
History Timeline for Biography, Company History & Event Timeline Security & Risk Analysis
wordpress.org/plugins/timeline-awesomeCreate animated horizontal and vertical timeline under 5 minutes for personal history, company timeline and event story timeline
Is History Timeline for Biography, Company History & Event Timeline Safe to Use in 2026?
High Risk
Score 48/100History Timeline for Biography, Company History & Event Timeline carries significant security risk with 2 known CVEs, 2 still unpatched. Consider switching to a maintained alternative.
The "timeline-awesome" plugin version 1.0.6 presents a mixed security posture. On the positive side, static analysis reveals a small attack surface with no identified AJAX handlers or REST API routes exposed without authentication. The code also demonstrates good practices by exclusively using prepared statements for SQL queries and a high percentage of output escaping, along with no file operations or external HTTP requests. However, a significant concern arises from its vulnerability history, which shows two known medium-severity CVEs, both of which remain unpatched. These historical vulnerabilities point to patterns of Missing Authorization and Cross-Site Scripting, indicating potential weaknesses in how user input is handled and access is controlled. The absence of nonce checks and capability checks in the static analysis, coupled with the historical vulnerabilities, suggests that while the current code might be cleaner, the plugin has a track record of security flaws that require attention. The unpatched nature of past vulnerabilities is a critical indicator of ongoing risk.
The plugin's current static analysis doesn't reveal any immediate critical or high severity issues like dangerous functions or unsanitized taint flows. However, the presence of 0 nonce checks and 0 capability checks, despite a history of Cross-Site Scripting and Missing Authorization vulnerabilities, is a notable weakness. This suggests that past vulnerabilities may not have been fully remediated in the codebase, or that the current version, while appearing clean in static analysis, could still be susceptible to similar issues if input handling or authorization mechanisms are not robust. The most pressing issue remains the two unpatched medium-severity vulnerabilities, which expose users to known risks.
Key Concerns
- Unpatched CVEs (2)
- No nonce checks
- No capability checks
History Timeline for Biography, Company History & Event Timeline Security Vulnerabilities
CVEs by Year
Severity Breakdown
2 total CVEs
History Timeline <= 1.0.6 - Missing Authorization
History Timeline <= 1.0.5 - Authenticated (Author+) Stored Cross-Site Scripting
History Timeline for Biography, Company History & Event Timeline Code Analysis
Output Escaping
History Timeline for Biography, Company History & Event Timeline Attack Surface
Shortcodes 1
WordPress Hooks 15
Maintenance & Trust
History Timeline for Biography, Company History & Event Timeline Maintenance & Trust
Maintenance Signals
Community Trust
History Timeline for Biography, Company History & Event Timeline Alternatives
Bold Timeline Lite
bold-timeline-lite
Bold Timeline Lite – WordPress Timeline Plugin
Cool Timeline (Horizontal & Vertical Timeline)
cool-timeline
Showcase your story or company history, events, and roadmap in an interactive timeline using the powerful Cool Timeline plugin.
Timeline and History slider
timeline-and-history-slider
Timeline Plugin for WordPress. Easy to add and display history OR timeline for your WordPress website. Also work with Gutenberg shortcode block.
Event Timeline – Vertical Timeline
rich-event-timeline
Timeline plugin is fully responsive. Timeline Is awesome WordPress plugin with many useful features and effects.
Post Timeline
post-timeline
Create stunning and interactive timelines for your WordPress posts with ease. Post Timeline is the ultimate plugin for displaying your WordPress conte …
History Timeline for Biography, Company History & Event Timeline Developer Profile
11 plugins · 3K total installs
How We Detect History Timeline for Biography, Company History & Event Timeline
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/timeline-awesome/public/css/fontawesome.min.css/wp-content/plugins/timeline-awesome/public/css/timeline-awesome-public.css/wp-content/plugins/timeline-awesome/public/css/responsive.csstimeline-awesome/public/css/fontawesome.min.css?ver=timeline-awesome/public/css/timeline-awesome-public.css?ver=timeline-awesome/public/css/responsive.css?ver=HTML / DOM Fingerprints
timeline-awesome-containertimeline-itemtimeline-icontimeline-datetimeline-contentdata-timeline-style[timeline_awesome id="