
DMS Shortcode Module For Divi Security & Risk Analysis
wordpress.org/plugins/dms-shortcode-module-for-diviConsente di inserire sezioni, moduli o layout della libreria DIVI, all'interno di un'altro contenuto o pagina creata con DIVI o DIVI Builder …
Is DMS Shortcode Module For Divi Safe to Use in 2026?
Generally Safe
Score 85/100DMS Shortcode Module For Divi has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.
The plugin "dms-shortcode-module-for-divi" v2.5 exhibits a mixed security posture. On the positive side, it has a very limited attack surface with only one entry point identified as a shortcode. The absence of known CVEs, along with the fact that all SQL queries are prepared, suggests a level of care in development and a lack of historically exploitable vulnerabilities. This indicates a generally good practice in certain areas of security.
However, the static analysis reveals significant concerns. The most prominent issue is the complete lack of output escaping across all identified outputs, which presents a substantial risk for Cross-Site Scripting (XSS) vulnerabilities. Furthermore, the absence of any capability checks or nonce checks on its entry points means that any user, regardless of their role or permissions, could potentially trigger the shortcode's functionality. This lack of authorization checks amplifies the risk posed by unescaped output. The fact that taint analysis shows zero flows is less reassuring given the other significant vulnerabilities found, suggesting that the analysis might not have been comprehensive enough or that the identified entry point did not allow for complex taint scenarios.
In conclusion, while the plugin benefits from a small attack surface and a clean vulnerability history, the critical issues of unescaped output and missing authorization controls make it a risky component. The lack of these fundamental security measures outweighs the positive aspects, requiring immediate attention to mitigate potential XSS and unauthorized access risks.
Key Concerns
- All outputs unescaped
- Shortcode has no capability checks
- Shortcode has no nonce checks
DMS Shortcode Module For Divi Security Vulnerabilities
DMS Shortcode Module For Divi Release Timeline
DMS Shortcode Module For Divi Code Analysis
Output Escaping
DMS Shortcode Module For Divi Attack Surface
Shortcodes 1
WordPress Hooks 2
Maintenance & Trust
DMS Shortcode Module For Divi Maintenance & Trust
Maintenance Signals
Community Trust
DMS Shortcode Module For Divi Alternatives
Simple Divi Shortcode
simple-divi-shortcode
Insert DIVI Library item inside module content or inside a php template by using a shortcode.
Dynamic Video for Divi Posts
dynamic-video-for-divi-posts
Short Description: Embeds videos into posts via a custom field and [dynamic_video] shortcode for Divi, with optional featured image fallback.
Supreme Modules Lite – Divi Theme, Extra Theme and Divi Builder
supreme-modules-for-divi
Divi Supreme lite plugin enhances the experience and features found on Divi and extend with custom creative modules to help you build amazing websites …
Column Shortcodes
column-shortcodes
Adds shortcodes to easily create columns in your posts or pages.
Divi Torque Lite – Divi Theme, Divi Builder & Extra Theme
addons-for-divi
The Divi Torque plugin you install after Divi builder! Packed with 70+ stunning modules like Post Grid, Filterable Gallery, Google Reviews, and more.
DMS Shortcode Module For Divi Developer Profile
1 plugin · 60 total installs
How We Detect DMS Shortcode Module For Divi
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
HTML / DOM Fingerprints
<!--DMS Exit if direct access--><!--DMS Funzione per mostrare il modulo--><!--DMS Aggiornamento del 18/11/2919 - aggiunge la possibilità di vedere ID del modulo direttamente da pannello Libreria Divi --><!--DMS Crea Colonna in libreria Divi-->+2 more[dmsdivimodule id=