Divi Socials Security & Risk Analysis

wordpress.org/plugins/divi-socials

Divi Socials adds more social icons with different styles and colors to your Divi header.

70 active installs v1.1 PHP + WP 3.0.1+ Updated Sep 4, 2019
diviiconssocial-media
85
A · Safe
CVEs total0
Unpatched0
Last CVENever
Download
Safety Verdict

Is Divi Socials Safe to Use in 2026?

Generally Safe

Score 85/100

Divi Socials has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.

No known CVEs Updated 6yr ago
Risk Assessment

Based on the static analysis, the "divi-socials" v1.1 plugin exhibits a seemingly strong security posture. There are no identified entry points like AJAX handlers, REST API routes, or shortcodes, which significantly reduces the potential attack surface. The code also adheres to good practices by using prepared statements for all SQL queries and avoiding dangerous functions, file operations, and external HTTP requests. Furthermore, there's no record of past vulnerabilities, suggesting a history of secure development.

However, the analysis does reveal some areas of concern. A significant portion of the output (33%) is not properly escaped, which could potentially lead to cross-site scripting (XSS) vulnerabilities if user-supplied data is included in these outputs. The complete absence of nonce and capability checks across all code, combined with zero identified flows in taint analysis (which might indicate an inability to effectively analyze or a very small codebase), raises questions about the plugin's ability to properly authenticate and authorize actions, especially if new entry points were introduced or if the analysis was limited. While the current attack surface appears to be zero, the lack of robust authorization checks is a potential weakness that could be exploited if any unintended entry points are discovered.

In conclusion, while "divi-socials" v1.1 scores well on many fronts, particularly in preventing common SQL injection and code execution vulnerabilities, the unescaped output and the complete lack of authorization checks present tangible risks. The absence of historical vulnerabilities is a positive indicator, but it does not negate the risks identified in the current code analysis. Further investigation into the output escaping and the implementation of authorization mechanisms is recommended to solidify its security.

Key Concerns

  • Unescaped output found
  • No nonce checks found
  • No capability checks found
Vulnerabilities
None known

Divi Socials Security Vulnerabilities

No known vulnerabilities — this is a good sign.
Code Analysis
Analyzed Mar 16, 2026

Divi Socials Code Analysis

Dangerous Functions
0
Raw SQL Queries
0
0 prepared
Unescaped Output
4
8 escaped
Nonce Checks
0
Capability Checks
0
File Operations
0
External Requests
0
Bundled Libraries
0

Output Escaping

67% escaped12 total outputs
Attack Surface

Divi Socials Attack Surface

Entry Points0
Unprotected0
WordPress Hooks 8
actionadmin_noticesdivi-socials.php:59
actionplugins_loadedincludes\class-divi-socials.php:140
actionadmin_enqueue_scriptsincludes\class-divi-socials.php:154
actionadmin_enqueue_scriptsincludes\class-divi-socials.php:155
actionadmin_menuincludes\class-divi-socials.php:156
actionadmin_initincludes\class-divi-socials.php:157
actionwp_enqueue_scriptsincludes\class-divi-socials.php:172
actionget_template_part_includes/social_iconsincludes\class-divi-socials.php:173
Maintenance & Trust

Divi Socials Maintenance & Trust

Maintenance Signals

WordPress version tested5.2.24
Last updatedSep 4, 2019
PHP min version
Downloads5K

Community Trust

Rating80/100
Number of ratings4
Active installs70
Developer Profile

Divi Socials Developer Profile

David Towoju

4 plugins · 470 total installs

91
trust score
Avg Security Score
96/100
Avg Patch Time
30 days
View full developer profile
Detection Fingerprints

How We Detect Divi Socials

Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.

Asset Fingerprints

Asset Paths
/wp-content/plugins/divi-socials/css/divi-socials-admin.css/wp-content/plugins/divi-socials/js/divi-socials-admin.js
Script Paths
/wp-content/plugins/divi-socials/js/divi-socials-admin.js
Version Parameters
divi-socials-admin?ver=divi-socials-admin.js?ver=

HTML / DOM Fingerprints

CSS Classes
divi-socials-admin
FAQ

Frequently Asked Questions about Divi Socials