Timber Security & Risk Analysis

wordpress.org/plugins/timber-library

Helps you create themes faster with sustainable code. With Timber, you write HTML using Twig Templates http://www.upstatement.com/timber/

20K active installs v1.23.4 PHP 7.2.5+ WP 5.3.0+ Updated May 31, 2025
template-enginetemplatestwig
97
A · Safe
CVEs total2
Unpatched0
Last CVEJul 24, 2025
Safety Verdict

Is Timber Safe to Use in 2026?

Generally Safe

Score 97/100

Timber has a strong security track record. Known vulnerabilities have been patched promptly. It's a solid choice for most WordPress installations.

2 known CVEsLast CVE: Jul 24, 2025Updated 11mo ago
Risk Assessment

The static analysis of Timber Library v1.23.4 indicates a generally strong security posture in terms of direct code vulnerabilities. The absence of any identified dangerous functions, raw SQL queries, unescaped outputs, file operations, external HTTP requests, or taint flows with unsanitized paths is a positive sign. Furthermore, the lack of AJAX handlers, REST API routes, shortcodes, and cron events means the direct attack surface exposed by the plugin is effectively zero, and there are no unprotected entry points detected. However, the plugin's vulnerability history presents a significant concern. With two known CVEs, including one high and one medium severity vulnerability, the plugin has a past of security weaknesses. The fact that none are currently unpatched is good, but the types of past vulnerabilities (Dependency on Vulnerable Third-Party Component, Deserialization of Untrusted Data) suggest potential risks related to how the plugin handles external data or relies on other components. While the current code analysis is clean, the historical data warrants vigilance regarding potential future vulnerabilities, especially if the plugin continues to integrate with or rely on third-party elements that could become vulnerable.

Key Concerns

  • Past high severity vulnerability
  • Past medium severity vulnerability
  • Dependency on Vulnerable Third-Party Component history
  • Deserialization of Untrusted Data history
Vulnerabilities
2 published

Timber Security Vulnerabilities

CVEs by Year

1 CVE in 2024
2024
1 CVE in 2025
2025
Patched Has unpatched

Severity Breakdown

High
1
Medium
1

2 total CVEs

CVE-2024-45411medium · 6.5Dependency on Vulnerable Third-Party Component

Timber <= 1.23.1 - Use of a Vulnerable Dependency

Jul 24, 2025 Patched in 1.23.3 (1d)
CVE-2024-29800high · 7.2Deserialization of Untrusted Data

Timber <= 1.23.0 - Authenticated (Admin+) PHP Object Injection

May 7, 2024 Patched in 1.23.1 (9d)
Version History

Timber Release Timeline

Code Analysis
Analyzed Mar 16, 2026

Timber Code Analysis

Dangerous Functions
0
Raw SQL Queries
0
0 prepared
Unescaped Output
0
0 escaped
Nonce Checks
0
Capability Checks
0
File Operations
0
External Requests
0
Bundled Libraries
0
Attack Surface

Timber Attack Surface

Entry Points0
Unprotected0
WordPress Hooks 7
actionafter_setup_themetimber-starter-theme\src\StarterSite.php:26
actioninittimber-starter-theme\src\StarterSite.php:27
actioninittimber-starter-theme\src\StarterSite.php:28
filtertimber/contexttimber-starter-theme\src\StarterSite.php:30
filtertimber/twig/filterstimber-starter-theme\src\StarterSite.php:31
filtertimber/twig/functionstimber-starter-theme\src\StarterSite.php:32
filtertimber/twig/environment/optionstimber-starter-theme\src\StarterSite.php:33
Maintenance & Trust

Timber Maintenance & Trust

Maintenance Signals

WordPress version tested6.8.5
Last updatedMay 31, 2025
PHP min version7.2.5
Downloads1.5M

Community Trust

Rating98/100
Number of ratings71
Active installs20K
Developer Profile

Timber Developer Profile

jarednova

6 plugins · 21K total installs

91
trust score
Avg Security Score
87/100
Avg Patch Time
5 days
View full developer profile
Detection Fingerprints

How We Detect Timber

Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.

Asset Fingerprints

Asset Paths
/wp-content/plugins/timber-library/timber.php

HTML / DOM Fingerprints

FAQ

Frequently Asked Questions about Timber