
Duplica – Duplicate Posts, Pages, Custom Posts or Users Security & Risk Analysis
wordpress.org/plugins/duplicaDuplicate posts, pages or custom posts with a single click.
Is Duplica – Duplicate Posts, Pages, Custom Posts or Users Safe to Use in 2026?
Generally Safe
Score 99/100Duplica – Duplicate Posts, Pages, Custom Posts or Users has a strong security track record. Known vulnerabilities have been patched promptly.
The duplica plugin v0.16 exhibits a generally good security posture based on the static analysis. The absence of any dangerous functions, raw SQL queries, file operations, or external HTTP requests is highly commendable. Furthermore, the robust implementation of output escaping (95%), nonce checks, and capability checks indicates a strong awareness of secure coding practices. The attack surface is also minimal, with no unprotected entry points discovered during the analysis.
However, the presence of one previously documented medium-severity vulnerability, even though currently patched, raises a slight concern. The 'Missing Authorization' type of the past vulnerability is a common and potentially impactful issue. While the static analysis found no current taint flows or immediate vulnerabilities, the historical data suggests that authorization checks might be an area that requires continued diligence from developers to ensure no new weaknesses are introduced in future updates.
In conclusion, duplica v0.16 appears to be a well-secured plugin with strong coding standards. The strengths lie in its minimal attack surface and thorough implementation of security checks. The primary area for continued vigilance is ensuring that the pattern of past authorization issues does not re-emerge, as this has been the historical weak point for this plugin.
Key Concerns
- Past medium vulnerability (Missing Authorization)
Duplica – Duplicate Posts, Pages, Custom Posts or Users Security Vulnerabilities
CVEs by Year
Severity Breakdown
1 total CVE
Duplica <= 0.6 - Authenticated (Subscriber+) Missing Authorization to Users/Posts Duplicates Creation
Duplica – Duplicate Posts, Pages, Custom Posts or Users Code Analysis
Output Escaping
Duplica – Duplicate Posts, Pages, Custom Posts or Users Attack Surface
Scheduled Events 1
Maintenance & Trust
Duplica – Duplicate Posts, Pages, Custom Posts or Users Maintenance & Trust
Maintenance Signals
Community Trust
Duplica – Duplicate Posts, Pages, Custom Posts or Users Alternatives
Clone Posts
clone-posts
Easily clone (duplicate) Posts, Pages and Custom Post Types, including their custom fields (post_meta)
Custom Post Manager – Duplicate or Clone Posts, Pages, and Custom Post Types
custom-posts-manager
Quickly clone or duplicate Posts, Pages, and Custom Post Types with a single click.
Yoast Duplicate Post
duplicate-post
The go-to tool for cloning posts and pages, including the powerful Rewrite & Republish feature.
WPvivid — Backup, Migration & Staging
wpvivid-backuprestore
Migrate, staging, backup WordPress, all in one.
Duplicate Post
copy-delete-posts
Duplicate post
Duplica – Duplicate Posts, Pages, Custom Posts or Users Developer Profile
10 plugins · 41K total installs
How We Detect Duplica – Duplicate Posts, Pages, Custom Posts or Users
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/duplica/assets/css/admin.css/wp-content/plugins/duplica/assets/js/admin.js/wp-content/plugins/duplica/assets/js/admin.jsduplica/assets/css/admin.css?ver=duplica/assets/js/admin.js?ver=HTML / DOM Fingerprints
duplica_ajax_object