Duplica – Duplicate Posts, Pages, Custom Posts or Users Security & Risk Analysis

wordpress.org/plugins/duplica

Duplicate posts, pages or custom posts with a single click.

2K active installs v0.16 PHP 7.4+ WP 6.0+ Updated Jun 3, 2025
cloneduplicateduplicate-post-typesduplicate-postsduplicate-users
99
A · Safe
CVEs total1
Unpatched0
Last CVEJul 18, 2024
Safety Verdict

Is Duplica – Duplicate Posts, Pages, Custom Posts or Users Safe to Use in 2026?

Generally Safe

Score 99/100

Duplica – Duplicate Posts, Pages, Custom Posts or Users has a strong security track record. Known vulnerabilities have been patched promptly.

1 known CVELast CVE: Jul 18, 2024Updated 10mo ago
Risk Assessment

The duplica plugin v0.16 exhibits a generally good security posture based on the static analysis. The absence of any dangerous functions, raw SQL queries, file operations, or external HTTP requests is highly commendable. Furthermore, the robust implementation of output escaping (95%), nonce checks, and capability checks indicates a strong awareness of secure coding practices. The attack surface is also minimal, with no unprotected entry points discovered during the analysis.

However, the presence of one previously documented medium-severity vulnerability, even though currently patched, raises a slight concern. The 'Missing Authorization' type of the past vulnerability is a common and potentially impactful issue. While the static analysis found no current taint flows or immediate vulnerabilities, the historical data suggests that authorization checks might be an area that requires continued diligence from developers to ensure no new weaknesses are introduced in future updates.

In conclusion, duplica v0.16 appears to be a well-secured plugin with strong coding standards. The strengths lie in its minimal attack surface and thorough implementation of security checks. The primary area for continued vigilance is ensuring that the pattern of past authorization issues does not re-emerge, as this has been the historical weak point for this plugin.

Key Concerns

  • Past medium vulnerability (Missing Authorization)
Vulnerabilities
1

Duplica – Duplicate Posts, Pages, Custom Posts or Users Security Vulnerabilities

CVEs by Year

1 CVE in 2024
2024
Patched Has unpatched

Severity Breakdown

Medium
1

1 total CVE

CVE-2024-5997medium · 4.3Missing Authorization

Duplica <= 0.6 - Authenticated (Subscriber+) Missing Authorization to Users/Posts Duplicates Creation

Jul 18, 2024 Patched in 0.7 (1d)
Code Analysis
Analyzed Mar 17, 2026

Duplica – Duplicate Posts, Pages, Custom Posts or Users Code Analysis

Dangerous Functions
0
Raw SQL Queries
0
0 prepared
Unescaped Output
1
18 escaped
Nonce Checks
2
Capability Checks
3
File Operations
0
External Requests
0
Bundled Libraries
0

Output Escaping

95% escaped19 total outputs
Attack Surface

Duplica – Duplicate Posts, Pages, Custom Posts or Users Attack Surface

Entry Points0
Unprotected0

Scheduled Events 1

codexpert-daily
Maintenance & Trust

Duplica – Duplicate Posts, Pages, Custom Posts or Users Maintenance & Trust

Maintenance Signals

WordPress version tested6.8.5
Last updatedJun 3, 2025
PHP min version7.4
Downloads29K

Community Trust

Rating90/100
Number of ratings2
Active installs2K
Developer Profile

Duplica – Duplicate Posts, Pages, Custom Posts or Users Developer Profile

Codexpert, Inc

10 plugins · 41K total installs

75
trust score
Avg Security Score
81/100
Avg Patch Time
39 days
View full developer profile
Detection Fingerprints

How We Detect Duplica – Duplicate Posts, Pages, Custom Posts or Users

Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.

Asset Fingerprints

Asset Paths
/wp-content/plugins/duplica/assets/css/admin.css/wp-content/plugins/duplica/assets/js/admin.js
Script Paths
/wp-content/plugins/duplica/assets/js/admin.js
Version Parameters
duplica/assets/css/admin.css?ver=duplica/assets/js/admin.js?ver=

HTML / DOM Fingerprints

JS Globals
duplica_ajax_object
FAQ

Frequently Asked Questions about Duplica – Duplicate Posts, Pages, Custom Posts or Users