
Event Timeline – Vertical Timeline Security & Risk Analysis
wordpress.org/plugins/rich-event-timelineTimeline plugin is fully responsive. Timeline Is awesome WordPress plugin with many useful features and effects.
Is Event Timeline – Vertical Timeline Safe to Use in 2026?
Use With Caution
Score 64/100Event Timeline – Vertical Timeline has 1 unpatched vulnerability. Evaluate alternatives or apply available mitigations.
The rich-event-timeline plugin exhibits a strong security posture in its static analysis. The complete absence of dangerous functions, the exclusive use of prepared statements for SQL queries, and 100% proper output escaping are excellent security practices. Furthermore, the presence of nonce and capability checks on entry points, alongside zero unsanitized taint flows, indicates a well-developed defensive coding approach. However, the plugin is not without its risks.
The vulnerability history reveals one known medium-severity Cross-Site Scripting (XSS) vulnerability, which remains unpatched. While the static analysis didn't identify any current XSS issues, the historical presence of such a vulnerability is a significant concern, suggesting potential for similar flaws. The bundled TinyMCE library, while not explicitly flagged as outdated, could present a risk if it's an older version lacking security patches.
In conclusion, while the current codebase demonstrates good security hygiene in many areas, the unpatched XSS vulnerability significantly lowers its overall security score. This historical issue demands immediate attention, and ongoing vigilance is recommended to ensure future updates address any newly discovered vulnerabilities.
Key Concerns
- Unpatched CVE (Medium Severity XSS)
- Bundled outdated library (TinyMCE)
Event Timeline – Vertical Timeline Security Vulnerabilities
CVEs by Year
Severity Breakdown
1 total CVE
Event Timeline <= 1.1.6 - Authenticated (Admin+) Stored Cross-Site Scripting
Event Timeline – Vertical Timeline Code Analysis
Bundled Libraries
SQL Query Safety
Output Escaping
Data Flow Analysis
Event Timeline – Vertical Timeline Attack Surface
AJAX Handlers 8
Shortcodes 1
WordPress Hooks 5
Maintenance & Trust
Event Timeline – Vertical Timeline Maintenance & Trust
Maintenance Signals
Community Trust
Event Timeline – Vertical Timeline Alternatives
Ultimate Timeline – Responsive History Timeline
ultimate-timeline
Ultimate Timeline plugin creates beautiful history time-lines on your website. It is responsive time-line showcase in DESC order based on posted date …
Bold Timeline Lite
bold-timeline-lite
Bold Timeline Lite – WordPress Timeline Plugin
Timeline and History slider
timeline-and-history-slider
Timeline Plugin for WordPress. Easy to add and display history OR timeline for your WordPress website. Also work with Gutenberg shortcode block.
History Timeline for Biography, Company History & Event Timeline
timeline-awesome
Create animated horizontal and vertical timeline under 5 minutes for personal history, company timeline and event story timeline
EventCrafter – Responsive Timelines, Roadmaps & Events Builder
eventcrafter-visual-timeline
Create beautiful vertical timelines, product roadmaps, and event history. Manage your events using the intuitive Visual Builder.
Event Timeline – Vertical Timeline Developer Profile
7 plugins · 9K total installs
How We Detect Event Timeline – Vertical Timeline
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/rich-event-timeline/Style/Rich-Web-Icons.css/wp-content/plugins/rich-event-timeline/Style/Rich-Web-Timeline-Admin-Style.css/wp-content/plugins/rich-event-timeline/Scripts/Rich-Web-Timeline-Scripts.js/wp-content/plugins/rich-event-timeline/Scripts/tinymce.js/wp-content/plugins/rich-event-timeline/Scripts/Rich-Web-Timeline-Admin-Scripts.js/wp-content/plugins/rich-event-timeline/Scripts/Rich-Web-Timeline-Alpha-Color-Picker.js/wp-content/plugins/rich-event-timeline/Style/Rich-Web-Timeline-Alpha-Color-Picker.css/wp-content/plugins/rich-event-timeline/Scripts/Rich-Web-Timeline-Scripts.js/wp-content/plugins/rich-event-timeline/Scripts/tinymce.js/wp-content/plugins/rich-event-timeline/Scripts/Rich-Web-Timeline-Admin-Scripts.js/wp-content/plugins/rich-event-timeline/Scripts/Rich-Web-Timeline-Alpha-Color-Picker.jsHTML / DOM Fingerprints
object.ajaxurlobject.rw_timeline_nonce<div class="Rich-Web-Timeline-container"