
Bold Timeline Lite Security & Risk Analysis
wordpress.org/plugins/bold-timeline-liteBold Timeline Lite – WordPress Timeline Plugin
Is Bold Timeline Lite Safe to Use in 2026?
Generally Safe
Score 95/100Bold Timeline Lite has a strong security track record. Known vulnerabilities have been patched promptly.
The 'bold-timeline-lite' plugin v1.2.8 presents a mixed security posture. While it demonstrates strengths in SQL query handling with 100% prepared statements and a solid number of capability checks (9), concerns arise from its attack surface and historical vulnerability patterns. The presence of one AJAX handler without authentication checks is a significant risk, representing a direct entry point that could be exploited by unauthenticated users. The plugin also has a history of 5 medium-severity vulnerabilities, primarily related to Cross-site Scripting and Missing Authorization. Although no critical or high-severity vulnerabilities are currently unpatched, this history suggests a recurring tendency for issues related to input sanitization and access control. The static analysis shows a generally good approach to output escaping (70% proper), but this is overshadowed by the unprotected AJAX endpoint and the past incidents. While the taint analysis shows no critical or high-severity unsanitized flows, the overall risk is elevated due to the unprotected entry point and the historical precedent of security flaws.
Key Concerns
- Unprotected AJAX handler
- Historical medium severity vulnerabilities (5 total)
- Historical XSS and Missing Authorization issues
Bold Timeline Lite Security Vulnerabilities
CVEs by Year
Severity Breakdown
5 total CVEs
Bold Timeline Lite <= 1.2.7 - Authenticated (Contributor+) Stored Cross-Site Scripting
Bold Timeline Lite <= 1.2.7 - Authenticated (Contributor+) Stored Cross-Site Scripting via 'title' Parameter in 'bold_timeline_group' Shortcode
Bold Timeline Lite <= 1.2.0 - Authenticated (Contributor+) Stored Cross-Site Scripting
Bold Timeline Lite <= 1.1.9 - Missing Authorization to Admin Notice Dismissal
Bold Timeline Lite <= 1.1.4 - Authenticated (Contributor+) Stored Cross-Site Scripting via Shortcode
Bold Timeline Lite Code Analysis
SQL Query Safety
Output Escaping
Data Flow Analysis
Bold Timeline Lite Attack Surface
AJAX Handlers 1
Shortcodes 4
WordPress Hooks 31
Maintenance & Trust
Bold Timeline Lite Maintenance & Trust
Maintenance Signals
Community Trust
Bold Timeline Lite Alternatives
History Timeline for Biography, Company History & Event Timeline
timeline-awesome
Create animated horizontal and vertical timeline under 5 minutes for personal history, company timeline and event story timeline
Timeline Widget For Elementor (Elementor Timeline, Vertical & Horizontal Timeline)
timeline-widget-addon-for-elementor
Highlight your company’s history, milestones, and key events directly inside Elementor using stunning vertical and horizontal timelines.
Cool Timeline (Horizontal & Vertical Timeline)
cool-timeline
Showcase your story or company history, events, and roadmap in an interactive timeline using the powerful Cool Timeline plugin.
Timeline and History slider
timeline-and-history-slider
Timeline Plugin for WordPress. Easy to add and display history OR timeline for your WordPress website. Also work with Gutenberg shortcode block.
Timeline Module for Divi
timeline-module-for-divi
Highlight your company's history, milestones, and future plans with the advanced Timeline Module for Divi.
Bold Timeline Lite Developer Profile
8 plugins · 69K total installs
How We Detect Bold Timeline Lite
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/bold-timeline-lite/style.css/wp-content/plugins/bold-timeline-lite/assets/js/bold-timeline.js/wp-content/plugins/bold-timeline-lite/assets/js/bold-timeline.jsbold-timeline-lite/style.css?ver=bold-timeline-lite/assets/js/bold-timeline.js?ver=HTML / DOM Fingerprints
bold-timeline-itembt-timeline-iconbt-timeline-contentbt-timeline-datebt-timeline-titlebt-timeline-textbold-timeline-groupbt-timeline-group-header+2 moredata-bt-timeline-iddata-bt-timeline-styleBold_Timeline[bold_timeline[bt_bb_timeline