Timeline Express – No Icons Add-On Security & Risk Analysis
wordpress.org/plugins/timeline-express-no-icons-add-onRemove the icons associated with Timeline Express announcements.
Is Timeline Express – No Icons Add-On Safe to Use in 2026?
Generally Safe
Score 85/100Timeline Express – No Icons Add-On has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.
The plugin "timeline-express-no-icons-add-on" v1.2.0 demonstrates a strong security posture based on the provided static analysis. The absence of any AJAX handlers, REST API routes, shortcodes, or cron events with unprotected entry points indicates a minimal attack surface, which is a significant strength. Furthermore, the code utilizes prepared statements for all SQL queries, ensures 100% output escaping, and has zero recorded vulnerability history, including no known CVEs. The presence of a nonce check is also a positive indicator of security awareness.
While the static analysis and vulnerability history are exceptionally clean, the data reveals no critical or high-severity issues, and notably, zero untainted flows were analyzed. This suggests that either the plugin is very simple and has limited data processing, or the analysis tools were not able to thoroughly trace data flow within its codebase. The plugin does bundle TinyMCE, which could potentially be a vector if an outdated version with known vulnerabilities is included, though this is not explicitly stated in the provided data.
Overall, the plugin appears to be developed with security in mind, exhibiting good practices like prepared statements and output escaping. The lack of historical vulnerabilities further reinforces this. However, the limited scope of taint analysis and the potential for issues within bundled libraries warrant a cautious approach. The plugin's strengths lie in its lack of direct entry points and adherence to fundamental security principles in its code.
Key Concerns
- Bundled library (TinyMCE) may have vulnerabilities
Timeline Express – No Icons Add-On Security Vulnerabilities
Timeline Express – No Icons Add-On Code Analysis
Bundled Libraries
Timeline Express – No Icons Add-On Attack Surface
WordPress Hooks 7
Maintenance & Trust
Timeline Express – No Icons Add-On Maintenance & Trust
Maintenance Signals
Community Trust
Timeline Express – No Icons Add-On Alternatives
Timeline Express – Date – Time Add-On
timeline-express-date-time-add-on
Assign and display times alongside the announcement dates in Timeline Express announcements.
Advanced Custom Fields – Taxonomy Field add-on
advanced-custom-fields-taxonomy-field-add-on
Adds a Taxonomy Field to Advanced Custom Fields. Select one or more taxonomy terms and assign them to the post.
Timeline Express HTML Excerpts Add-on
timeline-express-html-excerpt-add-on
Enable a new HTML Excerpt field on Timeline Express announcements, which can be used to replace the default generated excerpts.
Post Timeline
post-timeline
Create stunning and interactive timelines for your WordPress posts with ease. Post Timeline is the ultimate plugin for displaying your WordPress conte …
Timeline Express – Single Column Add-On
timeline-express-single-column-add-on
Enable a 'single-column' parameter in Timeline Express to display timelines in a single column.
Timeline Express – No Icons Add-On Developer Profile
15 plugins · 136K total installs
How We Detect Timeline Express – No Icons Add-On
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/timeline-express-no-icons-add-on/lib/css/timeline-express-no-icons-add-on.css/wp-content/plugins/timeline-express-no-icons-add-on/lib/css/timeline-express-no-icons-add-on.min.csstimeline-express-no-icons-add-on/lib/css/timeline-express-no-icons-add-on.css?ver=timeline-express-no-icons-add-on/lib/css/timeline-express-no-icons-add-on.min.css?ver=HTML / DOM Fingerprints
hide-iconno-animationno-icondata-no-icons