Spelhubben Weather Security & Risk Analysis

wordpress.org/plugins/spelhubben-weather

Weather widget, Gutenberg block and shortcode with optional map and multi-provider forecasts.

10 active installs v2.0.2 PHP 7.4+ WP 6.9.4+ Updated Mar 11, 2026
blocksforecastshortcodeweatherwidget
100
A · Safe
CVEs total0
Unpatched0
Last CVENever
Download
Safety Verdict

Is Spelhubben Weather Safe to Use in 2026?

Generally Safe

Score 100/100

Spelhubben Weather has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.

No known CVEs Updated 22d ago
Risk Assessment

The spelhubben-weather plugin v2.0.2 exhibits a generally good security posture, with a strong adherence to secure coding practices. The complete absence of critical or high-severity taint flows, along with the fact that all SQL queries utilize prepared statements, indicates a conscious effort to prevent common web vulnerabilities like SQL injection. Furthermore, the high percentage of properly escaped output suggests a good understanding of preventing Cross-Site Scripting (XSS) attacks. The plugin also benefits from a clean vulnerability history, with no known CVEs, which is a positive sign of its past security maintenance.

However, there are notable areas for improvement. The presence of 2 out of 4 entry points being unprotected is a significant concern. Specifically, 2 AJAX handlers lack authentication checks, opening the door for potential unauthorized actions or information disclosure if these handlers perform sensitive operations. While the total attack surface isn't massive, these unprotected entry points represent a direct vulnerability. The plugin's reliance on external HTTP requests (14) also warrants careful monitoring, as misconfigurations or vulnerabilities in external services could indirectly impact the plugin's security.

In conclusion, spelhubben-weather v2.0.2 demonstrates a solid foundation in secure coding. The lack of known vulnerabilities and the use of prepared statements are strengths. The primary weakness lies in the unprotected AJAX handlers, which represent a direct and exploitable risk. Addressing these unprotected entry points should be the immediate priority to further harden the plugin's security.

Key Concerns

  • 2 unprotected AJAX handlers
Vulnerabilities
None known

Spelhubben Weather Security Vulnerabilities

No known vulnerabilities — this is a good sign.
Code Analysis
Analyzed Mar 17, 2026

Spelhubben Weather Code Analysis

Dangerous Functions
0
Raw SQL Queries
0
4 prepared
Unescaped Output
42
527 escaped
Nonce Checks
10
Capability Checks
12
File Operations
1
External Requests
14
Bundled Libraries
0

SQL Query Safety

100% prepared4 total queries

Output Escaping

93% escaped569 total outputs
Data Flows
All sanitized

Data Flow Analysis

2 flows
sv_vader_handle_import_settings (admin\admin.php:139)
Source (user input) Sink (dangerous op) Sanitizer Transform Unsanitized Sanitized
Attack Surface
2 unprotected

Spelhubben Weather Attack Surface

Entry Points4
Unprotected2

AJAX Handlers 3

authwp_ajax_svv_check_attribadmin\admin.php:260
authwp_ajax_svv_preview_shortcodeadmin\admin.php:643
authwp_ajax_svv_load_wporg_showcaseadmin\admin.php:681

Shortcodes 1

[spelhubben_weather] includes\class-plugin.php:48
WordPress Hooks 16
actionadmin_enqueue_scriptsadmin\admin.php:107
actionadmin_post_svv_export_settingsadmin\admin.php:132
actionadmin_post_svv_import_settingsadmin\admin.php:205
actionadmin_menuadmin\admin.php:319
actionadmin_initadmin\admin.php:358
actionadmin_post_svv_reset_defaultsadmin\admin.php:378
actioninitincludes\class-plugin.php:23
actioninitincludes\class-plugin.php:24
actioninitincludes\class-plugin.php:25
actionwp_enqueue_scriptsincludes\class-plugin.php:26
actionadmin_menuincludes\class-plugin.php:30
actionadmin_initincludes\class-plugin.php:33
actionwidgets_initincludes\class-plugin.php:37
actionvc_before_initincludes\integrations\vc.php:7
actionwidgets_initspelhubben-weather.php:91
actionplugins_loadedspelhubben-weather.php:100
Maintenance & Trust

Spelhubben Weather Maintenance & Trust

Maintenance Signals

WordPress version tested6.9.4
Last updatedMar 11, 2026
PHP min version7.4
Downloads1K

Community Trust

Rating0/100
Number of ratings0
Active installs10
Developer Profile

Spelhubben Weather Developer Profile

Kenta Mattsson

1 plugin · 10 total installs

94
trust score
Avg Security Score
100/100
Avg Patch Time
30 days
View full developer profile
Detection Fingerprints

How We Detect Spelhubben Weather

Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.

Asset Fingerprints

Asset Paths
/wp-content/plugins/spelhubben-weather/admin/admin.css/wp-content/plugins/spelhubben-weather/admin/admin.js/wp-content/plugins/spelhubben-weather/assets/style.css/wp-content/plugins/spelhubben-weather/assets/vendor/leaflet/leaflet.css/wp-content/plugins/spelhubben-weather/assets/vendor/leaflet/leaflet.js/wp-content/plugins/spelhubben-weather/assets/map.js
Script Paths
/wp-content/plugins/spelhubben-weather/admin/admin.js
Version Parameters
spelhubben-weather/admin/admin.css?ver=spelhubben-weather/admin/admin.js?ver=spelhubben-weather/assets/style.css?ver=spelhubben-weather/assets/vendor/leaflet/leaflet.css?ver=spelhubben-weather/assets/vendor/leaflet/leaflet.js?ver=spelhubben-weather/assets/map.js?ver=

HTML / DOM Fingerprints

CSS Classes
sv-vader-admin
HTML Comments
Copyright (C) 2026 Spelhubben Licensed under the GNU General Public License v3 (or later) https://www.gnu.org/licenses/gpl-3.0.html admin/admin.php+10 more
Data Attributes
data-copieddata-copydata-expanddata-collapsedata-renderingdata-ok+9 more
JS Globals
SVV_ADMIN_I18N
FAQ

Frequently Asked Questions about Spelhubben Weather