Surbma | Divi Extras Security & Risk Analysis

wordpress.org/plugins/surbma-divi-extras

Useful modifications for the Divi Theme.

1K active installs v5.1 PHP 7.0+ WP 5.2+ Updated Apr 8, 2023
dividivi-themeelegant-themeselegantthemespage-builder
85
A · Safe
CVEs total0
Unpatched0
Last CVENever
Safety Verdict

Is Surbma | Divi Extras Safe to Use in 2026?

Generally Safe

Score 85/100

Surbma | Divi Extras has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.

No known CVEs Updated 2yr ago
Risk Assessment

The static analysis of surbma-divi-extras v5.1 reveals an exceptionally clean codebase with no detected attack surface, dangerous functions, file operations, or external HTTP requests. All SQL queries are properly prepared, and all output is correctly escaped, indicating strong adherence to secure coding practices. The absence of any recorded vulnerabilities or CVEs in its history further strengthens this positive security posture, suggesting a well-maintained and thoroughly vetted plugin.

While the current version appears highly secure, the complete lack of any capability checks or nonce checks across its zero entry points is a notable observation. This could imply that the plugin is designed to be purely decorative or rely entirely on its parent theme (Divi) for any necessary authorization, which is generally a less robust security approach if there were any hidden entry points or future functionalities. However, based on the provided data, there are no immediate exploitable vulnerabilities. The plugin exhibits excellent immediate security but lacks explicit built-in authorization mechanisms, which might be a concern for future development or unforeseen interactions.

In conclusion, surbma-divi-extras v5.1 presents an excellent security profile based on the provided static analysis and vulnerability history. Its strengths lie in its zero attack surface, safe handling of data, and lack of historical vulnerabilities. The sole area for potential consideration, though not a direct vulnerability based on this data, is the absence of explicit capability and nonce checks, which could be a point of improvement for future robustness.

Key Concerns

  • No nonce checks found
  • No capability checks found
Vulnerabilities
None known

Surbma | Divi Extras Security Vulnerabilities

No known vulnerabilities — this is a good sign.
Code Analysis
Analyzed Mar 16, 2026

Surbma | Divi Extras Code Analysis

Dangerous Functions
0
Raw SQL Queries
0
0 prepared
Unescaped Output
0
6 escaped
Nonce Checks
0
Capability Checks
0
File Operations
0
External Requests
0
Bundled Libraries
0

Output Escaping

100% escaped6 total outputs
Attack Surface

Surbma | Divi Extras Attack Surface

Entry Points0
Unprotected0
WordPress Hooks 4
actionplugins_loadedsurbma-divi-extras.php:26
actionwp_enqueue_scriptssurbma-divi-extras.php:48
filtercomment_form_defaultssurbma-divi-extras.php:55
filteret_html_logo_containersurbma-divi-extras.php:64
Maintenance & Trust

Surbma | Divi Extras Maintenance & Trust

Maintenance Signals

WordPress version tested6.2.9
Last updatedApr 8, 2023
PHP min version7.0
Downloads49K

Community Trust

Rating80/100
Number of ratings4
Active installs1K
Developer Profile

Surbma | Divi Extras Developer Profile

Surbma

27 plugins · 30K total installs

71
trust score
Avg Security Score
88/100
Avg Patch Time
127 days
View full developer profile
Detection Fingerprints

How We Detect Surbma | Divi Extras

Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.

Asset Fingerprints

Asset Paths
/wp-content/plugins/surbma-divi-extras/css/surbma-divi-extras.css
Version Parameters
surbma-divi-extras/css/surbma-divi-extras.css?ver=3.2.2

HTML / DOM Fingerprints

CSS Classes
logo_containerlogo_helper
FAQ

Frequently Asked Questions about Surbma | Divi Extras