Falang for Divi Lite Security & Risk Analysis

wordpress.org/plugins/falang-for-divi-lite

The Falang for Divi plugin makes your Divi page translation simpler.

100 active installs v1.23 PHP 5.6+ WP 4.7+ Updated Sep 12, 2025
divifalangmultilanguagemultilingualtranslation
100
A · Safe
CVEs total0
Unpatched0
Last CVENever
Download
Safety Verdict

Is Falang for Divi Lite Safe to Use in 2026?

Generally Safe

Score 100/100

Falang for Divi Lite has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.

No known CVEs Updated 6mo ago
Risk Assessment

The "falang-for-divi-lite" v1.23 plugin exhibits a generally strong security posture based on the provided static analysis. The absence of any known CVEs, combined with a complete lack of taint flows and a high percentage of properly escaped output, indicates diligent security practices. Furthermore, the reliance on prepared statements for all SQL queries is a significant strength, mitigating common SQL injection risks. The plugin also demonstrates good practice by incorporating capability checks, suggesting an awareness of access control.

However, there are a few areas that warrant attention. The presence of two instances of the dangerous `preg_replace` with the `/e` modifier, while not directly flagged by taint analysis in this instance, represents a potential risk for remote code execution if user-supplied input were ever to be processed by these functions without proper sanitization. The single file operation, though not inherently insecure, is an entry point that would benefit from closer scrutiny to ensure it's handled securely. The complete absence of nonce checks, particularly if any AJAX handlers or REST API routes were to be introduced in the future, could present a Cross-Site Request Forgery (CSRF) vulnerability.

In conclusion, the plugin is well-secured with no immediate critical vulnerabilities apparent from the data. The developer appears to follow good security hygiene. The primary areas for improvement are to either remove or secure the usage of `preg_replace(/e)` and to consider implementing nonce checks as a proactive measure against potential CSRF attacks, especially if the plugin's functionality is expanded.

Key Concerns

  • Dangerous functions: preg_replace(/e)
  • Nonce checks: 0
Vulnerabilities
None known

Falang for Divi Lite Security Vulnerabilities

No known vulnerabilities — this is a good sign.
Code Analysis
Analyzed Mar 16, 2026

Falang for Divi Lite Code Analysis

Dangerous Functions
2
Raw SQL Queries
0
0 prepared
Unescaped Output
4
15 escaped
Nonce Checks
0
Capability Checks
6
File Operations
1
External Requests
0
Bundled Libraries
0

Dangerous Functions Found

preg_replace(/e)preg_replace( '@\[et_pb_post_nav[^\]]*?\].*?\[\/efalang-for-divi-lite.php:477
preg_replace(/e)preg_replace( '@\[embed[^\]]*?\].*?\[\/efalang-for-divi-lite.php:484

Output Escaping

79% escaped19 total outputs
Attack Surface

Falang for Divi Lite Attack Surface

Entry Points0
Unprotected0
WordPress Hooks 12
actionadmin_noticesadmin\admin-notices.php:38
actionadmin_noticesfalang-for-divi-lite.php:45
actionplugins_loadedfalang-for-divi-lite.php:53
actioninitfalang-for-divi-lite.php:55
actionwp_headfalang-for-divi-lite.php:57
filteret_builder_main_tabsfalang-for-divi-lite.php:93
filterfalang_is_supported_builderfalang-for-divi-lite.php:96
filteret_pb_module_shortcode_attributesfalang-for-divi-lite.php:126
filteret_pb_module_contentfalang-for-divi-lite.php:127
filteret_truncate_postfalang-for-divi-lite.php:130
filterfalang_divi_override_contentfalang-for-divi-lite.php:137
filteret_pb_module_global_attsfalang-for-divi-lite.php:143
Maintenance & Trust

Falang for Divi Lite Maintenance & Trust

Maintenance Signals

WordPress version tested6.8.5
Last updatedSep 12, 2025
PHP min version5.6
Downloads6K

Community Trust

Rating100/100
Number of ratings11
Active installs100
Developer Profile

Falang for Divi Lite Developer Profile

sbouey

6 plugins · 2K total installs

77
trust score
Avg Security Score
97/100
Avg Patch Time
131 days
View full developer profile
Detection Fingerprints

How We Detect Falang for Divi Lite

Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.

Asset Fingerprints

Asset Paths
/wp-content/plugins/falang-for-divi-lite/admin/css/falang-divi-admin.css/wp-content/plugins/falang-for-divi-lite/admin/js/falang-divi-admin.js/wp-content/plugins/falang-for-divi-lite/frontend/css/falang-divi-frontend.css
Script Paths
/wp-content/plugins/falang-for-divi-lite/admin/js/falang-divi-admin.js/wp-content/plugins/falang-for-divi-lite/frontend/js/falang-divi-frontend.js
Version Parameters
falang-for-divi-lite/admin/css/falang-divi-admin.css?ver=falang-for-divi-lite/admin/js/falang-divi-admin.js?ver=falang-for-divi-lite/frontend/css/falang-divi-frontend.css?ver=falang-for-divi-lite/frontend/js/falang-divi-frontend.js?ver=

HTML / DOM Fingerprints

CSS Classes
falang-divi-admin-noticefalang-divi-pro-upgrade-notice
HTML Comments
<!-- Falang Divi Lite Message -->
Data Attributes
data-falang-divi-module-namedata-falang-divi-module-field
JS Globals
falang_divi_admin_params
FAQ

Frequently Asked Questions about Falang for Divi Lite