
Timeline Express – Single Column Add-On Security & Risk Analysis
wordpress.org/plugins/timeline-express-single-column-add-onEnable a 'single-column' parameter in Timeline Express to display timelines in a single column.
Is Timeline Express – Single Column Add-On Safe to Use in 2026?
Generally Safe
Score 85/100Timeline Express – Single Column Add-On has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.
The security posture of the timeline-express-single-column-add-on plugin v1.1.0 appears to be strong based on the static analysis provided. There are no identified entry points such as AJAX handlers, REST API routes, shortcodes, or cron events that are directly exposed. Furthermore, the code signals indicate a complete absence of dangerous functions, all SQL queries are using prepared statements, and all outputs are properly escaped. The lack of file operations and external HTTP requests also contributes to a reduced attack surface. The vulnerability history shows no recorded CVEs, suggesting a good track record of security.
However, a significant concern arises from the complete absence of nonce checks and capability checks. While the current static analysis reports zero entry points without authentication, this does not preclude potential vulnerabilities if new functionality were to be added or if the reporting is incomplete. The plugin's reliance on bundled libraries like TinyMCE also introduces a potential risk if this library is not kept up-to-date by the plugin developer. Without any documented checks for nonces or capabilities, any functionality, even if not immediately apparent as an entry point, could be susceptible to unauthorized access or manipulation if vulnerabilities are discovered in the core WordPress functions it might rely upon.
In conclusion, the plugin exhibits excellent practices regarding SQL security, output escaping, and avoiding dangerous functions. The clean vulnerability history is a positive indicator. The primary weakness lies in the apparent lack of any explicit nonce or capability checks, which is a critical security control for WordPress plugins. This omission, coupled with the use of bundled libraries, represents a potential risk that warrants attention, even in the absence of direct evidence of exploitation.
Key Concerns
- Missing nonce checks
- Missing capability checks
- Bundled library (TinyMCE) potentially outdated
Timeline Express – Single Column Add-On Security Vulnerabilities
Timeline Express – Single Column Add-On Code Analysis
Bundled Libraries
Timeline Express – Single Column Add-On Attack Surface
WordPress Hooks 6
Maintenance & Trust
Timeline Express – Single Column Add-On Maintenance & Trust
Maintenance Signals
Community Trust
Timeline Express – Single Column Add-On Alternatives
Timeline Express HTML Excerpts Add-on
timeline-express-html-excerpt-add-on
Enable a new HTML Excerpt field on Timeline Express announcements, which can be used to replace the default generated excerpts.
Timeline Express – Date – Time Add-On
timeline-express-date-time-add-on
Assign and display times alongside the announcement dates in Timeline Express announcements.
Timeline Express – No Icons Add-On
timeline-express-no-icons-add-on
Remove the icons associated with Timeline Express announcements.
SMSA Shipping (official)
smsa-shipping-official
This plugin integrates SMSA Express Shipping for easy shipment tracking and management.
Column Stretch for Elementor
column-stretch-elementor
Elementor Column Stretch is a simple WordPress plugin that adds ability to Elementor page builder to stretch the columns to left or right.
Timeline Express – Single Column Add-On Developer Profile
15 plugins · 136K total installs
How We Detect Timeline Express – Single Column Add-On
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/timeline-express-single-column-add-on/lib/css/timeline-express-single-column.css/wp-content/plugins/timeline-express-single-column-add-on/lib/css/timeline-express-single-column.min.css/wp-content/plugins/timeline-express-single-column-add-on/lib/js/timeline-express-single-column.js/wp-content/plugins/timeline-express-single-column-add-on/lib/js/timeline-express-single-column.min.jslib/js/timeline-express-single-column.jslib/js/timeline-express-single-column.min.jstimeline-express-single-column-add-on/lib/css/timeline-express-single-column.css?ver=timeline-express-single-column-add-on/lib/js/timeline-express-single-column.js?ver=HTML / DOM Fingerprints
single-columntimeline-express-single-column-stylescd-timeline-block.single-columncd-timeline-content:beforesingle-column