Timeline for WP Elementor Security & Risk Analysis

wordpress.org/plugins/timeline-for-wp-elementor

Timeline for WP Elementor is a powerful tool for creating timelines in WordPress websites. With Timeline for WP Elementor , you can easily create …

20 active installs v1.2 PHP + WP 5.0+ Updated Feb 28, 2023
addonselementorthemesbytetimelinewidget
85
A · Safe
CVEs total0
Unpatched0
Last CVENever
Safety Verdict

Is Timeline for WP Elementor Safe to Use in 2026?

Generally Safe

Score 85/100

Timeline for WP Elementor has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.

No known CVEs Updated 3yr ago
Risk Assessment

The "timeline-for-wp-elementor" v1.2 plugin exhibits a mixed security posture. While the absence of recorded vulnerabilities and the use of prepared statements for SQL queries are positive signs, several critical security concerns arise from the static analysis. The most significant issue is the presence of an unprotected AJAX handler, which represents a direct entry point for attackers without any authentication or authorization checks. Furthermore, the complete lack of output escaping across all identified output points is highly concerning, indicating a high risk of cross-site scripting (XSS) vulnerabilities. The plugin also shows no evidence of nonce checks or capability checks, further exacerbating the risks associated with its entry points. The lack of vulnerability history could be interpreted in two ways: either the plugin has been historically secure, or it hasn't been sufficiently scrutinized. Given the current code analysis findings, the latter is more probable. In conclusion, while the plugin avoids common pitfalls like raw SQL queries, the critical findings related to the unprotected AJAX handler and pervasive lack of output escaping necessitate immediate attention to mitigate significant security risks.

Key Concerns

  • Unprotected AJAX handler found
  • All outputs unescaped
  • No nonce checks
  • No capability checks
Vulnerabilities
None known

Timeline for WP Elementor Security Vulnerabilities

No known vulnerabilities — this is a good sign.
Code Analysis
Analyzed Mar 16, 2026

Timeline for WP Elementor Code Analysis

Dangerous Functions
0
Raw SQL Queries
0
0 prepared
Unescaped Output
5
0 escaped
Nonce Checks
0
Capability Checks
0
File Operations
0
External Requests
0
Bundled Libraries
0

Output Escaping

0% escaped5 total outputs
Attack Surface
1 unprotected

Timeline for WP Elementor Attack Surface

Entry Points1
Unprotected1

AJAX Handlers 1

authwp_ajax_wpte_never_showincludes\aep-notice\admin-notice.php:39
WordPress Hooks 13
actionelementor/preview/enqueue_stylesbase.php:7
actionwp_enqueue_scriptsbase.php:8
actionelementor/widgets/widgets_registeredbase.php:23
actionelementor/elements/categories_registeredbase.php:24
actionadmin_noticesincludes\aep-notice\admin-notice.php:4
actionadmin_enqueue_scriptsincludes\aep-notice\admin-notice.php:28
actioninitinit.php:64
actionplugins_loadedinit.php:67
actionplugins_loadedinit.php:68
actionwp_headinit.php:69
actionadmin_noticesinit.php:102
actionadmin_noticesinit.php:108
actionadmin_noticesinit.php:114
Maintenance & Trust

Timeline for WP Elementor Maintenance & Trust

Maintenance Signals

WordPress version tested6.1.10
Last updatedFeb 28, 2023
PHP min version
Downloads1K

Community Trust

Rating0/100
Number of ratings0
Active installs20
Developer Profile

Timeline for WP Elementor Developer Profile

B.M. Rafiul Alam

4 plugins · 7K total installs

96
trust score
Avg Security Score
94/100
Avg Patch Time
3 days
View full developer profile
Detection Fingerprints

How We Detect Timeline for WP Elementor

Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.

Asset Fingerprints

Asset Paths
/wp-content/plugins/timeline-for-wp-elementor/assets/css/style.css/wp-content/plugins/timeline-for-wp-elementor/includes/aep-notice/img/aep-inf-img.jpg

HTML / DOM Fingerprints

CSS Classes
aep-noticeaep-notice-logoaep-notice-contentaep-links
FAQ

Frequently Asked Questions about Timeline for WP Elementor