
WindyCoat Security & Risk Analysis
wordpress.org/plugins/windycoatCSS Overrides
Is WindyCoat Safe to Use in 2026?
Generally Safe
Score 100/100WindyCoat has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.
The 'windycoat' plugin v1.3.0 presents a mixed security posture. On the positive side, it demonstrates good practices by avoiding dangerous functions, exclusively using prepared statements for SQL queries, and generally performing adequate output escaping. The absence of known vulnerabilities and critical taint flows is also a strong indicator of a relatively secure codebase. However, significant concerns arise from its attack surface. The plugin exposes one REST API route without any permission callbacks, making it a potential entry point for unauthorized access or manipulation if sensitive data or functionality is handled. Furthermore, the complete lack of nonce checks and capability checks across its entry points is a critical oversight, leaving it vulnerable to various attack vectors, including Cross-Site Request Forgery (CSRF) and privilege escalation if the exposed REST API route is exploited.
Key Concerns
- REST API route without permission callback
- No nonce checks
- No capability checks
- Unescaped output identified
WindyCoat Security Vulnerabilities
WindyCoat Code Analysis
Output Escaping
WindyCoat Attack Surface
REST API Routes 1
Shortcodes 1
WordPress Hooks 10
Scheduled Events 1
Maintenance & Trust
WindyCoat Maintenance & Trust
Maintenance Signals
Community Trust
WindyCoat Alternatives
Location Weather
pflegekorb-open-weather
Location Weather is a flexible and easy to use weather plugin that allows you to add unlimited weather widgets and get up-to-date weather information …
Weather Atlas Widget
weather-atlas
The Weather Widget with the Most Active Installations. Highly customizable, simple & beautiful. Detailed current weather, hourly & daily forecasts
Meteo
meteoart
Add an accurate French weather forecast to your site. Choose any city and country, then embed the customizable MeteoArt widget.
Weer
weer
This is a Dutch weather forecast widget, Just select your location and you are good to go!
Free Weather
free-weather
Add a free 6-day weather forecast widget to your site. Clean design, accurate data — perfect for blogs, news, or travel websites.
WindyCoat Developer Profile
2 plugins · 0 total installs
How We Detect WindyCoat
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/windycoat/weather/build//wp-content/plugins/windycoat/weather/build/static/js/bundle.jsHTML / DOM Fingerprints
wc-widget-wrapwc-widget<!-- WindyCoat Widget -->data-widget-iddata-widget-themedata-api-keydata-location-namedata-unitsdata-forecast-days+5 morewc_widget_config/wp-json/windycoat/v1/weather/[wc_weather