Timeline Express – Single Column Add-On Security & Risk Analysis

wordpress.org/plugins/timeline-express-single-column-add-on

Enable a 'single-column' parameter in Timeline Express to display timelines in a single column.

600 active installs v1.1.0 PHP 5.6+ WP + Updated Mar 22, 2023
addoncolumnexpresssingletimeline
85
A · Safe
CVEs total0
Unpatched0
Last CVENever
Safety Verdict

Is Timeline Express – Single Column Add-On Safe to Use in 2026?

Generally Safe

Score 85/100

Timeline Express – Single Column Add-On has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.

No known CVEs Updated 3yr ago
Risk Assessment

The security posture of the timeline-express-single-column-add-on plugin v1.1.0 appears to be strong based on the static analysis provided. There are no identified entry points such as AJAX handlers, REST API routes, shortcodes, or cron events that are directly exposed. Furthermore, the code signals indicate a complete absence of dangerous functions, all SQL queries are using prepared statements, and all outputs are properly escaped. The lack of file operations and external HTTP requests also contributes to a reduced attack surface. The vulnerability history shows no recorded CVEs, suggesting a good track record of security.

However, a significant concern arises from the complete absence of nonce checks and capability checks. While the current static analysis reports zero entry points without authentication, this does not preclude potential vulnerabilities if new functionality were to be added or if the reporting is incomplete. The plugin's reliance on bundled libraries like TinyMCE also introduces a potential risk if this library is not kept up-to-date by the plugin developer. Without any documented checks for nonces or capabilities, any functionality, even if not immediately apparent as an entry point, could be susceptible to unauthorized access or manipulation if vulnerabilities are discovered in the core WordPress functions it might rely upon.

In conclusion, the plugin exhibits excellent practices regarding SQL security, output escaping, and avoiding dangerous functions. The clean vulnerability history is a positive indicator. The primary weakness lies in the apparent lack of any explicit nonce or capability checks, which is a critical security control for WordPress plugins. This omission, coupled with the use of bundled libraries, represents a potential risk that warrants attention, even in the absence of direct evidence of exploitation.

Key Concerns

  • Missing nonce checks
  • Missing capability checks
  • Bundled library (TinyMCE) potentially outdated
Vulnerabilities
None known

Timeline Express – Single Column Add-On Security Vulnerabilities

No known vulnerabilities — this is a good sign.
Code Analysis
Analyzed Mar 16, 2026

Timeline Express – Single Column Add-On Code Analysis

Dangerous Functions
0
Raw SQL Queries
0
0 prepared
Unescaped Output
0
0 escaped
Nonce Checks
0
Capability Checks
0
File Operations
0
External Requests
0
Bundled Libraries
1

Bundled Libraries

TinyMCE
Attack Surface

Timeline Express – Single Column Add-On Attack Surface

Entry Points0
Unprotected0
WordPress Hooks 6
actionadmin_noticestimeline-express-single-column-add-on.php:88
filtershortcode_atts_timeline-expresstimeline-express-single-column-add-on.php:103
filtertimeline-express-announcement-container-classtimeline-express-single-column-add-on.php:139
filtertimeline_express_container_classestimeline-express-single-column-add-on.php:142
actiontimeline-express-container-toptimeline-express-single-column-add-on.php:145
actionplugins_loadedtimeline-express-single-column-add-on.php:250
Maintenance & Trust

Timeline Express – Single Column Add-On Maintenance & Trust

Maintenance Signals

WordPress version tested6.2.9
Last updatedMar 22, 2023
PHP min version5.6
Downloads12K

Community Trust

Rating0/100
Number of ratings0
Active installs600
Developer Profile

Timeline Express – Single Column Add-On Developer Profile

Evan Herman

15 plugins · 136K total installs

68
trust score
Avg Security Score
84/100
Avg Patch Time
375 days
View full developer profile
Detection Fingerprints

How We Detect Timeline Express – Single Column Add-On

Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.

Asset Fingerprints

Asset Paths
/wp-content/plugins/timeline-express-single-column-add-on/lib/css/timeline-express-single-column.css/wp-content/plugins/timeline-express-single-column-add-on/lib/css/timeline-express-single-column.min.css/wp-content/plugins/timeline-express-single-column-add-on/lib/js/timeline-express-single-column.js/wp-content/plugins/timeline-express-single-column-add-on/lib/js/timeline-express-single-column.min.js
Script Paths
lib/js/timeline-express-single-column.jslib/js/timeline-express-single-column.min.js
Version Parameters
timeline-express-single-column-add-on/lib/css/timeline-express-single-column.css?ver=timeline-express-single-column-add-on/lib/js/timeline-express-single-column.js?ver=

HTML / DOM Fingerprints

CSS Classes
single-columntimeline-express-single-column-stylescd-timeline-block.single-columncd-timeline-content:before
Data Attributes
single-column
FAQ

Frequently Asked Questions about Timeline Express – Single Column Add-On