Kenzap Timeline Security & Risk Analysis

wordpress.org/plugins/kenzap-timeline

A beautiful and easy customizable set of Gutenberg blocks to create timeline section for the new editor. Easily adjust the following parameters:

40 active installs v1.1.1 PHP 5.6+ WP 5.0+ Updated Nov 10, 2020
progressroadmaptimeline
85
A · Safe
CVEs total0
Unpatched0
Last CVENever
Download
Safety Verdict

Is Kenzap Timeline Safe to Use in 2026?

Generally Safe

Score 85/100

Kenzap Timeline has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.

No known CVEs Updated 5yr ago
Risk Assessment

The static analysis of the kenzap-timeline plugin version 1.1.1 indicates a strong security posture. The plugin has zero identified attack surface points, meaning there are no publicly accessible AJAX handlers, REST API routes, shortcodes, or cron events that could be exploited. Furthermore, the code signals reveal excellent security practices. All SQL queries utilize prepared statements, all output is properly escaped, and there are no dangerous functions, file operations, or external HTTP requests identified. The presence of a capability check further strengthens its security, although the absence of nonce checks is noted. The plugin's vulnerability history is completely clean, with no recorded CVEs of any severity. This lack of historical vulnerabilities, combined with the robust static analysis findings, suggests that the plugin has been developed with security in mind. The main area for potential concern, though minor given the overall findings, is the absence of nonce checks, which could theoretically be a point of weakness if other security measures were compromised. However, based on the provided data, the plugin appears to be very secure.

Key Concerns

  • Missing nonce checks
Vulnerabilities
None known

Kenzap Timeline Security Vulnerabilities

No known vulnerabilities — this is a good sign.
Code Analysis
Analyzed Mar 16, 2026

Kenzap Timeline Code Analysis

Dangerous Functions
0
Raw SQL Queries
0
0 prepared
Unescaped Output
0
0 escaped
Nonce Checks
0
Capability Checks
1
File Operations
0
External Requests
0
Bundled Libraries
0
Attack Surface

Kenzap Timeline Attack Surface

Entry Points0
Unprotected0
WordPress Hooks 8
actionadmin_initplugin.php:50
actionadmin_noticesplugin.php:51
actioninitsrc\init.php:24
filterbody_classsrc\init.php:32
filteradmin_body_classsrc\init.php:33
actionenqueue_block_assetssrc\init.php:53
actionenqueue_block_editor_assetssrc\init.php:92
actionthe_postsrc\init.php:119
Maintenance & Trust

Kenzap Timeline Maintenance & Trust

Maintenance Signals

WordPress version tested5.5.18
Last updatedNov 10, 2020
PHP min version5.6
Downloads4K

Community Trust

Rating0/100
Number of ratings0
Active installs40
Developer Profile

Kenzap Timeline Developer Profile

WP Asia

7 plugins · 260 total installs

84
trust score
Avg Security Score
85/100
Avg Patch Time
30 days
View full developer profile
Detection Fingerprints

How We Detect Kenzap Timeline

Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.

Asset Fingerprints

Asset Paths
/wp-content/plugins/kenzap-timeline/dist/blocks.style.build.css/wp-content/plugins/kenzap-timeline/dist/blocks.build.js/wp-content/plugins/kenzap-timeline/dist/blocks.editor.build.css
Script Paths
/wp-content/plugins/kenzap-timeline/dist/owl-carousel/owl-carousel.js/wp-content/plugins/kenzap-timeline/timeline-3/script.js/wp-content/plugins/kenzap-timeline/timeline-4/script.js

HTML / DOM Fingerprints

CSS Classes
kenzap
Data Attributes
kenzap_timeline_gutenberg_path
JS Globals
kenzap_timeline_gutenberg_path
Shortcode Output
kenzap/timeline-3kenzap/timeline-4
FAQ

Frequently Asked Questions about Kenzap Timeline