
Merge + Minify + Refresh Check DIVI Security & Risk Analysis
wordpress.org/plugins/mmr-disable-for-diviDisable MMR when editing a page using the DIVI editor.
Is Merge + Minify + Refresh Check DIVI Safe to Use in 2026?
Generally Safe
Score 100/100Merge + Minify + Refresh Check DIVI has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.
The "mmr-disable-for-divi" plugin v1.1.1 demonstrates a strong security posture based on the provided static analysis. The absence of any identified entry points like AJAX handlers, REST API routes, or shortcodes significantly limits the potential attack surface. Furthermore, the code exhibits excellent security practices, with no dangerous functions detected, all SQL queries using prepared statements, and all output being properly escaped. The lack of file operations and external HTTP requests further contributes to its security. The plugin also has no recorded vulnerability history, indicating a clean track record.
While the static analysis reveals no critical or high-severity issues, the complete absence of nonce and capability checks across all identified (though zero) entry points is a notable concern. This suggests that even if future entry points were to be introduced, they might be implemented without these fundamental security measures. The vulnerability history being entirely clean is a positive sign, but it's crucial to remember that past security is not a guarantee of future security, especially given the noted potential for missing checks. Overall, the plugin is currently very secure due to its minimal attack surface and clean code, but the lack of explicit authentication and authorization checks in its design represents a theoretical weakness that could become a problem if the plugin's functionality expands without addressing this gap.
Key Concerns
- Missing nonce checks on potential entry points
- Missing capability checks on potential entry points
Merge + Minify + Refresh Check DIVI Security Vulnerabilities
Merge + Minify + Refresh Check DIVI Code Analysis
Merge + Minify + Refresh Check DIVI Attack Surface
WordPress Hooks 1
Maintenance & Trust
Merge + Minify + Refresh Check DIVI Maintenance & Trust
Maintenance Signals
Community Trust
Merge + Minify + Refresh Check DIVI Alternatives
Merge + Minify + Refresh
merge-minify-refresh
Merges/Concatenates CSS & Javascript and then minifies using Minify (for CSS) and Google Closure (for JS with Minify as a fallback).
Merge + Minify + Refresh Check Visual Composer
mmr-disable-for-visual-composer-editor
Disable MMR when editing a page using the Visual Composer editor.
Merge + Minify + Refresh Clear Caches
merge-minify-refresh-clear-caches
This plugin clears other page caches/proxies when the Merge + Minify + Refresh cache is regenerated.
MinQueue
minqueue
Minify & Concatenate Enqueued Scripts & Styles.
APH Merge Scripts
aph-merge-scripts
Merge and minify CSS & javascript files into one file. Easy to use. Support remote file - Javascript & CSS files hosted on other server or CDN
Merge + Minify + Refresh Check DIVI Developer Profile
4 plugins · 5K total installs
How We Detect Merge + Minify + Refresh Check DIVI
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.