
Timed Content Security & Risk Analysis
wordpress.org/plugins/timed-contentPlugin to show or hide portions of a Page or Post based on specific date/time characteristics.
Is Timed Content Safe to Use in 2026?
Generally Safe
Score 100/100Timed Content has a strong security track record. Known vulnerabilities have been patched promptly.
The "timed-content" plugin version 2.97 exhibits a mixed security posture. On the positive side, the static analysis reveals a clean attack surface with no identified AJAX handlers, REST API routes, shortcodes, or cron events, and all SQL queries utilize prepared statements. The absence of dangerous functions and file operations is also reassuring. However, there are areas of concern, notably the low percentage of properly escaped output (40%), indicating a potential for Cross-Site Scripting (XSS) vulnerabilities if user-supplied data is rendered without adequate sanitization.
The vulnerability history shows one known CVE, which has since been patched. The common vulnerability type being XSS is consistent with the output escaping findings. The last vulnerability was in January 2023, suggesting that while past issues have been addressed, the underlying coding practices related to output sanitization may still pose a risk.
In conclusion, while the plugin has a limited attack surface and good SQL practices, the insufficient output escaping is a notable weakness that could be exploited. The resolved CVE and the focus on XSS as a past vulnerability type highlight the importance of robust input validation and output encoding for any plugin dealing with user-generated or dynamic content.
Key Concerns
- Low percentage of properly escaped output
- Bundled outdated library (TinyMCE)
Timed Content Security Vulnerabilities
CVEs by Year
Severity Breakdown
1 total CVE
Timed Content <= 2.72 - Authenticated (Contributor+) Stored Cross-Site Scripting via Shortcode
Timed Content Code Analysis
Bundled Libraries
Output Escaping
Timed Content Attack Surface
Maintenance & Trust
Timed Content Maintenance & Trust
Maintenance Signals
Community Trust
Timed Content Alternatives
Timed Visibility Block
timed-visibility-block
Control when your content shines—perfect for time-sensitive promotions and special events!
Expire Content Block
expire-content-block
Block that hides or replaces content after a set date/time. Perfect for promotions, events, and temporary announcements.
The Events Calendar
the-events-calendar
The Events Calendar: #1 calendar plugin for WordPress. Create/manage events (virtual too!) on your site with the free plugin.
Schedule Post Changes With PublishPress Future: Unpublish, Delete, Change Status, Trash, Change Categories
post-expirator
PublishPress Future can make scheduled changes to your content. You can unpublish posts, move posts to a new status, update the categories, and more.
OttoKit: All-in-One Automation Platform
suretriggers
Experience the power of automation within WordPress: Connect 1,300+ apps, automate manual tasks, and unlock your full potential. Get started now!
Timed Content Developer Profile
5 plugins · 29K total installs
How We Detect Timed Content
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/timed-content/css/timed-content.css/wp-content/plugins/timed-content/css/dashicons/style.css/wp-content/plugins/timed-content/css/jqueryui/1.10.3/themes/smoothness/jquery-ui.css/wp-content/plugins/timed-content/js/jquery-ui-timepicker-0.3.3/jquery.ui.timepicker.min.js/wp-content/plugins/timed-content/js/jquery-ui-timepicker-0.3.3/jquery.ui.timepicker.css/wp-content/plugins/timed-content/js/jquery-ui-timepicker-0.3.3/jquery.ui.timepicker.min.jstimed-content/css/timed-content.css?ver=timed-content/css/dashicons/style.css?ver=timed-content/css/jqueryui/1.10.3/themes/smoothness/jquery-ui.css?ver=timed-content/js/jquery-ui-timepicker-0.3.3/jquery.ui.timepicker.min.js?ver=timed-content/js/jquery-ui-timepicker-0.3.3/jquery.ui.timepicker.css?ver=HTML / DOM Fingerprints
[timed-content-client][timed-content-server][timed-content-rule]