
Timeline Block – Beautiful Timeline Builder for WordPress (Vertical & Horizontal Timelines) Security & Risk Analysis
wordpress.org/plugins/timeline-block-blockDesign Timeline with ease! Featuring 7 customizable themes in both horizontal and vertical layouts,lets you showcase your stories,events,or projects.
Is Timeline Block – Beautiful Timeline Builder for WordPress (Vertical & Horizontal Timelines) Safe to Use in 2026?
Generally Safe
Score 98/100Timeline Block – Beautiful Timeline Builder for WordPress (Vertical & Horizontal Timelines) has a strong security track record. Known vulnerabilities have been patched promptly.
The "timeline-block-block" plugin v1.3.7 presents a mixed security posture. On the positive side, the static analysis reveals good coding practices with 100% of SQL queries using prepared statements and all output being properly escaped. There are no identified file operations or external HTTP requests, and the attack surface is minimal with only one shortcode and no unprotected entry points. However, the complete absence of nonce checks and capability checks across all entry points is a significant concern, as it suggests a lack of robust authorization and session validation, which could be exploited if vulnerabilities were present.
The vulnerability history is more concerning, with two previously discovered medium-severity vulnerabilities: "Authorization Bypass Through User-Controlled Key" and "Cross-site Scripting." While there are currently no unpatched vulnerabilities, the types of past issues indicate potential weaknesses in how user input is handled and access is managed. The fact that the last vulnerability was in 2026, despite being an unpatched CVE, is unusual and may indicate a data anomaly or a placeholder. The plugin's reliance on Freemius for bundled libraries also warrants attention, as outdated bundled libraries can introduce security risks if not regularly updated.
Overall, while the code quality in terms of SQL and output handling is commendable, the lack of essential security checks and the history of past vulnerabilities, particularly those related to authorization and XSS, indicate areas that require diligent monitoring and potential remediation. The plugin currently appears to be free of active exploits based on the provided data, but the underlying architectural weaknesses and historical patterns suggest a moderate risk level.
Key Concerns
- No nonce checks on entry points
- No capability checks on entry points
- 2 previously known medium CVEs
- Bundled Freemius library
Timeline Block – Beautiful Timeline Builder for WordPress (Vertical & Horizontal Timelines) Security Vulnerabilities
CVEs by Year
Severity Breakdown
2 total CVEs
Timeline Block <= 1.3.3 - Insecure Direct Object Reference to Authenticated (Author+) Private Timeline Exposure via Shortcode Attribute
Timeline Block <= 1.1.1 - Authenticated (Contributor+) Stored Cross-Site Scripting
Timeline Block – Beautiful Timeline Builder for WordPress (Vertical & Horizontal Timelines) Code Analysis
Bundled Libraries
Output Escaping
Timeline Block – Beautiful Timeline Builder for WordPress (Vertical & Horizontal Timelines) Attack Surface
Shortcodes 1
WordPress Hooks 9
Maintenance & Trust
Timeline Block – Beautiful Timeline Builder for WordPress (Vertical & Horizontal Timelines) Maintenance & Trust
Maintenance Signals
Community Trust
Timeline Block – Beautiful Timeline Builder for WordPress (Vertical & Horizontal Timelines) Alternatives
Cool Timeline (Horizontal & Vertical Timeline)
cool-timeline
Showcase your story or company history, events, and roadmap in an interactive timeline using the powerful Cool Timeline plugin.
Timeline – Vertical and Horizontal Timeline Layouts
b-timeline
Create stunning vertical or horizontal timelines to showcase stories, events, milestones, and memories on any WordPress site — no coding needed.
Journey Timeline Block
journey-timeline-block
Showcase your company history, project phases, or brand milestones with beautiful, responsive timeline blocks built for the WordPress Block Editor.
Timeline Widget For Elementor (Elementor Timeline, Vertical & Horizontal Timeline)
timeline-widget-addon-for-elementor
Highlight your company’s history, milestones, and key events directly inside Elementor using stunning vertical and horizontal timelines.
Vertical Timeline Widget for Elementor
3r-elementor-timeline-widget
Use a vertical timeline widget for Elementor to showcase your journey, story, milestones, or roadmap directly inside Elementor.
Timeline Block – Beautiful Timeline Builder for WordPress (Vertical & Horizontal Timelines) Developer Profile
120 plugins · 738K total installs
How We Detect Timeline Block – Beautiful Timeline Builder for WordPress (Vertical & Horizontal Timelines)
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/timeline-block-block/assets/js/timeline.min.js/wp-content/plugins/timeline-block-block/assets/css/timeline.min.css/wp-content/plugins/timeline-block-block/build/column.css/wp-content/plugins/timeline-block-block/build/column.js/wp-content/plugins/timeline-block-block/build/admin-dashboard.css/wp-content/plugins/timeline-block-block/build/admin-dashboard.js/wp-content/plugins/timeline-block-block/assets/js/timeline.min.js/wp-content/plugins/timeline-block-block/build/column.js/wp-content/plugins/timeline-block-block/build/admin-dashboard.jstimeline-block-block/assets/js/timeline.min.js?ver=timeline-block-block/assets/css/timeline.min.css?ver=timeline-block-block/build/column.css?ver=timeline-block-block/build/column.js?ver=timeline-block-block/build/admin-dashboard.css?ver=timeline-block-block/build/admin-dashboard.js?ver=HTML / DOM Fingerprints
tlgbAdminDashboardWrapperdata-infotlgbIsPipeCheckerTLGB_VERSIONTLGB_DIR_URLTLGB_DIR_PATHTLGB_HAS_FREETLGB_HAS_PRO[timeline_block id=