
Timeline and History slider Security & Risk Analysis
wordpress.org/plugins/timeline-and-history-sliderTimeline Plugin for WordPress. Easy to add and display history OR timeline for your WordPress website. Also work with Gutenberg shortcode block.
Is Timeline and History slider Safe to Use in 2026?
Generally Safe
Score 98/100Timeline and History slider has a strong security track record. Known vulnerabilities have been patched promptly.
The "timeline-and-history-slider" plugin v2.4.5 exhibits a mixed security posture. On the positive side, it demonstrates good practices with 100% of SQL queries using prepared statements and a strong percentage of output properly escaped. The total number of entry points is low, and there are no apparent unprotected AJAX handlers or REST API routes. The plugin also implements nonce and capability checks for its entry points, which is commendable.
However, there are significant concerns. The presence of the `unserialize` function is a known risk, as it can lead to deserialization vulnerabilities if the data being unserialized is not properly validated or controlled by an attacker. While the static analysis did not reveal any specific taint flows, the mere presence of this function warrants caution. The vulnerability history shows a past high-severity "PHP Remote File Inclusion" vulnerability, which is a serious issue. The fact that a high-severity vulnerability was patched relatively recently (indicated by the last vulnerability date) suggests a potential for recurring security weaknesses in the plugin's code.
Overall, while the plugin employs some good security measures like prepared statements and output escaping, the `unserialize` function and the past history of a severe vulnerability (RFI) introduce notable risks. The plugin is currently patched, but the underlying codebase might still harbor undiscovered vulnerabilities. Users should be aware of the potential risks associated with deserialization and the plugin's past security issues.
Key Concerns
- Presence of dangerous function: unserialize
- Past high severity vulnerability (RFI)
Timeline and History slider Security Vulnerabilities
CVEs by Year
Severity Breakdown
1 total CVE
Timeline and History slider <= 2.3 - Authenticated (Contributor+) Local File Inclusion
Timeline and History slider Code Analysis
Dangerous Functions Found
Output Escaping
Timeline and History slider Attack Surface
Shortcodes 1
WordPress Hooks 33
Scheduled Events 1
Maintenance & Trust
Timeline and History slider Maintenance & Trust
Maintenance Signals
Community Trust
Timeline and History slider Alternatives
Ultimate Timeline – Responsive History Timeline
ultimate-timeline
Ultimate Timeline plugin creates beautiful history time-lines on your website. It is responsive time-line showcase in DESC order based on posted date …
Bold Timeline Lite
bold-timeline-lite
Bold Timeline Lite – WordPress Timeline Plugin
Event Timeline – Vertical Timeline
rich-event-timeline
Timeline plugin is fully responsive. Timeline Is awesome WordPress plugin with many useful features and effects.
History Timeline for Biography, Company History & Event Timeline
timeline-awesome
Create animated horizontal and vertical timeline under 5 minutes for personal history, company timeline and event story timeline
Timeline Pro
timeline-pro
Timeline Pro is pure HTML & CSS timeline style grid for WordPress.
Timeline and History slider Developer Profile
33 plugins · 205K total installs
How We Detect Timeline and History slider
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/timeline-and-history-slider/assets/css/wpostahs-admin.css/wp-content/plugins/timeline-and-history-slider/assets/css/timeline-slider.css/wp-content/plugins/timeline-and-history-slider/assets/css/timeline-slider-responsive.css/wp-content/plugins/timeline-and-history-slider/assets/css/timeline-style.css/wp-content/plugins/timeline-and-history-slider/assets/js/timeline-slider.js/wp-content/plugins/timeline-and-history-slider/assets/js/timeline-slider-admin.js/wp-content/plugins/timeline-and-history-slider/assets/js/customizer.js/wp-content/plugins/timeline-and-history-slider/assets/js/timeline-script.js/wp-content/plugins/timeline-and-history-slider/assets/js/timeline-slider.js/wp-content/plugins/timeline-and-history-slider/assets/js/timeline-slider-admin.js/wp-content/plugins/timeline-and-history-slider/assets/js/customizer.js/wp-content/plugins/timeline-and-history-slider/assets/js/timeline-script.jstimeline-and-history-slider/assets/css/wpostahs-admin.css?ver=timeline-and-history-slider/assets/css/timeline-slider.css?ver=timeline-and-history-slider/assets/css/timeline-slider-responsive.css?ver=timeline-and-history-slider/assets/css/timeline-style.css?ver=timeline-and-history-slider/assets/js/timeline-slider.js?ver=timeline-and-history-slider/assets/js/timeline-slider-admin.js?ver=timeline-and-history-slider/assets/js/customizer.js?ver=timeline-and-history-slider/assets/js/timeline-script.js?ver=timeline-and-history-slider/assets/js/timeline-slider.js?ver=timeline-and-history-slider/assets/js/timeline-slider-admin.js?ver=HTML / DOM Fingerprints
tahs-timeline-slider-containertahs-timeline-slider-wraptahs-item-descriptiontahs-timeline-item-wraptahs-timeline-date-outerwraptahs-timeline-date-innerwraptahs-timeline-content-outerwraptahs-timeline-content-innerwrap+15 more<!-- Timeline Slider section ends -->data-typedata-itemdata-timeline-animationdata-layoutdata-aligndata-timeline-arrow+77 moretahs_slider_params[timeline-slider][timeline-slider id=""]