
Simple Divi Shortcode Security & Risk Analysis
wordpress.org/plugins/simple-divi-shortcodeInsert DIVI Library item inside module content or inside a php template by using a shortcode.
Is Simple Divi Shortcode Safe to Use in 2026?
Generally Safe
Score 100/100Simple Divi Shortcode has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.
The "simple-divi-shortcode" v1.2 plugin exhibits a mixed security posture. On the positive side, the plugin demonstrates good practices by exclusively using prepared statements for its SQL queries and having no recorded vulnerabilities (CVEs) or known issues. It also presents a very small attack surface with no AJAX handlers or REST API routes, and importantly, no direct entry points are left unprotected. The absence of file operations, external HTTP requests, and bundled libraries further reduces potential risks.
However, significant concerns arise from the output escaping. With three total outputs and 0% properly escaped, there is a high likelihood of cross-site scripting (XSS) vulnerabilities. The lack of nonce checks and capability checks, especially in the context of shortcodes (which can be triggered by any logged-in user), means that attackers could potentially inject malicious scripts that execute within the context of other users' sessions. The taint analysis showing no flows is not necessarily a strength, as it could indicate a lack of comprehensive taint analysis or a very simple code structure where such flows are unlikely to be detected by the tool.
In conclusion, while the plugin avoids common pitfalls like raw SQL and unpatched CVEs, the complete lack of output escaping on all its output points is a critical weakness that exposes users to XSS attacks. The absence of authentication and authorization checks on its single shortcode entry point amplifies this risk. The plugin's small attack surface is a mitigating factor, but the severity of the output escaping issue cannot be overstated.
Key Concerns
- Unescaped output on all outputs
- Missing nonce checks on entry points
- Missing capability checks on entry points
Simple Divi Shortcode Security Vulnerabilities
Simple Divi Shortcode Code Analysis
Output Escaping
Simple Divi Shortcode Attack Surface
Shortcodes 1
WordPress Hooks 6
Maintenance & Trust
Simple Divi Shortcode Maintenance & Trust
Maintenance Signals
Community Trust
Simple Divi Shortcode Alternatives
Surbma | Divi Project Shortcodes
surbma-divi-project-shortcodes
Shortcodes to display Divi's Project elements, like category and tag list.
Projects Custom Post Type by mbaierl
mbaierl-projects-cpt
The Divi "Projects" Custom Post Type - in case you move away from Divi but still want to use the Projects.
Column Shortcodes
column-shortcodes
Adds shortcodes to easily create columns in your posts or pages.
Surbma | Divi Extras
surbma-divi-extras
Useful modifications for the Divi Theme.
Eventin Addon for Divi Builder
eventin-divi-addon
Eventin - Divi Builder Addons for Event Management, Event Calendar and so on...
Simple Divi Shortcode Developer Profile
1 plugin · 10K total installs
How We Detect Simple Divi Shortcode
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
HTML / DOM Fingerprints
show-shortcodejQuery[showmodule id="