
Weather Underground Security & Risk Analysis
wordpress.org/plugins/wundergroundGet accurate and beautiful weather forecasts powered by Wunderground.com
Is Weather Underground Safe to Use in 2026?
Generally Safe
Score 85/100Weather Underground has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.
The "wunderground" plugin version 2.1.3 exhibits a mixed security posture. On the positive side, it demonstrates good practices by exclusively using prepared statements for all SQL queries and has no recorded vulnerability history, suggesting a generally secure development approach. The absence of dangerous functions, file operations, and critical/high taint flows further bolsters its security. However, several areas raise concern. The presence of two AJAX handlers without authentication checks creates a significant attack surface. Additionally, a low rate of output escaping (33%) suggests potential for Cross-Site Scripting (XSS) vulnerabilities. While taint analysis found no issues, the limited scope of analysis (0 flows) and the identified unprotected entry points warrant caution.
Key Concerns
- Unprotected AJAX handlers
- Low percentage of properly escaped output
Weather Underground Security Vulnerabilities
Weather Underground Code Analysis
SQL Query Safety
Output Escaping
Weather Underground Attack Surface
AJAX Handlers 4
Shortcodes 2
WordPress Hooks 9
Maintenance & Trust
Weather Underground Maintenance & Trust
Maintenance Signals
Community Trust
Weather Underground Alternatives
Weather Widget
weather-widget
This widget displays the current condition, temperature, and the feels like temperature. It uses weather.com’s xoap api to retrieve the information.
Weather Spider
weather-spider-display-weather-forecast-on-your-blog
Place clean, nice-looking weather forecasts from weatherbug.com within your blog and sidebar.
WP Forecast Weather
wp-forecast-weather
Forecast Weather plugin for wordpress using Wunderground API.
WP Historical Weather
wp-historical-weather
Historical Weather plugin for wordpress using Wunderground API.
Location Weather – WordPress Weather Forecast, AQI, Temperature and Weather Widget
location-weather
Customizable WordPress Weather Forecast plugin to display Current Temperature, Hourly & Daily Forecasts, up to 16-Day, Air Quality, & Live Weather Map
Weather Underground Developer Profile
23 plugins · 14K total installs
How We Detect Weather Underground
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/wunderground/assets/css/wunderground.css/wp-content/plugins/wunderground/assets/css/admin.css/wp-content/plugins/wunderground/assets/js/widget.js/wp-content/plugins/wunderground/assets/js/widget.min.js/wp-content/plugins/wunderground/assets/js/widget.js/wp-content/plugins/wunderground/assets/js/widget.min.jswunderground/style.css?ver=wunderground.css?ver=admin.css?ver=widget.js?ver=HTML / DOM Fingerprints
data-wu-widgetWuWidget[wunderground][forecast]