VéritéCo Timeline Security & Risk Analysis

wordpress.org/plugins/timeline-verite-shortcode

Use the incredible HTML5 Timeline developed by VéritéCo on your website. As easy as writing a shortcode.

80 active installs v0.9.7 PHP + WP 2.0.2+ Updated May 8, 2012
shortcodestamentimelinetimeline-verite-coverite
85
A · Safe
CVEs total0
Unpatched0
Last CVENever
Safety Verdict

Is VéritéCo Timeline Safe to Use in 2026?

Generally Safe

Score 85/100

VéritéCo Timeline has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.

No known CVEs Updated 13yr ago
Risk Assessment

The "timeline-verite-shortcode" v0.9.7 plugin exhibits a generally strong security posture based on the provided static analysis. The absence of any detected dangerous functions, SQL queries executed without prepared statements, unsanitized taint flows, and file operations are all positive indicators. Furthermore, the perfect score for output escaping suggests a good effort to prevent cross-site scripting vulnerabilities.

However, there are specific areas that warrant attention and mitigate the overall strong score. The complete lack of nonce checks and capability checks, even with a limited attack surface, presents a potential concern. While the current attack surface is minimal, any expansion or introduction of AJAX or REST API endpoints without these crucial security measures would significantly increase the risk.

The vulnerability history is remarkably clean, with no recorded CVEs. This, coupled with the static analysis findings, suggests that the developers have implemented sound security practices. Nevertheless, the absence of checks for actions that could be initiated by unauthenticated users remains a weakness that could be exploited if not addressed, especially as the plugin evolves.

Key Concerns

  • Missing nonce checks on entry points
  • Missing capability checks on entry points
Vulnerabilities
None known

VéritéCo Timeline Security Vulnerabilities

No known vulnerabilities — this is a good sign.
Code Analysis
Analyzed Mar 16, 2026

VéritéCo Timeline Code Analysis

Dangerous Functions
0
Raw SQL Queries
0
0 prepared
Unescaped Output
0
0 escaped
Nonce Checks
0
Capability Checks
0
File Operations
0
External Requests
0
Bundled Libraries
1

Bundled Libraries

TinyMCE
Attack Surface

VéritéCo Timeline Attack Surface

Entry Points1
Unprotected0

Shortcodes 1

[timeline] verite-timeline.php:42
WordPress Hooks 4
actioninitverite-timeline.php:30
actioninitverite-timeline.php:36
actionmedia_buttons_contextverite-timeline.php:115
actionadmin_footerverite-timeline.php:118
Maintenance & Trust

VéritéCo Timeline Maintenance & Trust

Maintenance Signals

WordPress version tested3.3.2
Last updatedMay 8, 2012
PHP min version
Downloads11K

Community Trust

Rating60/100
Number of ratings2
Active installs80
Developer Profile

VéritéCo Timeline Developer Profile

Miguel Peixe

2 plugins · 90 total installs

89
trust score
Avg Security Score
93/100
Avg Patch Time
30 days
View full developer profile
Detection Fingerprints

How We Detect VéritéCo Timeline

Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.

Asset Fingerprints

Asset Paths
/wp-content/plugins/timeline-verite-shortcode/js/timeline-embed.js/wp-content/plugins/timeline-verite-shortcode/css/timeline.css/wp-content/plugins/timeline-verite-shortcode/js/locale/pt-br.js/wp-content/plugins/timeline-verite-shortcode/js/locale/es.js/wp-content/plugins/timeline-verite-shortcode/js/locale/kr.js/wp-content/plugins/timeline-verite-shortcode/js/locale/de.js/wp-content/plugins/timeline-verite-shortcode/js/locale/it.js/wp-content/plugins/timeline-verite-shortcode/js/locale/fr.js+3 more
Script Paths
/wp-content/plugins/timeline-verite-shortcode/js/timeline-embed.js/wp-content/plugins/timeline-verite-shortcode/js/locale/pt-br.js/wp-content/plugins/timeline-verite-shortcode/js/locale/es.js/wp-content/plugins/timeline-verite-shortcode/js/locale/kr.js/wp-content/plugins/timeline-verite-shortcode/js/locale/de.js/wp-content/plugins/timeline-verite-shortcode/js/locale/it.js+4 more

HTML / DOM Fingerprints

CSS Classes
timeline-embed
HTML Comments
// <![CDATA[
Data Attributes
id="timeline-embed"id="add_timeline_form"
JS Globals
timeline_config
Shortcode Output
[timeline srcwidthheightmaptype
FAQ

Frequently Asked Questions about VéritéCo Timeline