[{"data":1,"prerenderedAt":-1},["ShallowReactive",2],{"$f2AV5C5TiwyMeHgXRmSM01iAS7FTuWObXFC-HbVk6TMk":3,"$fPL4-wEglkrTxXWhZH2BQYMrguGLLxOZ82yGg-vNay30":214,"$fhhPyZRPN43tm96_15BTgEvGf-8pSjrbZnzOq08Lf9Ww":219},{"slug":4,"name":5,"version":6,"author":7,"author_profile":8,"description":9,"short_description":10,"active_installs":11,"downloaded":12,"rating":13,"num_ratings":14,"last_updated":15,"tested_up_to":16,"requires_at_least":17,"requires_php":18,"tags":19,"homepage":23,"download_link":24,"security_score":25,"vuln_count":26,"unpatched_count":26,"last_vuln_date":27,"fetched_at":28,"discovery_status":29,"vulnerabilities":30,"developer":31,"crawl_stats":27,"alternatives":37,"analysis":122,"fingerprints":180},"yahoo-weather-plugin","Yahoo! Weather Plugin","1.1","zykhan","https:\u002F\u002Fprofiles.wordpress.org\u002Fzykhan\u002F","\u003Cp>Yahoo Weather Widget in new look, with multiple locations weather.Put your city weather in post\u002Fpage or widget. Easy to customize and support multi-widget.\u003Cbr \u002F>\nEnhanced Weather Icons and output with diffrent cities and two slider animation.\u003C\u002Fp>\n\u003Ch4>Options\u003C\u002Fh4>\n\u003Cul>\n\u003Cli>1.Admin Panel\u003C\u002Fli>\n\u003Cli>2.Inert Multiple Locations codes\u003C\u002Fli>\n\u003Cli>3.Temperature Options\u003C\u002Fli>\n\u003Cli>4.Easly customizable Stylesheets.\u003C\u002Fli>\n\u003Cli>4.Switch two front-end styles in admin panel\u003C\u002Fli>\n\u003C\u002Ful>\n\u003Ch4>Credits\u003C\u002Fh4>\n\u003Cul>\n\u003Cli>1.Yahoo Weather.\u003C\u002Fli>\n\u003Cli>2.Weather Location Codes\u002FIDs.\u003C\u002Fli>\n\u003C\u002Ful>\n\u003Ch3>Usage\u003C\u002Fh3>\n\u003Cul>\n\u003Cli>Use shorte code [ywsc] in your post\u002Fpage.\u003C\u002Fli>\n\u003Cli>Use as widget write shortcode [ywsc] in text widget.\u003C\u002Fli>\n\u003Cli>Note:if your theme does not support widget shortcode put  “add_filter(‘widget_text’, ‘do_shortcode’)” in yout function.php file.\u003C\u002Fli>\n\u003C\u002Ful>\n","Yahoo Weather Widget in new look, with multiple locations weather.Put your city weather in post\u002Fpage or widget. Easy to customize and support multi-wi &hellip;",10,4183,60,4,"2015-02-09T21:37:00.000Z","4.1.42","3.9","",[20,21,22],"feed","weather","yahoo","http:\u002F\u002Fiqonz.com","https:\u002F\u002Fdownloads.wordpress.org\u002Fplugin\u002Fyahoo-weather-plugin.1.1.zip",85,0,null,"2026-07-22T17:31:50.256Z","no_bundle",[],{"slug":7,"display_name":32,"profile_url":8,"plugin_count":14,"total_installs":33,"avg_security_score":25,"avg_patch_time_days":34,"trust_score":35,"computed_at":36},"faizykhan",50,30,84,"2026-08-29T05:18:38.758Z",[38,57,74,91,107],{"slug":39,"name":40,"version":41,"author":42,"author_profile":43,"description":44,"short_description":45,"active_installs":46,"downloaded":47,"rating":48,"num_ratings":49,"last_updated":50,"tested_up_to":51,"requires_at_least":52,"requires_php":18,"tags":53,"homepage":55,"download_link":56,"security_score":25,"vuln_count":26,"unpatched_count":26,"last_vuln_date":27,"fetched_at":28},"beautiful-yahoo-weather","Beautiful Yahoo Weather","1.4.2","Mohammad Pishdar","https:\u002F\u002Fprofiles.wordpress.org\u002Ffares_1990\u002F","\u003Cp>The Weather plugin enables you to get up-to-date weather information for your location.The Weather plugin is a dynamically-generated based on WOEID\u003C\u002Fp>\n\u003Ch4>Languages\u003C\u002Fh4>\n\u003Cp>persian english arabic bulgarian catalan chinese-simplified chinese-traditional danish dutch estonian finnish german french greek haitian-creole hindi indonesian italian japanese korean latvian maltese romanian russian spanish swedish turkish ukrainian vietnamese\u003C\u002Fp>\n","The Weather plugin enables you to get up-to-date weather information for your location.The Weather plugin is a dynamically-generated based on WOEID",100,28189,76,12,"2015-11-10T05:13:00.000Z","3.9.40","3.0.1",[54,21,22],"beautiful","http:\u002F\u002Fwww.wp-book.ir\u002F","https:\u002F\u002Fdownloads.wordpress.org\u002Fplugin\u002Fbeautiful-yahoo-weather.zip",{"slug":58,"name":59,"version":60,"author":61,"author_profile":62,"description":63,"short_description":64,"active_installs":33,"downloaded":65,"rating":13,"num_ratings":66,"last_updated":67,"tested_up_to":18,"requires_at_least":18,"requires_php":18,"tags":68,"homepage":72,"download_link":73,"security_score":25,"vuln_count":26,"unpatched_count":26,"last_vuln_date":27,"fetched_at":28},"clima","Clima","9","rodrigoart","https:\u002F\u002Fprofiles.wordpress.org\u002Frodrigoart\u002F","\u003Cp>Este plugin te permite traer los datos del clima de yahoo clima, vas a levantar la temperatura pudiendo eleigir entre\u003Cbr \u002F>\nCelcius o farenheit, y la imagen asociada a segun como este el tiempo, lluvia, despejado, nublado, etc. Podes mostrar esto mediante\u003Cbr \u002F>\nun widget o con la funcion \u003Ccode>\u003C?php show_clima();?>\u003C\u002Fcode> Añadido recientemente, podes traer por separado los valores, de temperatura, humedad, maxima, minima, etc. Usando  funciones como \u003Ccode>\u003C?php show_clima(humedad);?>\u003C\u002Fcode> mas info en seccion instalacion.\u003C\u002Fp>\n\u003Cp>This plugin allows you to bring data from yahoo weather climate, you can raise the temperature to between eleigir\u003Cbr \u002F>\nCelsius or Fahrenheit, and the image associated with depending on how this time, rain, clouds, cloudy, etc. You can show by\u003Cbr \u002F>\n     or use the widget. You can show temerature, humydity, wind direction, speed and more using functions like\u003Cbr \u002F>\n     more info in installation section.\u003C\u002Fp>\n","Este plugin te permite traer los datos del clima de yahoo clima, vas a levantar la temperatura pudiendo eleigir entre",19738,1,"2014-04-05T15:37:00.000Z",[58,69,70,21,71],"temperatura","temperature","yahoo-weather","http:\u002F\u002Fwww.rodrigoart.com.ar","https:\u002F\u002Fdownloads.wordpress.org\u002Fplugin\u002Fclima.zip",{"slug":71,"name":75,"version":76,"author":77,"author_profile":78,"description":79,"short_description":80,"active_installs":81,"downloaded":82,"rating":26,"num_ratings":26,"last_updated":83,"tested_up_to":84,"requires_at_least":18,"requires_php":18,"tags":85,"homepage":89,"download_link":90,"security_score":25,"vuln_count":26,"unpatched_count":26,"last_vuln_date":27,"fetched_at":28},"Yahoo Weather","1.3.4","magnus0","https:\u002F\u002Fprofiles.wordpress.org\u002Fmagnus0\u002F","\u003Cp>A simple Yahoo Weather widget\u003C\u002Fp>\n","A simple Yahoo Weather widget",20,19283,"2012-01-20T00:31:00.000Z","3.3.2",[86,21,87,88,22],"sidebar","widget","widgets","http:\u002F\u002Fwordpress.org\u002Fextend\u002Fplugins\u002Fyahoo-weather\u002F","https:\u002F\u002Fdownloads.wordpress.org\u002Fplugin\u002Fyahoo-weather.zip",{"slug":92,"name":93,"version":94,"author":95,"author_profile":96,"description":97,"short_description":98,"active_installs":11,"downloaded":99,"rating":26,"num_ratings":26,"last_updated":100,"tested_up_to":101,"requires_at_least":52,"requires_php":18,"tags":102,"homepage":104,"download_link":105,"security_score":25,"vuln_count":26,"unpatched_count":26,"last_vuln_date":27,"fetched_at":106},"clima-freekitime","clima freekitime","1.0","jmsv16","https:\u002F\u002Fprofiles.wordpress.org\u002Fjmsv16\u002F","\u003Cp>muestra el estado del clima de la ciudad que elijas utilizando la api de yahoo! weather, se implementa como funcion en la plantilla, shortcode o widge\u003C\u002Fp>\n\u003Ch3>Readme Generator\u003C\u002Fh3>\n\u003Cp>This Readme file was generated using \u003Ca href='http:\u002F\u002Fsudarmuthu.com\u002Fwordpress\u002Fwp-readme' rel=\"nofollow ugc\">wp-readme\u003C\u002Fa>, which generates readme files for WordPress Plugins.\u003C\u002Fp>\n","muestra el estado del clima de la ciudad que elijas utilizando la api de yahoo! weather, se implementa como funcion en la plantilla, shortcode o widge",3775,"2012-09-28T17:47:00.000Z","3.4.2",[103,58,21,71],"api","http:\u002F\u002Fclima.freekitime.com","https:\u002F\u002Fdownloads.wordpress.org\u002Fplugin\u002Fclima-freekitime.zip","2026-04-06T09:54:40.288Z",{"slug":108,"name":109,"version":110,"author":111,"author_profile":112,"description":113,"short_description":114,"active_installs":11,"downloaded":115,"rating":26,"num_ratings":26,"last_updated":116,"tested_up_to":117,"requires_at_least":118,"requires_php":18,"tags":119,"homepage":120,"download_link":121,"security_score":25,"vuln_count":26,"unpatched_count":26,"last_vuln_date":27,"fetched_at":28},"weather-man","Weather Man","1.00.0","binnyva","https:\u002F\u002Fprofiles.wordpress.org\u002Fbinnyva\u002F","\u003Cp>You can add the widget using the Widget page under Appearence.\u003C\u002Fp>\n\u003Ch3>1.00.0\u003C\u002Fh3>\n\u003Cul>\n\u003Cli>Beta release made.\u003C\u002Fli>\n\u003C\u002Ful>\n","Shows the weather as a widget in the sidebar.",5169,"2009-07-13T16:22:00.000Z","2.8","2.6",[103,21,87,22],"http:\u002F\u002Fwww.bin-co.com\u002Ftools\u002Fwordpress\u002Fplugins\u002Fweather-man\u002F","https:\u002F\u002Fdownloads.wordpress.org\u002Fplugin\u002Fweather-man.1.00.0.zip",{"attackSurface":123,"codeSignals":151,"taintFlows":165,"riskAssessment":166,"analyzedAt":179},{"hooks":124,"ajaxHandlers":143,"restRoutes":144,"shortcodes":145,"cronEvents":150,"entryPointCount":66,"unprotectedCount":26},[125,131,135,139],{"type":126,"name":127,"callback":128,"file":129,"line":130},"action","admin_init","yweather_init","index.php",25,{"type":126,"name":132,"callback":133,"file":129,"line":134},"admin_menu","weather_code_add_page",26,{"type":126,"name":136,"callback":137,"file":129,"line":138},"wp_head","my_ss",86,{"type":126,"name":140,"callback":141,"file":129,"line":142},"wp_footer","ss_boxslide",124,[],[],[146],{"tag":147,"callback":148,"file":129,"line":149},"ywsc","yw",125,[],{"dangerousFunctions":152,"sqlUsage":153,"outputEscaping":155,"fileOperations":66,"externalRequests":26,"nonceChecks":26,"capabilityChecks":26,"bundledLibraries":164},[],{"prepared":26,"raw":26,"locations":154},[],{"escaped":26,"rawEcho":156,"locations":157},3,[158,160,162],{"file":129,"line":13,"context":159},"raw output",{"file":129,"line":161,"context":159},62,{"file":129,"line":163,"context":159},222,[],[],{"summary":167,"deductions":168},"The \"yahoo-weather-plugin\" v1.1 plugin exhibits a generally strong security posture based on the provided static analysis. The absence of known vulnerabilities, including critical or high severity ones, and the complete avoidance of raw SQL queries and external HTTP requests are significant strengths.  Furthermore, the plugin has no recorded CVEs, indicating a history of security diligence or a lack of widespread exploitation.  The limited attack surface, consisting solely of a single shortcode with no identified entry points requiring authentication, is also a positive indicator.\n\nHowever, there are notable concerns regarding output escaping. With 3 total outputs and 0% properly escaped, there is a high likelihood of cross-site scripting (XSS) vulnerabilities. This is a critical weakness that can be exploited by attackers to inject malicious scripts into web pages, potentially leading to session hijacking, defacement, or redirection to malicious sites. The lack of nonce checks and capability checks also contributes to this risk, as these are standard security measures to prevent unauthorized actions and ensure proper authorization for user interactions. The single file operation also warrants attention, though without further context, its specific risk is unclear.\n\nIn conclusion, while the plugin demonstrates good practices in areas like SQL handling and external requests, the severe deficiency in output escaping presents a significant and immediate security risk. The absence of known vulnerabilities is encouraging, but it does not negate the inherent danger posed by unescaped output. Addressing the output escaping and implementing proper nonce and capability checks should be the highest priority to improve the plugin's overall security.",[169,172,175,177],{"reason":170,"points":171},"Unescaped output",8,{"reason":173,"points":174},"Missing nonce checks",7,{"reason":176,"points":174},"Missing capability checks",{"reason":178,"points":156},"Unclear risk from file operation","2026-04-16T12:52:42.616Z",{"wat":181,"direct":194},{"assetPaths":182,"generatorPatterns":187,"scriptPaths":188,"versionParams":189},[183,184,185,186],"\u002Fwp-content\u002Fplugins\u002Fyahoo-weather-plugin\u002Fcss\u002Fjquery.bxslider.css","\u002Fwp-content\u002Fplugins\u002Fyahoo-weather-plugin\u002Fcss\u002Fstyle1.css","\u002Fwp-content\u002Fplugins\u002Fyahoo-weather-plugin\u002Fcss\u002Fstyle2.css","\u002Fwp-content\u002Fplugins\u002Fyahoo-weather-plugin\u002Fjs\u002Fjquery.bxslider.js",[],[186],[190,191,192,193],"yahoo-weather-plugin\u002Fjs\u002Fjquery.bxslider.js?ver=","yahoo-weather-plugin\u002Fcss\u002Fstyle1.css?ver=","yahoo-weather-plugin\u002Fcss\u002Fstyle2.css?ver=","yahoo-weather-plugin\u002Fcss\u002Fjquery.bxslider.css?ver=",{"cssClasses":195,"htmlComments":203,"htmlAttributes":204,"restEndpoints":208,"jsGlobals":209,"shortcodeOutput":212},[21,196,197,198,199,200,201,202],"bxslider","temp_text","temp","unit","bd","cond","yom-mod",[],[205,206,207],"name='city_unit[city]'","name='city_unit[temp]'","name='ywstyles'",[],[210,211],"jQuery","$",[213],"\u003Cdiv class=\"weather\">\u003Cdiv class=\"bxslider\">",{"error":215,"url":216,"statusCode":217,"statusMessage":218,"message":218},true,"http:\u002F\u002Flocalhost\u002Fapi\u002Fplugins\u002Fyahoo-weather-plugin\u002Fbundle",404,"no bundle for this plugin yet",{"slug":4,"current_version":6,"total_versions":220,"versions":221},2,[222,228],{"version":6,"download_url":24,"svn_tag_url":223,"released_at":27,"has_diff":224,"diff_files_changed":225,"diff_lines":27,"trac_diff_url":226,"vulnerabilities":227,"is_current":215},"https:\u002F\u002Fplugins.svn.wordpress.org\u002Fyahoo-weather-plugin\u002Ftags\u002F1.1\u002F",false,[],"https:\u002F\u002Fplugins.trac.wordpress.org\u002Fchangeset?old_path=%2Fyahoo-weather-plugin%2Ftags%2F1.0&new_path=%2Fyahoo-weather-plugin%2Ftags%2F1.1",[],{"version":94,"download_url":229,"svn_tag_url":230,"released_at":27,"has_diff":224,"diff_files_changed":231,"diff_lines":27,"trac_diff_url":27,"vulnerabilities":232,"is_current":224},"https:\u002F\u002Fdownloads.wordpress.org\u002Fplugin\u002Fyahoo-weather-plugin.1.0.zip","https:\u002F\u002Fplugins.svn.wordpress.org\u002Fyahoo-weather-plugin\u002Ftags\u002F1.0\u002F",[],[]]