
Duplicate and Auto Draft Cleaner Security & Risk Analysis
wordpress.org/plugins/duplicate-and-auto-draft-cleanerClean auto-drafts and duplicate posts with manual controls, scheduled cleanup, activity logs, and safer delete confirmation.
Is Duplicate and Auto Draft Cleaner Safe to Use in 2026?
Generally Safe
Score 100/100Duplicate and Auto Draft Cleaner has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.
The "duplicate-and-auto-draft-cleaner" v1.5.2 plugin exhibits a generally good security posture, adhering to several best practices. Notably, all SQL queries are prepared, and a high percentage of output is properly escaped, which are crucial for preventing common web vulnerabilities. The plugin also incorporates nonce and capability checks, indicating an effort to secure its functionalities. The absence of any known vulnerabilities (CVEs) and a clean vulnerability history further contribute to its positive security profile.
However, the static analysis does reveal some areas for concern. The presence of two flows with unsanitized paths, one classified as high severity in the taint analysis, suggests a potential risk of path traversal or other file system-related vulnerabilities. While the overall attack surface appears small with no direct entry points identified as unprotected, these taint flows warrant further investigation to ensure sensitive data or system resources are not compromised. The plugin's strengths lie in its robust handling of database operations and output sanitization, but the identified unsanitized paths represent the most significant risk to address.
In conclusion, while the plugin has a commendable track record and good internal coding practices, the taint analysis findings are a significant weakness. The low number of vulnerabilities historically is a strong positive indicator, but the detected unsanitized paths are a critical area that could be exploited if not properly addressed. Users should remain aware of these potential risks and ensure the plugin is updated if any patches become available for these specific issues.
Key Concerns
- High severity taint flow found
- Flows with unsanitized paths found
Duplicate and Auto Draft Cleaner Security Vulnerabilities
Duplicate and Auto Draft Cleaner Code Analysis
SQL Query Safety
Output Escaping
Data Flow Analysis
Duplicate and Auto Draft Cleaner Attack Surface
WordPress Hooks 9
Scheduled Events 2
Maintenance & Trust
Duplicate and Auto Draft Cleaner Maintenance & Trust
Maintenance Signals
Community Trust
Duplicate and Auto Draft Cleaner Alternatives
Duplicate Post
copy-delete-posts
Duplicate post
Optimize Database after Deleting Revisions
rvg-optimize-database
One-click database optimization with precise revision cleanup and flexible scheduling. Speeding up sites since 2011!
Delete Duplicate Posts
delete-duplicate-posts
Get rid of duplicate posts and pages (any post type) on your blog with manual or automatic modes.
Clone Posts
clone-posts
Easily clone (duplicate) Posts, Pages and Custom Post Types, including their custom fields (post_meta)
Duplica – Duplicate Posts, Pages, Custom Posts or Users
duplica
Duplicate posts, pages or custom posts with a single click.
Duplicate and Auto Draft Cleaner Developer Profile
3 plugins · 60 total installs
How We Detect Duplicate and Auto Draft Cleaner
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/duplicate-and-auto-draft-cleaner/style.css/wp-content/plugins/duplicate-and-auto-draft-cleaner/admin-scripts.js/wp-content/plugins/duplicate-and-auto-draft-cleaner/admin-scripts.jsduplicate-and-auto-draft-cleaner/style.css?ver=duplicate-and-auto-draft-cleaner/admin-scripts.js?ver=HTML / DOM Fingerprints
adc-sectionadc-filter-rowadc-checkbox-filternav-tab-activedata-nonce-valuedupadc_ajax_object