History Timeline for Biography, Company History & Event Timeline Security & Risk Analysis

wordpress.org/plugins/timeline-awesome

Create animated horizontal and vertical timeline under 5 minutes for personal history, company timeline and event story timeline

1K active installs v1.0.6 PHP 7.0+ WP 5.4+ Updated Jun 25, 2024
company-timelineevent-timelinehistorytimelinevertical-timeline
48
D · High Risk
CVEs total2
Unpatched2
Last CVEDec 31, 2025
Safety Verdict

Is History Timeline for Biography, Company History & Event Timeline Safe to Use in 2026?

High Risk

Score 48/100

History Timeline for Biography, Company History & Event Timeline carries significant security risk with 2 known CVEs, 2 still unpatched. Consider switching to a maintained alternative.

2 known CVEs 2 unpatched Last CVE: Dec 31, 2025Updated 1yr ago
Risk Assessment

The "timeline-awesome" plugin version 1.0.6 presents a mixed security posture. On the positive side, static analysis reveals a small attack surface with no identified AJAX handlers or REST API routes exposed without authentication. The code also demonstrates good practices by exclusively using prepared statements for SQL queries and a high percentage of output escaping, along with no file operations or external HTTP requests. However, a significant concern arises from its vulnerability history, which shows two known medium-severity CVEs, both of which remain unpatched. These historical vulnerabilities point to patterns of Missing Authorization and Cross-Site Scripting, indicating potential weaknesses in how user input is handled and access is controlled. The absence of nonce checks and capability checks in the static analysis, coupled with the historical vulnerabilities, suggests that while the current code might be cleaner, the plugin has a track record of security flaws that require attention. The unpatched nature of past vulnerabilities is a critical indicator of ongoing risk.

The plugin's current static analysis doesn't reveal any immediate critical or high severity issues like dangerous functions or unsanitized taint flows. However, the presence of 0 nonce checks and 0 capability checks, despite a history of Cross-Site Scripting and Missing Authorization vulnerabilities, is a notable weakness. This suggests that past vulnerabilities may not have been fully remediated in the codebase, or that the current version, while appearing clean in static analysis, could still be susceptible to similar issues if input handling or authorization mechanisms are not robust. The most pressing issue remains the two unpatched medium-severity vulnerabilities, which expose users to known risks.

Key Concerns

  • Unpatched CVEs (2)
  • No nonce checks
  • No capability checks
Vulnerabilities
2

History Timeline for Biography, Company History & Event Timeline Security Vulnerabilities

CVEs by Year

1 CVE in 2022 · unpatched
2022
1 CVE in 2025 · unpatched
2025
Patched Has unpatched

Severity Breakdown

Medium
2

2 total CVEs

CVE-2025-62150medium · 4.3Missing Authorization

History Timeline <= 1.0.6 - Missing Authorization

Dec 31, 2025Unpatched
CVE-2022-37328medium · 6.4Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')

History Timeline <= 1.0.5 - Authenticated (Author+) Stored Cross-Site Scripting

Sep 2, 2022Unpatched
Code Analysis
Analyzed Mar 16, 2026

History Timeline for Biography, Company History & Event Timeline Code Analysis

Dangerous Functions
0
Raw SQL Queries
0
0 prepared
Unescaped Output
13
204 escaped
Nonce Checks
0
Capability Checks
0
File Operations
0
External Requests
0
Bundled Libraries
0

Output Escaping

94% escaped217 total outputs
Attack Surface

History Timeline for Biography, Company History & Event Timeline Attack Surface

Entry Points1
Unprotected0

Shortcodes 1

[timeline_awesome] timeline-awesome.php:198
WordPress Hooks 15
actionplugins_loadedincludes\class-timeline-awesome.php:142
actionadmin_enqueue_scriptsincludes\class-timeline-awesome.php:157
actionadmin_enqueue_scriptsincludes\class-timeline-awesome.php:158
actionwp_enqueue_scriptsincludes\class-timeline-awesome.php:173
actionwp_enqueue_scriptsincludes\class-timeline-awesome.php:174
actionelementor/initincludes\element-helper.php:14
actioninittimeline-awesome-post-type.php:5
actioncarbon_fields_register_fieldstimeline-awesome-post-type.php:48
actionelementor/widgets/widgets_registeredtimeline-awesome.php:83
filtermanage_timeline-awesome_posts_columnstimeline-awesome.php:103
actionmanage_timeline-awesome_posts_custom_columntimeline-awesome.php:107
filtersingle_templatetimeline-awesome.php:111
actionafter_setup_themetimeline-awesome.php:122
actionwp_headtimeline-awesome.php:220
actioncarbon_fields_register_fieldstimeline-awesome.php:351
Maintenance & Trust

History Timeline for Biography, Company History & Event Timeline Maintenance & Trust

Maintenance Signals

WordPress version tested6.5.8
Last updatedJun 25, 2024
PHP min version7.0
Downloads20K

Community Trust

Rating80/100
Number of ratings4
Active installs1K
Developer Profile

History Timeline for Biography, Company History & Event Timeline Developer Profile

themesawesome

11 plugins · 3K total installs

86
trust score
Avg Security Score
89/100
Avg Patch Time
30 days
View full developer profile
Detection Fingerprints

How We Detect History Timeline for Biography, Company History & Event Timeline

Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.

Asset Fingerprints

Asset Paths
/wp-content/plugins/timeline-awesome/public/css/fontawesome.min.css/wp-content/plugins/timeline-awesome/public/css/timeline-awesome-public.css/wp-content/plugins/timeline-awesome/public/css/responsive.css
Version Parameters
timeline-awesome/public/css/fontawesome.min.css?ver=timeline-awesome/public/css/timeline-awesome-public.css?ver=timeline-awesome/public/css/responsive.css?ver=

HTML / DOM Fingerprints

CSS Classes
timeline-awesome-containertimeline-itemtimeline-icontimeline-datetimeline-content
Data Attributes
data-timeline-style
Shortcode Output
[timeline_awesome id="
FAQ

Frequently Asked Questions about History Timeline for Biography, Company History & Event Timeline