
Wetterwarner Security & Risk Analysis
wordpress.org/plugins/wetterwarnerWetterwarner zeigt amtliche Wetterwarnungen für Deine eingestellte Region in einem Widget an.
Is Wetterwarner Safe to Use in 2026?
Generally Safe
Score 99/100Wetterwarner has a strong security track record. Known vulnerabilities have been patched promptly.
The plugin 'wetterwarner' v2.8 exhibits a mixed security posture. On the positive side, the static analysis reveals a clean slate regarding dangerous functions, SQL injection vulnerabilities (all queries use prepared statements), and taint analysis shows no critical or high severity unsanitized flows. The plugin also demonstrates good practices in output escaping, with a high percentage of outputs being properly handled. However, there are notable areas of concern. The complete absence of nonce checks and capability checks, particularly across the plugin's entry points, is a significant security weakness. While the attack surface is reported as zero unprotected entry points, the lack of these fundamental security mechanisms on the cron event means that any code executed by it could be triggered maliciously if an attacker can influence the cron job execution. The vulnerability history indicates a past Cross-site Scripting (XSS) vulnerability, and while currently unpatched vulnerabilities are zero, the presence of a previous XSS issue suggests that such vulnerabilities are within the plugin's historical risk profile and diligent code review is essential to prevent their recurrence. Overall, while the immediate static analysis suggests a low risk of direct code execution or data compromise through common web vulnerabilities, the lack of authentication and authorization checks on its cron event and the historical XSS issue warrant careful consideration.
Key Concerns
- Missing nonce checks on entry points
- Missing capability checks on entry points
- Historical XSS vulnerability
Wetterwarner Security Vulnerabilities
CVEs by Year
Severity Breakdown
1 total CVE
Wetterwarner <= 2.7.2 - Authenticated (Administrator+) Stored Cross-Site Scripting
Wetterwarner Code Analysis
Output Escaping
Wetterwarner Attack Surface
WordPress Hooks 12
Scheduled Events 1
Maintenance & Trust
Wetterwarner Maintenance & Trust
Maintenance Signals
Community Trust
Wetterwarner Alternatives
Wettervorhersage
wettervorhersage
Get the new and amazing weather forecast widget, select location and colors, responsive widget.
Wetter2
wetter
Beautiful English/German weather forecast widget, All locations around the world, no need for API key.
My Weather
my-weather
Display the weather for your city on the sidebar. Select from various layouts, designs and colours
Das Wetter von wetter.com
das-wetter-von-wettercom
Das Wetter Plugin für Wordpress von wetter.com zeigt aktuelle Wetterinformationen für die Stadt deiner Wahl an. Das Plugin ist leicht zu installieren …
schmie_Wetter
weather-for-germany
Update 5.06.11
Wetterwarner Developer Profile
1 plugin · 500 total installs
How We Detect Wetterwarner
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/wetterwarner/css/wetterwarner-styles.css/wp-content/plugins/wetterwarner/js/wetterwarner-script.js/wp-content/plugins/wetterwarner/js/wetterwarner-script.jswetterwarner-styles.css?ver=wetterwarner-script.js?ver=HTML / DOM Fingerprints
wetterwarner-widgetwetterwarner-introwetterwarner-map<!-- Wetterwarner Widget Starts --><!-- Wetterwarner Widget Ends -->data-feed-iddata-max-messagesdata-region-nameWetterwarner<div class="wetterwarner-widget"><div class="wetterwarner-warning"><div class="wetterwarner-map-container">