Social Divi Security & Risk Analysis

wordpress.org/plugins/social-divi

This plugin adds the ability to add more social icons to your website when using the Divi theme.

1K active installs v1.8.0 PHP 5.4+ WP 5.1+ Updated May 26, 2025
diviiconssocialsocial-media
100
A · Safe
CVEs total0
Unpatched0
Last CVENever
Safety Verdict

Is Social Divi Safe to Use in 2026?

Generally Safe

Score 100/100

Social Divi has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.

No known CVEs Updated 10mo ago
Risk Assessment

Based on the provided static analysis and vulnerability history, the "social-divi" v1.8.0 plugin exhibits a generally strong security posture. The absence of identified CVEs and the clean taint analysis results are particularly encouraging, suggesting a well-maintained codebase. The plugin also demonstrates good practices in its limited code signals, with all SQL queries utilizing prepared statements and a high percentage of output escaping. The presence of a capability check, even if only one, is also a positive indicator.

However, there are a few areas that warrant caution. The complete lack of identified entry points (AJAX handlers, REST API routes, shortcodes, cron events) is unusual and could indicate a limited functionality or, more concerningly, that the analysis might have missed potential entry points or that the plugin's functionality is heavily reliant on external integration or very specific conditions. The fact that no nonce checks were identified is a potential concern, especially if any functionality were to be introduced that handles user-submitted data, as this is a common vulnerability vector. The single capability check also suggests that granular permission control might be underdeveloped.

In conclusion, while the plugin's current state shows no immediate critical vulnerabilities and a commitment to secure coding practices in the areas analyzed, the limited attack surface and lack of explicit security checks like nonces could be points of concern depending on the plugin's actual intended functionality and how it interacts with user input or other systems. Further investigation into the plugin's full feature set and potential integration points would be advisable to ensure a comprehensive security assessment.

Key Concerns

  • No nonce checks found
  • Only one capability check found
  • No identified entry points is unusual
Vulnerabilities
None known

Social Divi Security Vulnerabilities

No known vulnerabilities — this is a good sign.
Code Analysis
Analyzed Mar 16, 2026

Social Divi Code Analysis

Dangerous Functions
0
Raw SQL Queries
0
0 prepared
Unescaped Output
1
11 escaped
Nonce Checks
0
Capability Checks
1
File Operations
0
External Requests
0
Bundled Libraries
0

Output Escaping

92% escaped12 total outputs
Attack Surface

Social Divi Attack Surface

Entry Points0
Unprotected0
WordPress Hooks 8
actionadmin_initsocial-divi.php:25
actionadmin_noticessocial-divi.php:34
actionget_template_part_includes/social_iconssrc\actions\add-icons-template.php:8
actionwp_enqueue_scriptssrc\actions\add-icons-template.php:17
filterplugin_row_metasrc\actions\add-links-to-plugin-meta.php:7
actionadmin_enqueue_scriptssrc\actions\add-links-to-plugin-meta.php:41
filteret_epanel_tab_namessrc\actions\update-theme-options.php:7
filteret_epanel_layout_datasrc\actions\update-theme-options.php:20
Maintenance & Trust

Social Divi Maintenance & Trust

Maintenance Signals

WordPress version tested6.8.5
Last updatedMay 26, 2025
PHP min version5.4
Downloads21K

Community Trust

Rating100/100
Number of ratings4
Active installs1K
Developer Profile

Social Divi Developer Profile

Jelle Roorda

1 plugin · 1K total installs

94
trust score
Avg Security Score
100/100
Avg Patch Time
30 days
View full developer profile
Detection Fingerprints

How We Detect Social Divi

Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.

Asset Fingerprints

Asset Paths
/wp-content/plugins/social-divi/src/includes/social_divi_remove_et_icons.js/wp-content/plugins/social-divi/src/includes/social_divi_styles.css/wp-content/plugins/social-divi/src/includes/social_divi_scripts.js
Script Paths
/wp-content/plugins/social-divi/src/includes/social_divi_remove_et_icons.js/wp-content/plugins/social-divi/src/includes/social_divi_scripts.js
Version Parameters
social-divi/style.css?ver=social-divi-admin-stylesocial-divi-admin-script

HTML / DOM Fingerprints

CSS Classes
social-divi-star-rating
Data Attributes
data-rating
FAQ

Frequently Asked Questions about Social Divi