
Expand Divi Security & Risk Analysis
wordpress.org/plugins/expand-diviAdds more functionlity to the Divi theme.
Is Expand Divi Safe to Use in 2026?
Generally Safe
Score 85/100Expand Divi has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.
The "expand-divi" v1.6.0 plugin exhibits a generally good security posture with several positive indicators. The absence of any recorded vulnerabilities, including critical or high severity ones, and the lack of known CVEs are significant strengths. The code analysis shows a commendable approach to SQL queries, with 100% using prepared statements, and a high percentage of output escaping (83%). There are no external HTTP requests or file operations, which further reduces the attack surface.
However, there are a few areas for concern. The presence of a "Dangerous function" (preg_replace(/e)) without further context on its usage is a potential risk, as this function can be exploited for code execution if not handled carefully. The lack of nonce checks and the limited capability checks (only 2) suggest that certain entry points, particularly the 3 shortcodes, might not be adequately protected against unauthorized access or misuse. While the total attack surface is low and has no unprotected entry points according to the analysis, the presence of these potentially weaker security controls warrants attention.
In conclusion, while "expand-divi" v1.6.0 has a strong track record and good practices in many areas, the identified "Dangerous function" and the limited nonce/capability checks on its shortcodes represent potential weaknesses that could be exploited. Addressing these specific points would further enhance the plugin's security.
Key Concerns
- Dangerous function usage detected (preg_replace(/e))
- No nonce checks implemented
- Limited capability checks (2)
- Output escaping only 83% proper
Expand Divi Security Vulnerabilities
Expand Divi Code Analysis
Dangerous Functions Found
Output Escaping
Expand Divi Attack Surface
Shortcodes 3
WordPress Hooks 24
Maintenance & Trust
Expand Divi Maintenance & Trust
Maintenance Signals
Community Trust
Expand Divi Alternatives
One Click Demo Import
one-click-demo-import
Import your demo content, widgets and theme settings with one click. Theme authors! Enable simple theme demo import for your users.
Advanced Random Posts Widget
advanced-random-posts-widget
Provides flexible and advanced random posts. Display it via shortcode or widget with thumbnails, post excerpt, and much more!
Essential Widgets
essential-widgets
Essential Widgets is a WordPress plugin for widgets that allows you to create and add amazing widgets with high customization option
RaraTheme Companion
raratheme-companion
23 extremely useful custom widgets to create an engaging website.
Flexible Posts Widget
flexible-posts-widget
An advanced posts display widget with many options. Display posts in your sidebars any way you'd like!
Expand Divi Developer Profile
1 plugin · 1K total installs
How We Detect Expand Divi
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/expand-divi/assets/styles/admin-styles.css/wp-content/plugins/expand-divi/assets/scripts/admin-scripts.js/wp-content/plugins/expand-divi/assets/scripts/frontend-scripts.js/wp-content/plugins/expand-divi/assets/scripts/admin-scripts.js/wp-content/plugins/expand-divi/assets/scripts/frontend-scripts.jsexpand-divi/assets/styles/admin-styles.css?ver=expand-divi/assets/scripts/admin-scripts.js?ver=expand-divi/assets/scripts/frontend-scripts.js?ver=HTML / DOM Fingerprints
expand-divi-preloaderexpand-divi-single-post-tagsexpand-divi-share-iconsexpand-divi-author-boxexpand-divi-single-post-paginationexpand-divi-related-postsexpand-divi-archive-blog-stylesexpand-divi-remove-sidebar+3 moredata-expand-divi-preloader-styledata-expand-divi-preloader-colorExpandDiviFrontendExpandDiviAdmin[expand_divi_share][expand_divi_follow][expand_divi_library]