Surbma | Divi Project Shortcodes Security & Risk Analysis

wordpress.org/plugins/surbma-divi-project-shortcodes

Shortcodes to display Divi's Project elements, like category and tag list.

400 active installs v2.1 PHP 7.0+ WP 5.1+ Updated Apr 8, 2023
dividivi-themeelegant-themeselegantthemesshortcode
85
A · Safe
CVEs total0
Unpatched0
Last CVENever
Safety Verdict

Is Surbma | Divi Project Shortcodes Safe to Use in 2026?

Generally Safe

Score 85/100

Surbma | Divi Project Shortcodes has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.

No known CVEs Updated 2yr ago
Risk Assessment

The "surbma-divi-project-shortcodes" plugin v2.1 exhibits a mixed security posture. On the positive side, the static analysis reveals a lack of dangerous functions, secure handling of all SQL queries with prepared statements, and no file operations or external HTTP requests, which are excellent security practices. Furthermore, the vulnerability history is clean, with no recorded CVEs, indicating a potentially stable and well-maintained codebase regarding known exploits. However, a significant concern arises from the output escaping. With 100% of outputs not being properly escaped, there is a high risk of cross-site scripting (XSS) vulnerabilities. Any data rendered by the shortcodes that is influenced by user input or external sources is susceptible to injection attacks. While the plugin has a limited attack surface of 4 shortcodes, the absence of proper output sanitization on all of them presents a substantial security weakness. The lack of nonce and capability checks across the identified entry points, though currently showing no unauthenticated access, is also a notable weakness that could be exploited if vulnerabilities were introduced in the future.

Key Concerns

  • 100% of outputs not properly escaped
  • 0 Nonce checks on entry points
  • 0 Capability checks on entry points
Vulnerabilities
None known

Surbma | Divi Project Shortcodes Security Vulnerabilities

No known vulnerabilities — this is a good sign.
Code Analysis
Analyzed Mar 16, 2026

Surbma | Divi Project Shortcodes Code Analysis

Dangerous Functions
0
Raw SQL Queries
0
0 prepared
Unescaped Output
5
0 escaped
Nonce Checks
0
Capability Checks
0
File Operations
0
External Requests
0
Bundled Libraries
0

Output Escaping

0% escaped5 total outputs
Attack Surface

Surbma | Divi Project Shortcodes Attack Surface

Entry Points4
Unprotected0

Shortcodes 4

[project-category-list] surbma-divi-project-shortcodes.php:40
[project-tag-list] surbma-divi-project-shortcodes.php:45
[project-title] surbma-divi-project-shortcodes.php:59
[project-meta-box] surbma-divi-project-shortcodes.php:76
WordPress Hooks 1
actionplugins_loadedsurbma-divi-project-shortcodes.php:26
Maintenance & Trust

Surbma | Divi Project Shortcodes Maintenance & Trust

Maintenance Signals

WordPress version tested6.2.9
Last updatedApr 8, 2023
PHP min version7.0
Downloads10K

Community Trust

Rating96/100
Number of ratings6
Active installs400
Developer Profile

Surbma | Divi Project Shortcodes Developer Profile

Surbma

27 plugins · 30K total installs

71
trust score
Avg Security Score
88/100
Avg Patch Time
127 days
View full developer profile
Detection Fingerprints

How We Detect Surbma | Divi Project Shortcodes

Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.

Asset Fingerprints

Asset Paths
/wp-content/plugins/surbma-divi-project-shortcodes/js/surbma-divi-project-shortcodes.js
Script Paths
/wp-content/plugins/surbma-divi-project-shortcodes/js/surbma-divi-project-shortcodes.js
Version Parameters
surbma-divi-project-shortcodes/js/surbma-divi-project-shortcodes.js?ver=

HTML / DOM Fingerprints

CSS Classes
et_main_titleet_project_categorieset_project_metaet_project_meta_title
Shortcode Output
<div class="et_main_title"><h1></h1><span class="et_project_categories"></span></div><div class="et_project_meta"><strong class="et_project_meta_title">
FAQ

Frequently Asked Questions about Surbma | Divi Project Shortcodes