Timeline Full Widget Security & Risk Analysis

wordpress.org/plugins/timeline-full-widget

Free timeline plugin for WordPress, Elementor, and Gutenberg. Create responsive timelines, roadmaps, and milestones without code.

20 active installs v2.2.1 PHP + WP 5.0+ Updated May 30, 2026
blockseditorelementorgutenberg-blockstimeline
100
A · Safe
CVEs total0
Unpatched0
Last CVENever
Safety Verdict

Is Timeline Full Widget Safe to Use in 2026?

Generally Safe

Score 100/100

Timeline Full Widget has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.

No known CVEs Updated 2mo ago
Risk Assessment

The "timeline-full-widget" plugin v1.2.0 exhibits a strong security posture based on the provided static analysis. The complete absence of identified dangerous functions, raw SQL queries, and unsanitized taint flows is highly commendable. The plugin also demonstrates good practices by employing prepared statements for all SQL queries and properly escaping the vast majority of its output.

However, a few areas warrant attention. The lack of any nonce checks, while potentially mitigated by the absence of AJAX handlers and shortcodes, could be a concern if the plugin's functionality evolves. Similarly, relying solely on 4 capability checks without any nonce validation for its limited entry points presents a potential, albeit small, risk. The plugin also performs one file operation, which, without further context, could be a minor area for scrutiny. The absence of any recorded vulnerabilities in its history is a significant positive indicator, suggesting a well-maintained and secure codebase.

Overall, this plugin appears to be robustly secured. The developers have implemented good security practices in critical areas like SQL and output sanitization. The few minor potential risks identified are primarily due to the limited attack surface and the lack of specific security controls like nonces, which might be deemed acceptable given the current plugin structure. Continued vigilance and adherence to secure coding practices are recommended, especially if new features are added.

Key Concerns

  • No nonce checks found
  • File operations present
Vulnerabilities
None known

Timeline Full Widget Security Vulnerabilities

No known vulnerabilities — this is a good sign.
Version History

Timeline Full Widget Release Timeline

v2.2.1Current
v2.2.0
v2.1.1
v2.1.0
v2.0.0
v1.2.0
v1.1.0
v1.0.1
v1.0.0
Code Analysis
Analyzed Mar 17, 2026

Timeline Full Widget Code Analysis

Dangerous Functions
0
Raw SQL Queries
0
0 prepared
Unescaped Output
2
23 escaped
Nonce Checks
0
Capability Checks
4
File Operations
1
External Requests
0
Bundled Libraries
0

Output Escaping

92% escaped25 total outputs
Attack Surface

Timeline Full Widget Attack Surface

Entry Points0
Unprotected0
WordPress Hooks 14
actionelementor/widgets/registerelementor-timeline-widget.php:699
actioninittimeline-full-widget.php:57
actionelementor/widgets/widgets_registeredtimeline-full-widget.php:60
actionelementor/editor/after_enqueue_scriptstimeline-full-widget.php:61
actioninittimeline-full-widget.php:64
actionwp_enqueue_scriptstimeline-full-widget.php:67
actionadmin_inittimeline-full-widget.php:70
actionadmin_enqueue_scriptstimeline-full-widget.php:71
actionwp_enqueue_scriptstimeline-full-widget.php:74
actionadmin_enqueue_scriptstimeline-full-widget.php:75
filterscript_loader_tagtimeline-full-widget.php:78
filtermce_external_pluginstimeline-full-widget.php:336
filtermce_buttonstimeline-full-widget.php:345
filtertiny_mce_before_inittimeline-full-widget.php:354
Maintenance & Trust

Timeline Full Widget Maintenance & Trust

Maintenance Signals

WordPress version tested7.0.2
Last updatedMay 30, 2026
PHP min version
Downloads792

Community Trust

Rating0/100
Number of ratings0
Active installs20
Developer Profile

Timeline Full Widget Developer Profile

BlackStar

2 plugins · 20 total installs

94
trust score
Avg Security Score
100/100
Avg Patch Time
30 days
View full developer profile
Detection Fingerprints

How We Detect Timeline Full Widget

Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.

Asset Fingerprints

Asset Paths
/wp-content/plugins/timeline-full-widget/assets/css/core/style.css/wp-content/plugins/timeline-full-widget/assets/js/adapters/elementor-adapter.js/wp-content/plugins/timeline-full-widget/assets/js/adapters/gutenberg-adapter.js/wp-content/plugins/timeline-full-widget/assets/js/core/animation.js/wp-content/plugins/timeline-full-widget/assets/elementor/elementor-media-preview.js
Script Paths
/wp-content/plugins/timeline-full-widget/assets/elementor/elementor-media-preview.js/wp-content/plugins/timeline-full-widget/assets/js/adapters/elementor-adapter.js/wp-content/plugins/timeline-full-widget/assets/js/adapters/gutenberg-adapter.js/wp-content/plugins/timeline-full-widget/assets/js/core/animation.js
Version Parameters
timeline-full-widget/assets/css/core/style.css?ver=timeline-full-widget/assets/js/adapters/elementor-adapter.js?ver=timeline-full-widget/assets/js/adapters/gutenberg-adapter.js?ver=timeline-full-widget/assets/js/core/animation.js?ver=timeline-full-widget/assets/elementor/elementor-media-preview.js?ver=

HTML / DOM Fingerprints

CSS Classes
timeline-widget-main
Data Attributes
data-timeline-widget-options
JS Globals
window.zaTimelineElementor
Shortcode Output
[timeline-widget]
FAQ

Frequently Asked Questions about Timeline Full Widget