Timetable Security & Risk Analysis

wordpress.org/plugins/wp-timetable

Display a simple table timetable with different colours for different events.

10 active installs v0.0.1 PHP + WP 4.0+ Updated Nov 2, 2017
eventtabletimetimetablewp-timetable
85
A · Safe
CVEs total0
Unpatched0
Last CVENever
Safety Verdict

Is Timetable Safe to Use in 2026?

Generally Safe

Score 85/100

Timetable has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.

No known CVEs Updated 8yr ago
Risk Assessment

The static analysis of wp-timetable v0.0.1 reveals a seemingly minimal attack surface with zero identified entry points and no code signals indicating dangerous functions, SQL queries without prepared statements, or file operations. The absence of external HTTP requests and bundled libraries further suggests a contained codebase. However, a significant concern is the complete lack of output escaping, with 100% of the 14 identified outputs being unescaped. This means any data processed or displayed by the plugin could potentially be injected with malicious code, leading to cross-site scripting (XSS) vulnerabilities. The vulnerability history is clean, with no known CVEs, which is a positive sign. Despite the lack of reported vulnerabilities and a small attack surface, the critical flaw in output sanitization presents a notable security risk that needs immediate attention. The plugin exhibits good practices in areas like SQL query handling but falls critically short in protecting against XSS attacks due to insufficient output escaping.

Key Concerns

  • All output is unescaped
Vulnerabilities
None known

Timetable Security Vulnerabilities

No known vulnerabilities — this is a good sign.
Version History

Timetable Release Timeline

No version history available.
Code Analysis
Analyzed Mar 16, 2026

Timetable Code Analysis

Dangerous Functions
0
Raw SQL Queries
0
0 prepared
Unescaped Output
14
0 escaped
Nonce Checks
0
Capability Checks
0
File Operations
0
External Requests
0
Bundled Libraries
0

Output Escaping

0% escaped14 total outputs
Attack Surface

Timetable Attack Surface

Entry Points0
Unprotected0
WordPress Hooks 8
actionadmin_initadmin\timetable-admin.php:26
actionadmin_menuadmin\timetable-admin.php:48
actionadmin_initadmin\timetable-admin.php:98
actionadmin_inittimetable-foundation.php:37
actionadmin_menutimetable-foundation.php:70
actionadmin_enqueue_scriptstimetable-foundation.php:102
actionwidgets_inittimetable-widget.php:14
actionwp_enqueue_scriptstimetable-widget.php:32
Maintenance & Trust

Timetable Maintenance & Trust

Maintenance Signals

WordPress version tested4.8.28
Last updatedNov 2, 2017
PHP min version
Downloads2K

Community Trust

Rating0/100
Number of ratings0
Active installs10
Developer Profile

Timetable Developer Profile

harrymt

2 plugins · 100 total installs

84
trust score
Avg Security Score
85/100
Avg Patch Time
30 days
View full developer profile
Detection Fingerprints

How We Detect Timetable

Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.

Asset Fingerprints

Asset Paths
/wp-content/plugins/wp-timetable/assets/css/timetable.css
Version Parameters
wp-timetable/assets/css/timetable.css?ver=

HTML / DOM Fingerprints

CSS Classes
wp-timetable
FAQ

Frequently Asked Questions about Timetable