
Surbma | Divi Project Shortcodes Security & Risk Analysis
wordpress.org/plugins/surbma-divi-project-shortcodesShortcodes to display Divi's Project elements, like category and tag list.
Is Surbma | Divi Project Shortcodes Safe to Use in 2026?
Generally Safe
Score 85/100Surbma | Divi Project Shortcodes has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.
The "surbma-divi-project-shortcodes" plugin v2.1 exhibits a mixed security posture. On the positive side, the static analysis reveals a lack of dangerous functions, secure handling of all SQL queries with prepared statements, and no file operations or external HTTP requests, which are excellent security practices. Furthermore, the vulnerability history is clean, with no recorded CVEs, indicating a potentially stable and well-maintained codebase regarding known exploits. However, a significant concern arises from the output escaping. With 100% of outputs not being properly escaped, there is a high risk of cross-site scripting (XSS) vulnerabilities. Any data rendered by the shortcodes that is influenced by user input or external sources is susceptible to injection attacks. While the plugin has a limited attack surface of 4 shortcodes, the absence of proper output sanitization on all of them presents a substantial security weakness. The lack of nonce and capability checks across the identified entry points, though currently showing no unauthenticated access, is also a notable weakness that could be exploited if vulnerabilities were introduced in the future.
Key Concerns
- 100% of outputs not properly escaped
- 0 Nonce checks on entry points
- 0 Capability checks on entry points
Surbma | Divi Project Shortcodes Security Vulnerabilities
Surbma | Divi Project Shortcodes Code Analysis
Output Escaping
Surbma | Divi Project Shortcodes Attack Surface
Shortcodes 4
WordPress Hooks 1
Maintenance & Trust
Surbma | Divi Project Shortcodes Maintenance & Trust
Maintenance Signals
Community Trust
Surbma | Divi Project Shortcodes Alternatives
Surbma | Divi Extras
surbma-divi-extras
Useful modifications for the Divi Theme.
Surbma | Divi Remove Project CPT & Taxonomies
surbma-divi-remove-project-cpt
Removes the Project Custom Post Type from Divi theme.
Simple Divi Shortcode
simple-divi-shortcode
Insert DIVI Library item inside module content or inside a php template by using a shortcode.
Surbma | Divi Lightbox
surbma-divi-lightbox
Adds Divi's native lightbox effect to images (jpeg, jpg, gif, png, webp).
Supreme Modules Lite – Divi Theme, Extra Theme and Divi Builder
supreme-modules-for-divi
Divi Supreme lite plugin enhances the experience and features found on Divi and extend with custom creative modules to help you build amazing websites …
Surbma | Divi Project Shortcodes Developer Profile
27 plugins · 30K total installs
How We Detect Surbma | Divi Project Shortcodes
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/surbma-divi-project-shortcodes/js/surbma-divi-project-shortcodes.js/wp-content/plugins/surbma-divi-project-shortcodes/js/surbma-divi-project-shortcodes.jssurbma-divi-project-shortcodes/js/surbma-divi-project-shortcodes.js?ver=HTML / DOM Fingerprints
et_main_titleet_project_categorieset_project_metaet_project_meta_title<div class="et_main_title"><h1></h1><span class="et_project_categories"></span></div><div class="et_project_meta"><strong class="et_project_meta_title">