
ACME Divi Modules Security & Risk Analysis
wordpress.org/plugins/acme-divi-modulesAcme Divi Modules adds some free extra modules and hacks to Elegant Themes Divi Builder
Is ACME Divi Modules Safe to Use in 2026?
Use With Caution
Score 64/100ACME Divi Modules has 1 unpatched vulnerability. Evaluate alternatives or apply available mitigations.
The 'acme-divi-modules' v1.3.5 plugin exhibits a mixed security posture. While it avoids dangerous functions and uses prepared statements for all SQL queries, significant concerns exist regarding its attack surface and output sanitization. The presence of two AJAX handlers without authentication checks is a critical oversight, opening potential avenues for unauthorized actions. Furthermore, the fact that 52% of output is not properly escaped increases the risk of cross-site scripting (XSS) vulnerabilities. The taint analysis revealing unsanitized paths, although not classified as critical or high severity in this instance, warrants attention as it indicates potential for data manipulation if exploited in conjunction with other weaknesses.
The plugin's vulnerability history, specifically the presence of one unpatched medium severity CVE related to missing authorization, reinforces the concerns identified in the static analysis. This suggests a recurring pattern of authorization issues. The last vulnerability was in March 2025, implying it might be a recent or ongoing issue. While the absence of critical or high severity CVEs is positive, the existing medium vulnerability combined with the uncovered unprotected entry points suggests a need for immediate attention to strengthen its overall security. The plugin's strengths lie in its avoidance of direct SQL injection vectors and dangerous functions, but these are overshadowed by its susceptibility to authorization bypass and potential XSS attacks due to inadequate output escaping and unprotected AJAX endpoints.
Key Concerns
- Unprotected AJAX handlers
- Significant unescaped output
- Unpatched medium severity CVE
- Unsanitized paths in taint analysis
- No nonce checks on AJAX handlers
- No capability checks
ACME Divi Modules Security Vulnerabilities
CVEs by Year
Severity Breakdown
1 total CVE
ACME Divi Modules <= 1.3.5 - Missing Authorization
ACME Divi Modules Code Analysis
Output Escaping
Data Flow Analysis
ACME Divi Modules Attack Surface
AJAX Handlers 2
Shortcodes 4
WordPress Hooks 21
Maintenance & Trust
ACME Divi Modules Maintenance & Trust
Maintenance Signals
Community Trust
ACME Divi Modules Alternatives
Simple Divi Shortcode
simple-divi-shortcode
Insert DIVI Library item inside module content or inside a php template by using a shortcode.
Eventin Addon for Divi Builder
eventin-divi-addon
Eventin - Divi Builder Addons for Event Management, Event Calendar and so on...
Give – Divi Donation Modules
give-donation-modules-for-divi
A GiveWP add-on which allows you to embed any GiveWP shortcode into your Divi-powered pages.
Squad Form Styler – Contact Form 7, Gravity Forms, WPForms, and Fluent Forms
form-styler-for-divi
The Squad Forms Styler for Divi Builder allows you to style your Contact Form 7, Gravity Forms, and WPForms.
Squad Post Grid Module for Divi Theme, Extra Theme and Divi Builder
post-grid-module-for-divi
The Squad Post Grid Module for Divi Builder allows you to display your blog posts in a stylish and organized grid layout.
ACME Divi Modules Developer Profile
3 plugins · 430 total installs
How We Detect ACME Divi Modules
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/acme-divi-modules/css/jquery-ui.css/wp-content/plugins/acme-divi-modules/css/acme-divi-modules-admin.css/wp-content/plugins/acme-divi-modules/js/acme-divi-modules-admin.js/wp-content/plugins/acme-divi-modules/js/acme-divi-modules-admin.jsacme-divi-modules/css/jquery-ui.css?ver=acme-divi-modules/css/acme-divi-modules-admin.css?ver=acme-divi-modules/js/acme-divi-modules-admin.js?ver=HTML / DOM Fingerprints
acme-divi-modules-admindata-plugin-name="acme-divi-modules"ACME_DIVI_MODULES_NAME