Windspeed Converter Security & Risk Analysis

wordpress.org/plugins/wind-speed-converter

The Windspeed Converter gives you the possibility to insert a converter via widget or shortcode into your site.

10 active installs v1.3.0 PHP 7.4+ WP 5.0+ Updated Unknown
beaufortconverterknotsweatherwindspeed
100
A · Safe
CVEs total0
Unpatched0
Last CVENever
Safety Verdict

Is Windspeed Converter Safe to Use in 2026?

Generally Safe

Score 100/100

Windspeed Converter has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.

No known CVEs
Risk Assessment

The wind-speed-converter plugin v1.3.0 presents a mixed security posture. On the positive side, the static analysis reveals no dangerous functions, no direct SQL queries (all prepared statements), no file operations, and no external HTTP requests, which are all strong security indicators. The absence of known vulnerabilities in its history further suggests a generally well-maintained plugin. However, several areas raise concerns. The plugin lacks any nonce checks or capability checks, meaning that even its single shortcode entry point is not protected against potential unauthorized access or manipulation if a vulnerability were to be introduced in the future. Furthermore, only 55% of output is properly escaped, indicating a risk of Cross-Site Scripting (XSS) vulnerabilities if user-controlled data is outputted without sufficient sanitization.

Key Concerns

  • Missing nonce checks
  • Missing capability checks
  • Insufficient output escaping
Vulnerabilities
None known

Windspeed Converter Security Vulnerabilities

No known vulnerabilities — this is a good sign.
Code Analysis
Analyzed Mar 16, 2026

Windspeed Converter Code Analysis

Dangerous Functions
0
Raw SQL Queries
0
0 prepared
Unescaped Output
20
24 escaped
Nonce Checks
0
Capability Checks
0
File Operations
0
External Requests
0
Bundled Libraries
0

Output Escaping

55% escaped44 total outputs
Attack Surface

Windspeed Converter Attack Surface

Entry Points1
Unprotected0

Shortcodes 1

[windspeed_converter] windspeed-converter.php:87
WordPress Hooks 3
actionwidgets_initwindspeed-converter.php:48
actionwp_enqueue_scriptswindspeed-converter.php:56
actionwp_enqueue_scriptswindspeed-converter.php:74
Maintenance & Trust

Windspeed Converter Maintenance & Trust

Maintenance Signals

WordPress version tested6.9.4
Last updatedUnknown
PHP min version7.4
Downloads2K

Community Trust

Rating0/100
Number of ratings0
Active installs10
Developer Profile

Windspeed Converter Developer Profile

Andreas Ostheimer

2 plugins · 10 total installs

94
trust score
Avg Security Score
100/100
Avg Patch Time
30 days
View full developer profile
Detection Fingerprints

How We Detect Windspeed Converter

Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.

Asset Fingerprints

Asset Paths
/wp-content/plugins/wind-speed-converter/windspeed-converter.css/wp-content/plugins/wind-speed-converter/windspeed-converter.js/wp-content/plugins/wind-speed-converter/windspeed-converter-beaufort-scala.js
Script Paths
/wp-content/plugins/wind-speed-converter/windspeed-converter.js/wp-content/plugins/wind-speed-converter/windspeed-converter-beaufort-scala.js
Version Parameters
windspeed-converter.css?ver=windspeed-converter.js?ver=windspeed-converter-beaufort-scala.js?ver=

HTML / DOM Fingerprints

CSS Classes
wind_converterfieldinput_fieldmessageclear
Data Attributes
name="kmh"name="mph"name="beaufort"name="ms"name="knots"name="form_wind_converter"
JS Globals
wsconv_messages
Shortcode Output
<div id="wind_converter" class="wind_converter"><form name="form_wind_converter"><div id="kmh" class="field"><label>Km/h</label>
FAQ

Frequently Asked Questions about Windspeed Converter