World weather – WWO Security & Risk Analysis

wordpress.org/plugins/world-weather-wwo

Weather widget.

10 active installs v1.6 PHP + WP 3.2+ Updated Aug 28, 2013
weatherwidget
85
A · Safe
CVEs total0
Unpatched0
Last CVENever
Download
Safety Verdict

Is World weather – WWO Safe to Use in 2026?

Generally Safe

Score 85/100

World weather – WWO has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.

No known CVEs Updated 12yr ago
Risk Assessment

The 'world-weather-wwo' plugin v1.6 exhibits a strong security posture in several key areas, demonstrating good practices. The absence of known CVEs and a clean vulnerability history indicate a commitment to security and a lack of previously exploited weaknesses. The plugin also correctly handles its SQL queries, using prepared statements exclusively, and does not appear to perform any file operations or bundle external libraries, which are positive indicators. However, there are significant areas for concern arising from the static analysis. The fact that only 25% of outputs are properly escaped presents a substantial risk of Cross-Site Scripting (XSS) vulnerabilities, especially considering there are 77 total outputs. Furthermore, the complete lack of nonce checks and capability checks on all entry points, coupled with zero AJAX handlers and REST API routes that require authentication, suggests a wide-open attack surface. This could allow unauthenticated users to trigger potentially sensitive actions or inject malicious code. While the plugin has no direct critical issues from taint analysis or dangerous functions, the high percentage of unescaped output and the absence of basic security checks on entry points present a significant risk that needs immediate attention.

Key Concerns

  • Low percentage of properly escaped output
  • No nonce checks on entry points
  • No capability checks on entry points
Vulnerabilities
None known

World weather – WWO Security Vulnerabilities

No known vulnerabilities — this is a good sign.
Code Analysis
Analyzed Mar 16, 2026

World weather – WWO Code Analysis

Dangerous Functions
0
Raw SQL Queries
0
0 prepared
Unescaped Output
58
19 escaped
Nonce Checks
0
Capability Checks
0
File Operations
0
External Requests
1
Bundled Libraries
0

Output Escaping

25% escaped77 total outputs
Attack Surface

World weather – WWO Attack Surface

Entry Points0
Unprotected0
WordPress Hooks 2
actionwidgets_init2046-world-weather.php:48
filterhttp_headers_useragentincludes\helpers.php:25
Maintenance & Trust

World weather – WWO Maintenance & Trust

Maintenance Signals

WordPress version tested3.6.1
Last updatedAug 28, 2013
PHP min version
Downloads6K

Community Trust

Rating20/100
Number of ratings1
Active installs10
Developer Profile

World weather – WWO Developer Profile

2046

6 plugins · 140 total installs

86
trust score
Avg Security Score
88/100
Avg Patch Time
30 days
View full developer profile
Detection Fingerprints

How We Detect World weather – WWO

Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.

Asset Fingerprints

HTML / DOM Fingerprints

FAQ

Frequently Asked Questions about World weather – WWO