TechGasp Weather Master Security & Risk Analysis

wordpress.org/plugins/weather-master

TechGasp Weather Master is the heavy duty, professional wordpress weather plugin. Just like on TV.

100 active installs v5.1.6 PHP + WP 3.5+ Updated Mar 10, 2021
forecastshortcodetechgaspweatherwidget
85
A · Safe
CVEs total0
Unpatched0
Last CVENever
Safety Verdict

Is TechGasp Weather Master Safe to Use in 2026?

Generally Safe

Score 85/100

TechGasp Weather Master has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.

No known CVEs Updated 5yr ago
Risk Assessment

The "weather-master" plugin v5.1.6 exhibits a strong security posture based on the provided static analysis. The absence of any identified attack surface points, dangerous functions, or external HTTP requests is commendable. Furthermore, the adherence to prepared statements for all SQL queries mitigates common SQL injection risks. However, a significant concern arises from the complete lack of output escaping. With 108 outputs analyzed and 0% properly escaped, this indicates a high potential for cross-site scripting (XSS) vulnerabilities, as user-supplied data could be injected and executed within the browser. The plugin's vulnerability history is clean, with no recorded CVEs, which suggests a good track record. Despite this, the lack of output escaping presents a critical weakness that could be easily exploited by attackers.

Key Concerns

  • 0% output escaping
Vulnerabilities
None known

TechGasp Weather Master Security Vulnerabilities

No known vulnerabilities — this is a good sign.
Code Analysis
Analyzed Mar 16, 2026

TechGasp Weather Master Code Analysis

Dangerous Functions
0
Raw SQL Queries
0
0 prepared
Unescaped Output
108
0 escaped
Nonce Checks
0
Capability Checks
0
File Operations
0
External Requests
0
Bundled Libraries
0

Output Escaping

0% escaped108 total outputs
Attack Surface

TechGasp Weather Master Attack Surface

Entry Points0
Unprotected0
WordPress Hooks 8
actionadmin_menuincludes\weather-master-admin-addons.php:39
actionadmin_menuincludes\weather-master-admin-addons.php:42
actionnetwork_admin_menuincludes\weather-master-admin.php:10
actionadmin_menuincludes\weather-master-admin.php:11
actionadmin_menuincludes\weather-master-admin.php:14
actionwidgets_initincludes\weather-master-widget-ow-fast.php:3
filterthe_contentweather-master.php:52
filterplugin_action_linksweather-master.php:53
Maintenance & Trust

TechGasp Weather Master Maintenance & Trust

Maintenance Signals

WordPress version tested5.7.15
Last updatedMar 10, 2021
PHP min version
Downloads37K

Community Trust

Rating58/100
Number of ratings19
Active installs100
Developer Profile

TechGasp Weather Master Developer Profile

TechGasp

19 plugins · 3K total installs

84
trust score
Avg Security Score
86/100
Avg Patch Time
30 days
View full developer profile
Detection Fingerprints

How We Detect TechGasp Weather Master

Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.

Asset Fingerprints

Asset Paths
/wp-content/plugins/weather-master/includes/weather-master-admin.php/wp-content/plugins/weather-master/includes/weather-master-admin-addons.php/wp-content/plugins/weather-master/includes/weather-master-widget-ow-fast.php
Script Paths
//openweathermap.org/themes/openweathermap/assets/vendor/owm/js/weather-widget-generator.js

HTML / DOM Fingerprints

CSS Classes
weather-master-error
Data Attributes
id="openweathermap-widget-22"
JS Globals
window.myWidgetParam
FAQ

Frequently Asked Questions about TechGasp Weather Master