
Carbon Copy Security & Risk Analysis
wordpress.org/plugins/carbon-copyCopy pages, posts, menus quickly and conveniently.
Is Carbon Copy Safe to Use in 2026?
Generally Safe
Score 100/100Carbon Copy has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.
The "carbon-copy" plugin v1.3.6 exhibits a strong security posture based on the provided static analysis. There are no identified dangerous functions, all SQL queries utilize prepared statements, and a high percentage (75%) of output is properly escaped, indicating good development practices. The absence of known CVEs and a clean vulnerability history further suggests a mature and secure plugin. The limited attack surface with no exposed AJAX handlers, REST API routes, shortcodes, or cron events without proper authorization checks is a significant strength. However, the presence of file operations and nonce checks, while not inherently problematic, would warrant closer inspection in a more in-depth audit to ensure they are implemented securely and without potential for abuse. The limited number of static analysis flows analyzed and the overall lack of recorded vulnerabilities in its history might also suggest a less extensive testing or auditing process in the past, though this is speculative.
Key Concerns
- 25% of outputs are not properly escaped
- File operations present
- Nonce checks present
Carbon Copy Security Vulnerabilities
Carbon Copy Code Analysis
Output Escaping
Data Flow Analysis
Carbon Copy Attack Surface
WordPress Hooks 36
Maintenance & Trust
Carbon Copy Maintenance & Trust
Maintenance Signals
Community Trust
Carbon Copy Alternatives
Duplicate Post
copy-delete-posts
Duplicate post
Duplicate Post – duplicate pages, copy content, clone posts
duplicate-post-rb
Duplicate Post RB makes it easy to duplicate posts, pages and custom post types. Create duplicate posts, clone content, automate duplication
Quick Copy – Duplicate Posts & Pages
duplicator-post-page
Easily duplicate any post or page, including all metadata and taxonomies, with just one click.
Duplicate Post and Clone Page
duplicate-post-and-clone-page
One click duplicate post and page. The best solution for easy copy page and post. It just works!
WP Duplicate Page
wp-duplicate-page
Clone WordPress page, post, custom post types
Carbon Copy Developer Profile
4 plugins · 5K total installs
How We Detect Carbon Copy
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/carbon-copy/carbon-copy.css/wp-content/plugins/carbon-copy/carbon-copy.js/wp-content/plugins/carbon-copy/carbon-copy.jscarbon-copy.css?ver=carbon-copy.js?ver=HTML / DOM Fingerprints
carbon-copy-column-titlecarbon-copy-column-contentdata-carbon-copy-post-id