Timeline Block – Beautiful Timeline Builder for WordPress (Vertical & Horizontal Timelines) Security & Risk Analysis

wordpress.org/plugins/timeline-block-block

Design Timeline with ease! Featuring 7 customizable themes in both horizontal and vertical layouts,lets you showcase your stories,events,or projects.

3K active installs v1.3.7 PHP 7.1+ WP 6.5+ Updated Feb 28, 2026
blockhorizontal-timelinetimelinetimeline-buildervertical-timeline
98
A · Safe
CVEs total2
Unpatched0
Last CVEFeb 5, 2026
Download
Safety Verdict

Is Timeline Block – Beautiful Timeline Builder for WordPress (Vertical & Horizontal Timelines) Safe to Use in 2026?

Generally Safe

Score 98/100

Timeline Block – Beautiful Timeline Builder for WordPress (Vertical & Horizontal Timelines) has a strong security track record. Known vulnerabilities have been patched promptly.

2 known CVEsLast CVE: Feb 5, 2026Updated 1mo ago
Risk Assessment

The "timeline-block-block" plugin v1.3.7 presents a mixed security posture. On the positive side, the static analysis reveals good coding practices with 100% of SQL queries using prepared statements and all output being properly escaped. There are no identified file operations or external HTTP requests, and the attack surface is minimal with only one shortcode and no unprotected entry points. However, the complete absence of nonce checks and capability checks across all entry points is a significant concern, as it suggests a lack of robust authorization and session validation, which could be exploited if vulnerabilities were present.

The vulnerability history is more concerning, with two previously discovered medium-severity vulnerabilities: "Authorization Bypass Through User-Controlled Key" and "Cross-site Scripting." While there are currently no unpatched vulnerabilities, the types of past issues indicate potential weaknesses in how user input is handled and access is managed. The fact that the last vulnerability was in 2026, despite being an unpatched CVE, is unusual and may indicate a data anomaly or a placeholder. The plugin's reliance on Freemius for bundled libraries also warrants attention, as outdated bundled libraries can introduce security risks if not regularly updated.

Overall, while the code quality in terms of SQL and output handling is commendable, the lack of essential security checks and the history of past vulnerabilities, particularly those related to authorization and XSS, indicate areas that require diligent monitoring and potential remediation. The plugin currently appears to be free of active exploits based on the provided data, but the underlying architectural weaknesses and historical patterns suggest a moderate risk level.

Key Concerns

  • No nonce checks on entry points
  • No capability checks on entry points
  • 2 previously known medium CVEs
  • Bundled Freemius library
Vulnerabilities
2

Timeline Block – Beautiful Timeline Builder for WordPress (Vertical & Horizontal Timelines) Security Vulnerabilities

CVEs by Year

1 CVE in 2025
2025
1 CVE in 2026
2026
Patched Has unpatched

Severity Breakdown

Medium
2

2 total CVEs

CVE-2026-1228medium · 4.3Authorization Bypass Through User-Controlled Key

Timeline Block <= 1.3.3 - Insecure Direct Object Reference to Authenticated (Author+) Private Timeline Exposure via Shortcode Attribute

Feb 5, 2026 Patched in 1.3.4 (1d)
CVE-2025-26754medium · 6.4Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')

Timeline Block <= 1.1.1 - Authenticated (Contributor+) Stored Cross-Site Scripting

Feb 14, 2025 Patched in 1.1.3 (5d)
Code Analysis
Analyzed Mar 16, 2026

Timeline Block – Beautiful Timeline Builder for WordPress (Vertical & Horizontal Timelines) Code Analysis

Dangerous Functions
0
Raw SQL Queries
0
0 prepared
Unescaped Output
0
6 escaped
Nonce Checks
0
Capability Checks
0
File Operations
0
External Requests
0
Bundled Libraries
1

Bundled Libraries

Freemius

Output Escaping

100% escaped6 total outputs
Attack Surface

Timeline Block – Beautiful Timeline Builder for WordPress (Vertical & Horizontal Timelines) Attack Surface

Entry Points1
Unprotected0

Shortcodes 1

[timeline_block] includes\class-tlgb-main.php:6
WordPress Hooks 9
actioninitclass-tlgb-block.php:6
actionenqueue_block_assetsclass-tlgb-block.php:7
actionenqueue_block_editor_assetsclass-tlgb-block.php:8
actionadmin_menuincludes\class-tlgb-admin.php:7
actionadmin_enqueue_scriptsincludes\class-tlgb-admin.php:8
actioninitincludes\class-tlgb-cpt.php:5
filtermanage_timeline_block_posts_columnsincludes\class-tlgb-cpt.php:6
actionmanage_timeline_block_posts_custom_columnincludes\class-tlgb-cpt.php:7
actionplugins_loadedincludes\class-tlgb-main.php:5
Maintenance & Trust

Timeline Block – Beautiful Timeline Builder for WordPress (Vertical & Horizontal Timelines) Maintenance & Trust

Maintenance Signals

WordPress version tested6.9.4
Last updatedFeb 28, 2026
PHP min version7.1
Downloads59K

Community Trust

Rating100/100
Number of ratings5
Active installs3K
Developer Profile

Timeline Block – Beautiful Timeline Builder for WordPress (Vertical & Horizontal Timelines) Developer Profile

colorlibplugins

120 plugins · 738K total installs

78
trust score
Avg Security Score
99/100
Avg Patch Time
140 days
View full developer profile
Detection Fingerprints

How We Detect Timeline Block – Beautiful Timeline Builder for WordPress (Vertical & Horizontal Timelines)

Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.

Asset Fingerprints

Asset Paths
/wp-content/plugins/timeline-block-block/assets/js/timeline.min.js/wp-content/plugins/timeline-block-block/assets/css/timeline.min.css/wp-content/plugins/timeline-block-block/build/column.css/wp-content/plugins/timeline-block-block/build/column.js/wp-content/plugins/timeline-block-block/build/admin-dashboard.css/wp-content/plugins/timeline-block-block/build/admin-dashboard.js
Script Paths
/wp-content/plugins/timeline-block-block/assets/js/timeline.min.js/wp-content/plugins/timeline-block-block/build/column.js/wp-content/plugins/timeline-block-block/build/admin-dashboard.js
Version Parameters
timeline-block-block/assets/js/timeline.min.js?ver=timeline-block-block/assets/css/timeline.min.css?ver=timeline-block-block/build/column.css?ver=timeline-block-block/build/column.js?ver=timeline-block-block/build/admin-dashboard.css?ver=timeline-block-block/build/admin-dashboard.js?ver=

HTML / DOM Fingerprints

CSS Classes
tlgbAdminDashboardWrapper
Data Attributes
data-info
JS Globals
tlgbIsPipeCheckerTLGB_VERSIONTLGB_DIR_URLTLGB_DIR_PATHTLGB_HAS_FREETLGB_HAS_PRO
Shortcode Output
[timeline_block id=
FAQ

Frequently Asked Questions about Timeline Block – Beautiful Timeline Builder for WordPress (Vertical & Horizontal Timelines)