DMS Shortcode Module For Divi Security & Risk Analysis

wordpress.org/plugins/dms-shortcode-module-for-divi

Consente di inserire sezioni, moduli o layout della libreria DIVI, all'interno di un'altro contenuto o pagina creata con DIVI o DIVI Builder …

60 active installs v2.5 PHP 5.6+ WP 4.0+ Updated Oct 26, 2022
diviembedmenumoduleshortcode
85
A · Safe
CVEs total0
Unpatched0
Last CVENever
Safety Verdict

Is DMS Shortcode Module For Divi Safe to Use in 2026?

Generally Safe

Score 85/100

DMS Shortcode Module For Divi has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.

No known CVEs Updated 3yr ago
Risk Assessment

The plugin "dms-shortcode-module-for-divi" v2.5 exhibits a mixed security posture. On the positive side, it has a very limited attack surface with only one entry point identified as a shortcode. The absence of known CVEs, along with the fact that all SQL queries are prepared, suggests a level of care in development and a lack of historically exploitable vulnerabilities. This indicates a generally good practice in certain areas of security.

However, the static analysis reveals significant concerns. The most prominent issue is the complete lack of output escaping across all identified outputs, which presents a substantial risk for Cross-Site Scripting (XSS) vulnerabilities. Furthermore, the absence of any capability checks or nonce checks on its entry points means that any user, regardless of their role or permissions, could potentially trigger the shortcode's functionality. This lack of authorization checks amplifies the risk posed by unescaped output. The fact that taint analysis shows zero flows is less reassuring given the other significant vulnerabilities found, suggesting that the analysis might not have been comprehensive enough or that the identified entry point did not allow for complex taint scenarios.

In conclusion, while the plugin benefits from a small attack surface and a clean vulnerability history, the critical issues of unescaped output and missing authorization controls make it a risky component. The lack of these fundamental security measures outweighs the positive aspects, requiring immediate attention to mitigate potential XSS and unauthorized access risks.

Key Concerns

  • All outputs unescaped
  • Shortcode has no capability checks
  • Shortcode has no nonce checks
Vulnerabilities
None known

DMS Shortcode Module For Divi Security Vulnerabilities

No known vulnerabilities — this is a good sign.
Version History

DMS Shortcode Module For Divi Release Timeline

No version history available.
Code Analysis
Analyzed Mar 16, 2026

DMS Shortcode Module For Divi Code Analysis

Dangerous Functions
0
Raw SQL Queries
0
0 prepared
Unescaped Output
1
0 escaped
Nonce Checks
0
Capability Checks
0
File Operations
0
External Requests
0
Bundled Libraries
0

Output Escaping

0% escaped1 total outputs
Attack Surface

DMS Shortcode Module For Divi Attack Surface

Entry Points1
Unprotected0

Shortcodes 1

[dmsdivimodule] dms-shortcode-module-fordivi.php:24
WordPress Hooks 2
filtermanage_et_pb_layout_posts_columnsdms-shortcode-module-fordivi.php:28
actionmanage_et_pb_layout_posts_custom_columndms-shortcode-module-fordivi.php:29
Maintenance & Trust

DMS Shortcode Module For Divi Maintenance & Trust

Maintenance Signals

WordPress version tested6.0.11
Last updatedOct 26, 2022
PHP min version5.6
Downloads2K

Community Trust

Rating100/100
Number of ratings2
Active installs60
Developer Profile

DMS Shortcode Module For Divi Developer Profile

Rosetta Facciolini

1 plugin · 60 total installs

84
trust score
Avg Security Score
85/100
Avg Patch Time
30 days
View full developer profile
Detection Fingerprints

How We Detect DMS Shortcode Module For Divi

Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.

Asset Fingerprints

HTML / DOM Fingerprints

HTML Comments
<!--DMS Exit if direct access--><!--DMS Funzione per mostrare il modulo--><!--DMS Aggiornamento del 18/11/2919 - aggiunge la possibilità di vedere ID del modulo direttamente da pannello Libreria Divi --><!--DMS Crea Colonna in libreria Divi-->+2 more
Shortcode Output
[dmsdivimodule id=
FAQ

Frequently Asked Questions about DMS Shortcode Module For Divi