Divein Builder Security & Risk Analysis

wordpress.org/plugins/divein-builder

Advanced drag and drop page builder plugin. Create pages and posts visually with any theme, any template, any design.

0 active installs v1.0 PHP 5.4+ WP 4.5+ Updated Dec 30, 2017
drag-and-dropeditorlanding-pagepage-buildervisual-editor
85
A · Safe
CVEs total0
Unpatched0
Last CVENever
Download
Safety Verdict

Is Divein Builder Safe to Use in 2026?

Generally Safe

Score 85/100

Divein Builder has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.

No known CVEs Updated 8yr ago
Risk Assessment

The divein-builder plugin v1.0 exhibits a mixed security posture. On the positive side, it demonstrates good practices regarding SQL queries, utilizing prepared statements exclusively, and a high percentage of properly escaped output. The absence of file operations, external HTTP requests, and bundled libraries further reduces potential attack vectors. However, significant concerns arise from the attack surface analysis. The presence of one AJAX handler without authentication checks is a critical oversight, creating a direct entry point for unauthorized actions. Furthermore, the plugin lacks nonce checks and capability checks entirely, meaning that even if authenticated, users might not be properly authorized to perform certain actions. The sole dangerous function detected, `preg_replace(/e)`, while not directly exploitable in this context without further data, is a known function that historically has led to vulnerabilities if not handled with extreme care.

The vulnerability history is currently clean, with no recorded CVEs. This is a positive indicator, suggesting that either the plugin has been developed with security in mind or has not yet been subjected to extensive public scrutiny. However, the lack of past vulnerabilities should not be a reason for complacency, especially given the identified weaknesses in the static analysis. The combination of an unprotected AJAX endpoint and a lack of authorization checks presents a tangible risk that could be exploited by an attacker.

Key Concerns

  • Unprotected AJAX handler
  • No nonce checks
  • No capability checks
  • Dangerous function: preg_replace(/e)
Vulnerabilities
None known

Divein Builder Security Vulnerabilities

No known vulnerabilities — this is a good sign.
Code Analysis
Analyzed Mar 17, 2026

Divein Builder Code Analysis

Dangerous Functions
1
Raw SQL Queries
0
0 prepared
Unescaped Output
2
14 escaped
Nonce Checks
0
Capability Checks
0
File Operations
0
External Requests
0
Bundled Libraries
0

Dangerous Functions Found

preg_replace(/e)preg_replace( '/\d+/e'includes\shortcodes.php:72

Output Escaping

88% escaped16 total outputs
Attack Surface
1 unprotected

Divein Builder Attack Surface

Entry Points36
Unprotected1

AJAX Handlers 1

authwp_ajax_divein_builder_get_post_typesincludes\shortcodes.php:1248

Shortcodes 35

[divein_container] includes\shortcodes.php:107
[divein_container_inner] includes\shortcodes.php:108
[divein_container_inner_inner] includes\shortcodes.php:109
[divein_container_inner_inner_inner] includes\shortcodes.php:110
[divein_column] includes\shortcodes.php:158
[divein_column_inner] includes\shortcodes.php:159
[divein_column_inner_inner] includes\shortcodes.php:160
[divein_column_inner_inner_inner] includes\shortcodes.php:161
[divein_paragraph] includes\shortcodes.php:186
[divein_heading] includes\shortcodes.php:213
[divein_editor] includes\shortcodes.php:233
[divein_image] includes\shortcodes.php:266
[divein_button] includes\shortcodes.php:300
[divein_separator] includes\shortcodes.php:345
[divein_list] includes\shortcodes.php:395
[divein_list_inner] includes\shortcodes.php:396
[divein_list_inner_inner] includes\shortcodes.php:397
[divein_list_inner_inner_inner] includes\shortcodes.php:398
[divein_gallery] includes\shortcodes.php:435
[divein_slider] includes\shortcodes.php:488
[divein_carousel] includes\shortcodes.php:553
[divein_nested_builder] includes\shortcodes.php:568
[divein_nested_builder_inner] includes\shortcodes.php:569
[divein_nested_builder_inner_inner] includes\shortcodes.php:570
[divein_nested_builder_inner_inner_inner] includes\shortcodes.php:571
[divein_tabs] includes\shortcodes.php:652
[divein_accordion] includes\shortcodes.php:711
[divein_toggle] includes\shortcodes.php:743
[divein_closeable] includes\shortcodes.php:775
[divein_popup] includes\shortcodes.php:837
[divein_post_loop] includes\shortcodes.php:956
[item] includes\shortcodes.php:976
[item_inner] includes\shortcodes.php:977
[item_inner_inner] includes\shortcodes.php:978
[item_inner_inner_inner] includes\shortcodes.php:979
WordPress Hooks 4
actionadd_meta_boxesdivein-builder.php:45
actionadmin_enqueue_scriptsdivein-builder.php:76
actionwp_enqueue_scriptsdivein-builder.php:99
actionwp_footerincludes\shortcodes.php:994
Maintenance & Trust

Divein Builder Maintenance & Trust

Maintenance Signals

WordPress version tested4.9.29
Last updatedDec 30, 2017
PHP min version5.4
Downloads1K

Community Trust

Rating0/100
Number of ratings0
Active installs0
Developer Profile

Divein Builder Developer Profile

diveinwp

1 plugin · 0 total installs

84
trust score
Avg Security Score
85/100
Avg Patch Time
30 days
View full developer profile
Detection Fingerprints

How We Detect Divein Builder

Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.

Asset Fingerprints

Asset Paths
/wp-content/plugins/divein-builder/assets/lib/icons/embedded.css/wp-content/plugins/divein-builder/admin/builder.css/wp-content/plugins/divein-builder/admin/builder-app.js/wp-content/plugins/divein-builder/admin/backend-builder.js/wp-content/plugins/divein-builder/assets/lib/wp-color-picker/wp-color-picker-alpha.min.js/wp-content/plugins/divein-builder/assets/lib/owl/assets/owl.carousel.min.css/wp-content/plugins/divein-builder/assets/lib/owl/owl.carousel.min.js/wp-content/plugins/divein-builder/assets/lib/camera/camera.css+4 more
Script Paths
/wp-content/plugins/divein-builder/admin/builder-app.js/wp-content/plugins/divein-builder/admin/backend-builder.js/wp-content/plugins/divein-builder/assets/lib/wp-color-picker/wp-color-picker-alpha.min.js/wp-content/plugins/divein-builder/assets/lib/owl/owl.carousel.min.js/wp-content/plugins/divein-builder/assets/lib/camera/jquery.easing.1.3.min.js/wp-content/plugins/divein-builder/assets/lib/camera/camera.js+1 more

HTML / DOM Fingerprints

CSS Classes
divein-page-builder-rootdi-pb-editor-buttonsdi-pb-loadingdi-pb-popupsdi-pb-editordivein-standard-sectiondivein-container-fluiddivein-container+1 more
Data Attributes
data-divein-builder-item-id
JS Globals
DiveinBuilder
Shortcode Output
<div class="divein-page-builder-root"><div class="di-pb-editor-buttons"><span>Divein Builder</span><span>Visual</span><span>Text</span></div><div class="di-pb-loading"><div class="di-pb-popups"></div>
FAQ

Frequently Asked Questions about Divein Builder