
Weather Widget Pro Security & Risk Analysis
wordpress.org/plugins/weather-in-any-city-widgetWeather Widget Pro provides a complete weather forecast for any location around the world.
Is Weather Widget Pro Safe to Use in 2026?
Generally Safe
Score 99/100Weather Widget Pro has a strong security track record. Known vulnerabilities have been patched promptly.
The "weather-in-any-city-widget" plugin v1.1.41 presents a mixed security posture. On the positive side, it demonstrates good practices with 100% of its SQL queries utilizing prepared statements and no dangerous functions identified in the static analysis. Furthermore, its vulnerability history indicates that the single known medium-severity CVE has been patched, which is a good sign.
However, significant concerns arise from the plugin's attack surface. With two AJAX handlers, both lacking authentication checks, there's a clear entry point for unauthorized actions. The relatively low percentage (47%) of properly escaped output also raises red flags, potentially leading to Cross-Site Scripting vulnerabilities if user-supplied data is not handled carefully. The absence of nonce checks on AJAX handlers further exacerbates this risk, as it allows for potential Cross-Site Request Forgery attacks.
In conclusion, while the plugin avoids some common pitfalls like raw SQL and dangerous functions, the unprotected AJAX endpoints and the insufficient output escaping are notable weaknesses. The historical medium-severity XSS vulnerability, though patched, serves as a reminder of the potential for such issues if input validation and output sanitization are not consistently robust.
Key Concerns
- AJAX handlers without authentication checks
- Low percentage of properly escaped output
- No nonce checks on AJAX handlers
Weather Widget Pro Security Vulnerabilities
CVEs by Year
Severity Breakdown
1 total CVE
Weather Widget Pro <= 1.1.40 - Authenticated (Contributor+) Stored Cross-Site Scripting
Weather Widget Pro Code Analysis
Output Escaping
Weather Widget Pro Attack Surface
AJAX Handlers 2
Shortcodes 1
WordPress Hooks 4
Maintenance & Trust
Weather Widget Pro Maintenance & Trust
Maintenance Signals
Community Trust
Weather Widget Pro Alternatives
My Weather
my-weather
Display the weather for your city on the sidebar. Select from various layouts, designs and colours
Tiempo
tiempo
Spanish and English weather widget, 6 days weather forecast,
Location Weather – WordPress Weather Forecast, AQI, Temperature and Weather Widget
location-weather
Customizable WordPress Weather Forecast plugin to display Current Temperature, Hourly & Daily Forecasts, up to 16-Day, Air Quality, & Live Weather Map
Weather Atlas Widget
weather-atlas
The Weather Widget with the Most Active Installations. Highly customizable, simple & beautiful. Detailed current weather, hourly & daily forecasts
wp-forecast
wp-forecast
wp-forecast is a highly customizable plugin for wordpress, showing weather-data from open-meteo.com and/or openweathermap.com.
Weather Widget Pro Developer Profile
2 plugins · 1K total installs
How We Detect Weather Widget Pro
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/weather-in-any-city-widget/css/wiycw-style.css/wp-content/plugins/weather-in-any-city-widget/js/wiycw-script.js/wp-content/plugins/weather-in-any-city-widget/js/wiycw-script.jsweather-in-any-city-widget/css/wiycw-style.css?ver=weather-in-any-city-widget/js/wiycw-script.js?ver=HTML / DOM Fingerprints
WIYCW_widgetdata-actiondata-urlWIYCW_i18n_dataWIYCW_widget_settings/wp-json/weather-in-any-city-widget/v1/get-weather