
atec Duplicate Page & Post Security & Risk Analysis
wordpress.org/plugins/atec-duplicate-page-postDuplicate page or post with one click.
Is atec Duplicate Page & Post Safe to Use in 2026?
Generally Safe
Score 99/100atec Duplicate Page & Post has a strong security track record. Known vulnerabilities have been patched promptly.
The "atec-duplicate-page-post" plugin v1.2.25 exhibits a mixed security posture. On the positive side, the plugin demonstrates good practices by utilizing prepared statements for all SQL queries and properly escaping almost all output. It also incorporates nonce and capability checks, which are crucial for securing WordPress functionalities. The absence of taint analysis findings and dangerous function calls further suggests a generally well-written codebase.
However, a significant concern arises from the presence of one AJAX handler that lacks authentication checks. This represents a direct entry point that could be exploited by unauthenticated users if it performs any sensitive operations. The plugin also has a history of past vulnerabilities, with one medium severity CVE recorded. While currently unpatched vulnerabilities are zero, the recurrence of missing authorization as a common vulnerability type in its history is a red flag, suggesting potential recurring oversight in securing entry points.
In conclusion, while the plugin benefits from strong coding practices in areas like SQL and output handling, the unprotected AJAX endpoint and historical vulnerability patterns necessitate careful consideration. The focus should be on securing this exposed entry point and ensuring that future updates address any potential authorization flaws to mitigate risks.
Key Concerns
- AJAX handler without authentication check
- Past medium severity CVE
atec Duplicate Page & Post Security Vulnerabilities
CVEs by Year
Severity Breakdown
1 total CVE
atec Duplicate Page & Post <= 1.2.20 - Missing Authorization to Authenticated (Contributor+) Arbitrary Post Duplication and Data Exposure
atec Duplicate Page & Post Code Analysis
Output Escaping
atec Duplicate Page & Post Attack Surface
AJAX Handlers 1
WordPress Hooks 10
Maintenance & Trust
atec Duplicate Page & Post Maintenance & Trust
Maintenance Signals
Community Trust
atec Duplicate Page & Post Alternatives
No alternatives data available yet.
atec Duplicate Page & Post Developer Profile
16 plugins · 3K total installs
How We Detect atec Duplicate Page & Post
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/atec-duplicate-page-post/includes/ATEC/assets/css/atec-wpdpp-admin.css/wp-content/plugins/atec-duplicate-page-post/includes/ATEC/assets/js/atec-wpdpp-admin.js/wp-content/plugins/atec-duplicate-page-post/includes/ATEC/assets/js/atec-wpdpp-admin.jsatec-wpdpp-admin.js?ver=atec-wpdpp-admin.css?ver=HTML / DOM Fingerprints
atec-wpdpp-admin-rowatec-wpdpp-clone-buttondata-atec-wpdpp-idatec_wpdpp_ajax_cb