EventCrafter – Responsive Timelines, Roadmaps & Events Builder Security & Risk Analysis

wordpress.org/plugins/eventcrafter-visual-timeline

Create beautiful vertical timelines, product roadmaps, and event history. Manage your events using the intuitive Visual Builder.

0 active installs v1.3.0 PHP 7.4+ WP 5.0+ Updated Unknown
eventshistoryjsonroadmaptimeline
100
A · Safe
CVEs total0
Unpatched0
Last CVENever
Safety Verdict

Is EventCrafter – Responsive Timelines, Roadmaps & Events Builder Safe to Use in 2026?

Generally Safe

Score 100/100

EventCrafter – Responsive Timelines, Roadmaps & Events Builder has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.

No known CVEs
Risk Assessment

The security posture of eventcrafter-visual-timeline v1.3.0 appears strong based on the provided static analysis and vulnerability history. The plugin demonstrates good security practices by utilizing prepared statements for all SQL queries and properly escaping all output, which significantly mitigates risks of injection and cross-site scripting vulnerabilities. The presence of nonce and capability checks on its single entry point (shortcode) further enhances its security by ensuring proper authorization and integrity.

While the static analysis reveals no critical or high-severity taint flows and the plugin has no recorded vulnerability history, there are a few areas worth noting. The presence of a file operation and an external HTTP request, while not inherently vulnerabilities, represent potential attack vectors if not handled with extreme care and proper sanitization. These operations, along with the shortcode as the sole entry point, form a limited but present attack surface that requires continued vigilance.

In conclusion, eventcrafter-visual-timeline v1.3.0 presents a relatively low-risk profile. Its commitment to secure coding practices like prepared statements and output escaping is commendable. However, the inherent risks associated with file operations and external HTTP requests, even if currently unexploited, mean that ongoing monitoring and prompt updates in case of future discoveries are advisable. The lack of past vulnerabilities is a positive indicator of its development team's security awareness.

Key Concerns

  • File operation detected
  • External HTTP request detected
Vulnerabilities
None known

EventCrafter – Responsive Timelines, Roadmaps & Events Builder Security Vulnerabilities

No known vulnerabilities — this is a good sign.
Code Analysis
Analyzed Mar 17, 2026

EventCrafter – Responsive Timelines, Roadmaps & Events Builder Code Analysis

Dangerous Functions
0
Raw SQL Queries
0
0 prepared
Unescaped Output
0
34 escaped
Nonce Checks
1
Capability Checks
1
File Operations
1
External Requests
1
Bundled Libraries
0

Output Escaping

100% escaped34 total outputs
Attack Surface

EventCrafter – Responsive Timelines, Roadmaps & Events Builder Attack Surface

Entry Points1
Unprotected0

Shortcodes 1

[eventcrafter] eventcrafter.php:50
WordPress Hooks 10
actionadd_meta_boxesadmin\class-event-admin.php:13
actionsave_post_eventcrafter_tladmin\class-event-admin.php:14
actionadmin_enqueue_scriptsadmin\class-event-admin.php:15
actionwp_enqueue_scriptseventcrafter.php:48
actioniniteventcrafter.php:49
actioniniteventcrafter.php:137
actioniniteventcrafter.php:140
actioninitincludes\class-event-cpt.php:10
filtermanage_eventcrafter_tl_posts_columnsincludes\class-event-cpt.php:11
actionmanage_eventcrafter_tl_posts_custom_columnincludes\class-event-cpt.php:12
Maintenance & Trust

EventCrafter – Responsive Timelines, Roadmaps & Events Builder Maintenance & Trust

Maintenance Signals

WordPress version tested6.7.5
Last updatedUnknown
PHP min version7.4
Downloads149

Community Trust

Rating0/100
Number of ratings0
Active installs0
Developer Profile

EventCrafter – Responsive Timelines, Roadmaps & Events Builder Developer Profile

Fahad Murtaza

3 plugins · 0 total installs

94
trust score
Avg Security Score
100/100
Avg Patch Time
30 days
View full developer profile
Detection Fingerprints

How We Detect EventCrafter – Responsive Timelines, Roadmaps & Events Builder

Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.

Asset Fingerprints

Asset Paths
/wp-content/plugins/eventcrafter-visual-timeline/assets/css/eventcrafter.css/wp-content/plugins/eventcrafter-visual-timeline/assets/js/eventcrafter.js/wp-content/plugins/eventcrafter-visual-timeline/admin/css/builder.css/wp-content/plugins/eventcrafter-visual-timeline/admin/js/builder.js
Version Parameters
eventcrafter-visual-timeline/assets/css/eventcrafter.css?ver=eventcrafter-visual-timeline/assets/js/eventcrafter.js?ver=eventcrafter-visual-timeline/admin/css/builder.css?ver=eventcrafter-visual-timeline/admin/js/builder.js?ver=

HTML / DOM Fingerprints

CSS Classes
eventcrafter-error
Shortcode Output
<div class="eventcrafter-error">
FAQ

Frequently Asked Questions about EventCrafter – Responsive Timelines, Roadmaps & Events Builder