Vertical Timeline Widget for Elementor Security & Risk Analysis

wordpress.org/plugins/3r-elementor-timeline-widget

Use a vertical timeline widget for Elementor to showcase your journey, story, milestones, or roadmap directly inside Elementor.

10K active installs v2.7.2 PHP 7.2+ WP 5.2+ Updated Jan 29, 2026
elementorelementor-timelinetimelinevertical-timelinewidget
100
A · Safe
CVEs total1
Unpatched0
Last CVEDec 4, 2023
Safety Verdict

Is Vertical Timeline Widget for Elementor Safe to Use in 2026?

Generally Safe

Score 100/100

Vertical Timeline Widget for Elementor has a strong security track record. Known vulnerabilities have been patched promptly.

1 known CVELast CVE: Dec 4, 2023Updated 2mo ago
Risk Assessment

The plugin '3r-elementor-timeline-widget' v2.7.2 exhibits a generally strong security posture based on the static analysis. The absence of dangerous functions, SQL injection risks through prepared statements, file operations, and external HTTP requests is commendable. Crucially, all identified entry points, including AJAX handlers, are protected by nonce checks, and there are no unescaped outputs flagged as critical. This indicates good development practices in sanitizing input and output and securing critical functionalities.

However, the static analysis does reveal a concerning lack of capability checks across all entry points. While nonce checks provide a basic layer of protection against CSRF attacks, they do not prevent authenticated users from accessing functionalities they shouldn't have permission for. The vulnerability history, which includes a medium severity CVE for missing authorization in the past, reinforces this concern. The plugin has a history of authorization issues, and the current lack of capability checks suggests this could be a recurring weakness. Therefore, while the plugin has made improvements, the absence of proper authorization checks remains a notable security risk.

Key Concerns

  • Missing capability checks on entry points
  • Past medium severity CVE for missing authorization
  • Some output not properly escaped
Vulnerabilities
1

Vertical Timeline Widget for Elementor Security Vulnerabilities

CVEs by Year

1 CVE in 2023
2023
Patched Has unpatched

Severity Breakdown

Medium
1

1 total CVE

CVE-2023-49755medium · 4.3Missing Authorization

Elementor Timeline Widget <= 2.2 - Missing Authorization to Notice Dismissal

Dec 4, 2023 Patched in 2.3 (136d)
Code Analysis
Analyzed Mar 16, 2026

Vertical Timeline Widget for Elementor Code Analysis

Dangerous Functions
0
Raw SQL Queries
0
0 prepared
Unescaped Output
4
9 escaped
Nonce Checks
1
Capability Checks
0
File Operations
0
External Requests
0
Bundled Libraries
0

Output Escaping

69% escaped13 total outputs
Attack Surface

Vertical Timeline Widget for Elementor Attack Surface

Entry Points1
Unprotected0

AJAX Handlers 1

authwp_ajax_twae_hide_upgrade_notice_editorinit.php:108
WordPress Hooks 6
actionelementor/preview/enqueue_stylesinit.php:22
actionwp_enqueue_scriptsinit.php:23
actionelementor/editor/after_enqueue_stylesinit.php:24
actionelementor/editor/after_enqueue_scriptsinit.php:38
actionelementor/widgets/widgets_registeredinit.php:74
filterplugin_row_metainit.php:96
Maintenance & Trust

Vertical Timeline Widget for Elementor Maintenance & Trust

Maintenance Signals

WordPress version tested6.9.4
Last updatedJan 29, 2026
PHP min version7.2
Downloads165K

Community Trust

Rating96/100
Number of ratings26
Active installs10K
Developer Profile

Vertical Timeline Widget for Elementor Developer Profile

Satinder Singh

4 plugins · 11K total installs

79
trust score
Avg Security Score
100/100
Avg Patch Time
136 days
View full developer profile
Detection Fingerprints

How We Detect Vertical Timeline Widget for Elementor

Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.

Asset Fingerprints

Asset Paths
/wp-content/plugins/3r-elementor-timeline-widget/assets/css/twe-editor.css/wp-content/plugins/3r-elementor-timeline-widget/assets/js/twe-editor.js/wp-content/plugins/3r-elementor-timeline-widget/assets/css/style.css
Script Paths
/wp-content/plugins/3r-elementor-timeline-widget/assets/js/twe-editor.js
Version Parameters
3r-elementor-timeline-widget/assets/css/twe-editor.css?ver=3r-elementor-timeline-widget/assets/js/twe-editor.js?ver=3r-elementor-timeline-widget/assets/css/style.css?ver=

HTML / DOM Fingerprints

CSS Classes
twae-upgrade-notice
JS Globals
twae_ajax_obj
FAQ

Frequently Asked Questions about Vertical Timeline Widget for Elementor