
WP SIMILE Timeline Security & Risk Analysis
wordpress.org/plugins/wp-simile-timelineIntegrates the SIMILE Timeline into WordPress and provides an option interface for the various timeline settings.
Is WP SIMILE Timeline Safe to Use in 2026?
Generally Safe
Score 85/100WP SIMILE Timeline has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.
The wp-simile-timeline plugin, version 0.5.3, presents a mixed security profile. On the positive side, it demonstrates good practices by exclusively using prepared statements for all SQL queries and has no recorded historical vulnerabilities, suggesting a mature and relatively secure development history. The attack surface is also small, with only one shortcode and no AJAX handlers or REST API routes identified as entry points. However, significant concerns arise from the static analysis. The plugin exhibits a very low rate of output escaping (only 3%), indicating a high potential for cross-site scripting (XSS) vulnerabilities. Furthermore, taint analysis reveals two high-severity flows with unsanitized paths, which could lead to sensitive data exposure or unauthorized actions if exploited. The presence of a dangerous function like `set_time_limit` also warrants caution, as it can be misused to cause denial-of-service conditions. While the vulnerability history is clean, the identified code-level weaknesses, particularly the poor output escaping and high-severity taint flows, represent immediate risks that outweigh the lack of past CVEs.
Key Concerns
- High severity taint flows with unsanitized paths
- Low percentage of properly escaped output
- Use of dangerous function set_time_limit
- Lack of capability checks on entry points
WP SIMILE Timeline Security Vulnerabilities
WP SIMILE Timeline Release Timeline
WP SIMILE Timeline Code Analysis
Dangerous Functions Found
SQL Query Safety
Output Escaping
Data Flow Analysis
WP SIMILE Timeline Attack Surface
Shortcodes 1
WordPress Hooks 10
Maintenance & Trust
WP SIMILE Timeline Maintenance & Trust
Maintenance Signals
Community Trust
WP SIMILE Timeline Alternatives
CoolClock – a Javascript Analog Clock
coolclock
Show an analog clock on your WordPress site sidebar or in post and page content.
JS Categories List Widget
jquery-categories-list
A simple Gutenberg block and JS widget (can be called from posts) for displaying categories in a list with some effects.
Show Eventbrite Events – Event Feed for Eventbrite
event-feed-for-eventbrite
Show Eventbrite events easily with the Eventbrite WordPress plugin. Eventbrite widget integration without imports or complicated setup.
Allow Javascript in Text Widgets
allow-javascript-in-text-widgets
Replaces the default text widget with one that allows Javascript so you can do basic things like add Google Ads to your sidebar without using other pl …
catnip
catnip
With catnip and The Cat API it's Caturday everyday in WordPress!
WP SIMILE Timeline Developer Profile
3 plugins · 30 total installs
How We Detect WP SIMILE Timeline
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/wp-simile-timeline/inc/js/timeline-api.js/wp-content/plugins/wp-simile-timeline/inc/js/timeline-source.js/wp-content/plugins/wp-simile-timeline/inc/js/timeline-init.js/wp-content/plugins/wp-simile-timeline/inc/css/timeline.css/wp-content/plugins/wp-simile-timeline/inc/css/timeline_admin.css/wp-content/plugins/wp-simile-timeline/inc/js/timeline-api.js/wp-content/plugins/wp-simile-timeline/inc/js/timeline-source.js/wp-content/plugins/wp-simile-timeline/inc/js/timeline-init.jswp-simile-timeline/inc/js/timeline-api.js?ver=wp-simile-timeline/inc/js/timeline-source.js?ver=wp-simile-timeline/inc/js/timeline-init.js?ver=wp-simile-timeline/inc/css/timeline.css?ver=wp-simile-timeline/inc/css/timeline_admin.css?ver=HTML / DOM Fingerprints
timeline-bandtimeline-eventtimeline-hotzoneSIMILE Timeline for WordPressCopyright 2006-2019 freshlabsThis program is free software: you can redistribute it and/or modifyThis program is distributed in the hope that it will be useful,+40 moredata-timeline-eventsdata-timeline-band-iddata-timeline-event-idTimelineTimeline_ajax_urlTimeline_ajax_nonce[similetimeline]