
Divi Socials Security & Risk Analysis
wordpress.org/plugins/divi-socialsDivi Socials adds more social icons with different styles and colors to your Divi header.
Is Divi Socials Safe to Use in 2026?
Generally Safe
Score 85/100Divi Socials has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.
Based on the static analysis, the "divi-socials" v1.1 plugin exhibits a seemingly strong security posture. There are no identified entry points like AJAX handlers, REST API routes, or shortcodes, which significantly reduces the potential attack surface. The code also adheres to good practices by using prepared statements for all SQL queries and avoiding dangerous functions, file operations, and external HTTP requests. Furthermore, there's no record of past vulnerabilities, suggesting a history of secure development.
However, the analysis does reveal some areas of concern. A significant portion of the output (33%) is not properly escaped, which could potentially lead to cross-site scripting (XSS) vulnerabilities if user-supplied data is included in these outputs. The complete absence of nonce and capability checks across all code, combined with zero identified flows in taint analysis (which might indicate an inability to effectively analyze or a very small codebase), raises questions about the plugin's ability to properly authenticate and authorize actions, especially if new entry points were introduced or if the analysis was limited. While the current attack surface appears to be zero, the lack of robust authorization checks is a potential weakness that could be exploited if any unintended entry points are discovered.
In conclusion, while "divi-socials" v1.1 scores well on many fronts, particularly in preventing common SQL injection and code execution vulnerabilities, the unescaped output and the complete lack of authorization checks present tangible risks. The absence of historical vulnerabilities is a positive indicator, but it does not negate the risks identified in the current code analysis. Further investigation into the output escaping and the implementation of authorization mechanisms is recommended to solidify its security.
Key Concerns
- Unescaped output found
- No nonce checks found
- No capability checks found
Divi Socials Security Vulnerabilities
Divi Socials Code Analysis
Output Escaping
Divi Socials Attack Surface
WordPress Hooks 8
Maintenance & Trust
Divi Socials Maintenance & Trust
Maintenance Signals
Community Trust
Divi Socials Alternatives
Social Divi
social-divi
This plugin adds the ability to add more social icons to your website when using the Divi theme.
AddToAny Share Buttons
add-to-any
Share buttons for WordPress including the AddToAny button, Facebook, Bluesky, Mastodon, WhatsApp, Pinterest, Reddit, many more, and follow icons too.
Social Icons Widget & Block – Social Media Icons & Share Buttons
social-icons-widget-by-wpzoom
Social media icons plugin for WordPress - Add 400+ social icons and share buttons. Gutenberg block, widget & Elementor support. GDPR compliant.
Social Media Share Buttons & Social Sharing Icons
ultimate-social-media-icons
Share buttons and pop up share icons for social media sharing
Lightweight Social Icons
lightweight-social-icons
Looking to add simple social icons to your widget areas? Choose the size and color of your icons, and then choose from 47 different social profiles.
Divi Socials Developer Profile
4 plugins · 470 total installs
How We Detect Divi Socials
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/divi-socials/css/divi-socials-admin.css/wp-content/plugins/divi-socials/js/divi-socials-admin.js/wp-content/plugins/divi-socials/js/divi-socials-admin.jsdivi-socials-admin?ver=divi-socials-admin.js?ver=HTML / DOM Fingerprints
divi-socials-admin