Ultimate Timeline – Responsive History Timeline Security & Risk Analysis

wordpress.org/plugins/ultimate-timeline

Ultimate Timeline plugin creates beautiful history time-lines on your website. It is responsive time-line showcase in DESC order based on posted date …

70 active installs v3.4 PHP + WP + Updated Feb 23, 2026
events-timelinehistory-timelineresponsive-timelineroadmaptimeline
100
A · Safe
CVEs total0
Unpatched0
Last CVENever
Safety Verdict

Is Ultimate Timeline – Responsive History Timeline Safe to Use in 2026?

Generally Safe

Score 100/100

Ultimate Timeline – Responsive History Timeline has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.

No known CVEs Updated 2mo ago
Risk Assessment

The 'ultimate-timeline' plugin v3.4 presents a generally positive security posture, with several good practices evident. The code analysis indicates no dangerous functions, all SQL queries are properly prepared, and a high percentage of output is escaped. The absence of vulnerability history, including CVEs, suggests a historically stable and secure plugin. However, there is one notable concern: an unprotected AJAX handler represents a significant attack vector. While the plugin has other security mechanisms like nonce and capability checks, the lack of authentication on this specific entry point could expose it to unauthorized actions if the functionality it triggers is sensitive.

Key Concerns

  • Unprotected AJAX handler
Vulnerabilities
None known

Ultimate Timeline – Responsive History Timeline Security Vulnerabilities

No known vulnerabilities — this is a good sign.
Version History

Ultimate Timeline – Responsive History Timeline Release Timeline

v3.4Current
v3.3
v3.2
v3.1
v3.0
v2.9
v2.8
v2.7
v2.6
v2.5
v2.4
v2.3
v2.2
v2.1
v2.0
v1.9
v1.8
v1.7
v1.6
v1.5
Code Analysis
Analyzed Mar 16, 2026

Ultimate Timeline – Responsive History Timeline Code Analysis

Dangerous Functions
0
Raw SQL Queries
0
0 prepared
Unescaped Output
7
124 escaped
Nonce Checks
2
Capability Checks
1
File Operations
0
External Requests
0
Bundled Libraries
0

Output Escaping

95% escaped131 total outputs
Attack Surface
1 unprotected

Ultimate Timeline – Responsive History Timeline Attack Surface

Entry Points2
Unprotected1

AJAX Handlers 1

authwp_ajax_wct-update-timeline-optionsadmin\weblizar-timeline-post-type.php:18

Shortcodes 1

[weblizar_timeline] public\public.php:10
WordPress Hooks 18
actionadd_meta_boxesadmin\weblizar-timeline-meta-box.php:6
actionsave_postadmin\weblizar-timeline-meta-box.php:7
filtermanage_edit-weblizar_timeline_columnsadmin\weblizar-timeline-post-type.php:10
actionmanage_weblizar_timeline_posts_custom_columnadmin\weblizar-timeline-post-type.php:11
actionpost_submitbox_misc_actionsadmin\weblizar-timeline-post-type.php:12
actionadmin_menuadmin\weblizar-timeline-post-type.php:13
actionadmin_enqueue_scriptsadmin\weblizar-timeline-post-type.php:15
actionadmin_enqueue_scriptsadmin\weblizar-timeline-post-type.php:16
actioninitincludes\fa-icons\fa-icons-class.php:18
actionwp_enqueue_scriptsincludes\fa-icons\fa-icons-class.php:21
actionadd_meta_boxesincludes\fa-icons\fa-icons-class.php:25
actionsave_postincludes\fa-icons\fa-icons-class.php:27
actionadmin_enqueue_scriptsincludes\fa-icons\fa-icons-class.php:29
actioninitpublic\public.php:6
actionwp_enqueue_scriptspublic\public.php:8
filterthe_contentpublic\public.php:12
filtersingle_templatepublic\public.php:14
actionplugins_loadedultimate-timeline.php:26
Maintenance & Trust

Ultimate Timeline – Responsive History Timeline Maintenance & Trust

Maintenance Signals

WordPress version tested6.9.4
Last updatedFeb 23, 2026
PHP min version
Downloads10K

Community Trust

Rating0/100
Number of ratings0
Active installs70
Developer Profile

Ultimate Timeline – Responsive History Timeline Developer Profile

Weblizar - WordPress Themes & Plugin

26 plugins · 56K total installs

76
trust score
Avg Security Score
96/100
Avg Patch Time
952 days
View full developer profile
Detection Fingerprints

How We Detect Ultimate Timeline – Responsive History Timeline

Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.

Asset Fingerprints

Asset Paths
/wp-content/plugins/ultimate-timeline/assets/css/bootstrap.min.css/wp-content/plugins/ultimate-timeline/includes/fa-icons/css/font-awesome/css/all.min.css/wp-content/plugins/ultimate-timeline/assets/css/timeline_option.css/wp-content/plugins/ultimate-timeline/assets/js/popper.min.js/wp-content/plugins/ultimate-timeline/assets/js/bootstrap.min.js/wp-content/plugins/ultimate-timeline/includes/fa-icons/js/min/awesome.js/wp-content/plugins/ultimate-timeline/assets/js/timeline_option.js/wp-content/plugins/ultimate-timeline/assets/js/wct-ajax.js+11 more
Script Paths
/wp-content/plugins/ultimate-timeline/assets/js/popper.min.js/wp-content/plugins/ultimate-timeline/assets/js/bootstrap.min.js/wp-content/plugins/ultimate-timeline/includes/fa-icons/js/min/awesome.js/wp-content/plugins/ultimate-timeline/assets/js/timeline_option.js/wp-content/plugins/ultimate-timeline/assets/js/wct-ajax.js/wp-content/plugins/ultimate-timeline/assets/js/jquery.fontselect.min.js+4 more
Version Parameters
ultimate-timeline/assets/css/bootstrap.min.css?ver=ultimate-timeline/includes/fa-icons/css/font-awesome/css/all.min.css?ver=ultimate-timeline/assets/css/timeline_option.css?ver=ultimate-timeline/assets/js/popper.min.js?ver=ultimate-timeline/assets/js/bootstrap.min.js?ver=ultimate-timeline/includes/fa-icons/js/min/awesome.js?ver=ultimate-timeline/assets/js/timeline_option.js?ver=ultimate-timeline/assets/js/wct-ajax.js?ver=ultimate-timeline/assets/css/fontselect.css?ver=ultimate-timeline/assets/css/image-upload.css?ver=ultimate-timeline/includes/fa-icons/css/fa-shims.css?ver=ultimate-timeline/includes/fa-icons/css/fa-field.css?ver=ultimate-timeline/assets/css/zebra_datepicker.min.css?ver=ultimate-timeline/assets/css/ultimate-timeline.css?ver=ultimate-timeline/assets/js/jquery.fontselect.min.js?ver=ultimate-timeline/assets/js/image-upload.js?ver=ultimate-timeline/includes/fa-icons/js/fa-field.js?ver=ultimate-timeline/assets/js/zebra_datepicker.min.js?ver=ultimate-timeline/assets/js/wct-admin.js?ver=

HTML / DOM Fingerprints

CSS Classes
weblizar-timeline-options-wrapper
HTML Comments
<!-- Ultimate Timeline --><!-- / Ultimate Timeline --><!-- WEBLIZAR TIMELINE BACKEND OPTIONS --><!-- /WEBLIZAR TIMELINE BACKEND OPTIONS -->
Data Attributes
data-wct-target-timelinedata-wct-color
JS Globals
wct_color_picker_global_vars
FAQ

Frequently Asked Questions about Ultimate Timeline – Responsive History Timeline