FAQ

Frequently Asked Questions about Prakiraan cuaca