Timeline Express Security & Risk Analysis

wordpress.org/plugins/timeline-express

Timeline Express creates a beautiful vertical animated and responsive timeline of posts, in chronological order.

10K active installs v1.8.1 PHP + WP 4.0+ Updated Mar 22, 2023
animatedcompanyresponsivetimelinevertical
85
A · Safe
CVEs total0
Unpatched0
Last CVENever
Safety Verdict

Is Timeline Express Safe to Use in 2026?

Generally Safe

Score 85/100

Timeline Express has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.

No known CVEs Updated 3yr ago
Risk Assessment

The security posture of Timeline Express v1.8.1 appears to be strong based on the provided static analysis and vulnerability history. The absence of any detected CVEs, particularly critical or high-severity ones, is a significant positive indicator. The code analysis reveals a clean slate with no dangerous functions, no file operations, and no external HTTP requests, all contributing to a reduced attack surface. Furthermore, the plugin exclusively uses prepared statements for its SQL queries and all output is properly escaped, mitigating common risks like SQL injection and Cross-Site Scripting (XSS).

However, a notable area of concern is the complete absence of nonce checks and capability checks. While the static analysis reports zero unprotected entry points, this could be an oversight in the analysis or indicate that all entry points are implicitly protected by WordPress core. Nevertheless, the explicit lack of these security mechanisms is a potential weakness. The presence of TinyMCE as a bundled library, while common, could also be a minor concern if it's an older version or has known vulnerabilities, though this is not explicitly stated.

In conclusion, Timeline Express v1.8.1 exhibits excellent security practices in several key areas, particularly in preventing common vulnerabilities like SQL injection and XSS. The lack of historical vulnerabilities further bolsters confidence. The primary weakness identified is the absence of explicit nonce and capability checks, which, while not directly leading to a detected vulnerability in this version, represents a missed opportunity for robust client-side and server-side security enforcement. This plugin is generally secure but could be improved by implementing these standard security checks.

Key Concerns

  • Missing nonce checks
  • Missing capability checks
Vulnerabilities
None known

Timeline Express Security Vulnerabilities

No known vulnerabilities — this is a good sign.
Code Analysis
Analyzed Mar 16, 2026

Timeline Express Code Analysis

Dangerous Functions
0
Raw SQL Queries
0
4 prepared
Unescaped Output
0
13 escaped
Nonce Checks
0
Capability Checks
0
File Operations
0
External Requests
0
Bundled Libraries
1

Bundled Libraries

TinyMCE

SQL Query Safety

100% prepared4 total queries

Output Escaping

100% escaped13 total outputs
Attack Surface

Timeline Express Attack Surface

Entry Points0
Unprotected0
WordPress Hooks 3
actiontimeline_express_before_announcement_contenttemplates\timeline-express-page-wrappers-start.php:47
actiontimeline_express_after_announcement_contenttemplates\timeline-express-page-wrappers-start.php:48
actioninittimeline-express.php:47
Maintenance & Trust

Timeline Express Maintenance & Trust

Maintenance Signals

WordPress version tested6.2.9
Last updatedMar 22, 2023
PHP min version
Downloads520K

Community Trust

Rating86/100
Number of ratings165
Active installs10K
Developer Profile

Timeline Express Developer Profile

Evan Herman

15 plugins · 136K total installs

68
trust score
Avg Security Score
84/100
Avg Patch Time
375 days
View full developer profile
Detection Fingerprints

How We Detect Timeline Express

Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.

Asset Fingerprints

Asset Paths
/wp-content/plugins/timeline-express/assets/css/timeline-express.css/wp-content/plugins/timeline-express/assets/js/timeline-express.min.js/wp-content/plugins/timeline-express/assets/js/timeline-express-isotope.min.js
Script Paths
/wp-content/plugins/timeline-express/assets/js/timeline-express.min.js/wp-content/plugins/timeline-express/assets/js/timeline-express-isotope.min.js
Version Parameters
timeline-express/assets/css/timeline-express.css?ver=timeline-express/assets/js/timeline-express.min.js?ver=timeline-express/assets/js/timeline-express-isotope.min.js?ver=

HTML / DOM Fingerprints

CSS Classes
timeline-express-wrappertimeline-express-datetimeline-express-contenttimeline-express-entry-titletimeline-express-entry-contenttimeline-express-entry-image
Data Attributes
data-timeline-mobile-scroll-effectdata-timeline-mobile-scroll-effect-speed
JS Globals
timelineExpress
Shortcode Output
[timeline-express[timeline-express-event
FAQ

Frequently Asked Questions about Timeline Express