Weer Security & Risk Analysis

wordpress.org/plugins/weer

This is a Dutch weather forecast widget, Just select your location and you are good to go!

500 active installs v1.0.0 PHP + WP 4.0.1+ Updated Mar 1, 2024
weather-widgetweerweer-pluginweerberichtweervoorspelling
85
A · Safe
CVEs total0
Unpatched0
Last CVENever
Safety Verdict

Is Weer Safe to Use in 2026?

Generally Safe

Score 85/100

Weer has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.

No known CVEs Updated 2yr ago
Risk Assessment

The "weer" v1.0.0 plugin exhibits a seemingly robust security posture based on the provided static analysis. The absence of any identified entry points like AJAX handlers, REST API routes, shortcodes, or cron events significantly limits the attack surface. Furthermore, the code signals show a promising lack of dangerous functions and file operations. The fact that all SQL queries are prepared statements is a strong indication of good practice in preventing SQL injection vulnerabilities. The vulnerability history is also clean, with no known CVEs, which suggests a low likelihood of past exploitable issues. However, a significant concern arises from the low percentage of properly escaped output (16%). This indicates that a substantial portion of dynamic content rendered by the plugin could be vulnerable to cross-site scripting (XSS) attacks, especially if user-supplied data is not adequately sanitized before output. While the current analysis reveals no direct taint flows or critical issues, the lack of output escaping represents a substantial and potentially exploitable weakness that needs immediate attention. Therefore, despite its strengths in other areas, the poor handling of output escaping presents a notable risk.

Key Concerns

  • Low percentage of properly escaped output
Vulnerabilities
None known

Weer Security Vulnerabilities

No known vulnerabilities — this is a good sign.
Code Analysis
Analyzed Mar 16, 2026

Weer Code Analysis

Dangerous Functions
0
Raw SQL Queries
0
0 prepared
Unescaped Output
43
8 escaped
Nonce Checks
0
Capability Checks
0
File Operations
0
External Requests
0
Bundled Libraries
0

Output Escaping

16% escaped51 total outputs
Attack Surface

Weer Attack Surface

Entry Points0
Unprotected0
WordPress Hooks 6
actionplugins_loadedincludes\class-weer.php:142
actionadmin_enqueue_scriptsincludes\class-weer.php:157
actionadmin_enqueue_scriptsincludes\class-weer.php:158
actionwp_enqueue_scriptsincludes\class-weer.php:173
actionwp_enqueue_scriptsincludes\class-weer.php:174
actionwidgets_initweer.php:372
Maintenance & Trust

Weer Maintenance & Trust

Maintenance Signals

WordPress version tested6.4.8
Last updatedMar 1, 2024
PHP min version
Downloads6K

Community Trust

Rating100/100
Number of ratings1
Active installs500
Developer Profile

Weer Developer Profile

weer1

1 plugin · 500 total installs

84
trust score
Avg Security Score
85/100
Avg Patch Time
30 days
View full developer profile
Detection Fingerprints

How We Detect Weer

Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.

Asset Fingerprints

Asset Paths
/wp-content/plugins/weer/weer-widget.js/wp-content/plugins/weer/weer-widget.css
Script Paths
/wp-content/plugins/weer/weer-widget.js
Version Parameters
weer/weer-widget.js?ver=weer/weer-widget.css?ver=

HTML / DOM Fingerprints

CSS Classes
weer-widgetweather_widget_wrapweather_widget_placeholder
Data Attributes
data-text-colordata-backgrounddata-widthdata-headerdata-daysdata-sunrise+6 more
JS Globals
weer_widget
Shortcode Output
<div class="weather_widget_placeholder"></div><div style="font-size: 14px;text-align: center;padding-top: 6px;padding-bottom: 4px;background: rgba(0,0,0,0.03);">Powered by <a target="_blank" href="https://www.weer1.com">Weer1.com</a></div>
FAQ

Frequently Asked Questions about Weer