Duplicate It – Post & Page Duplicator for WordPress Security & Risk Analysis

wordpress.org/plugins/duplicate-it

Lightweight one-click duplicate plugin for WordPress. Easily duplicate posts, pages and custom post types with automatic website builder detection.

100 active installs v2.3 PHP 5.2.4+ WP 3.4+ Updated Mar 11, 2026
custom-post-typeduplicate-pageduplicate-postpage-duplicatorpost-duplicator
100
A · Safe
CVEs total0
Unpatched0
Last CVENever
Safety Verdict

Is Duplicate It – Post & Page Duplicator for WordPress Safe to Use in 2026?

Generally Safe

Score 100/100

Duplicate It – Post & Page Duplicator for WordPress has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.

No known CVEs Updated 24d ago
Risk Assessment

The static analysis of the "duplicate-it" v2.3 plugin indicates a generally good security posture with no critical or high-severity code signals identified. The absence of dangerous functions, file operations, and external HTTP requests is a positive sign. Furthermore, the plugin demonstrates a commitment to security by including nonce checks and capability checks, and a high percentage of output escaping is a strong defense against XSS vulnerabilities. The vulnerability history being clean suggests the developers have a good track record of maintaining secure code.

However, a significant concern arises from the single SQL query found, which is not using prepared statements. This represents a potential for SQL injection vulnerabilities, although the lack of taint flow analysis makes it difficult to quantify the exact risk. The attack surface is reported as zero for entry points, which is excellent, but this could be an artifact of the analysis tool or a true testament to the plugin's design.

In conclusion, the "duplicate-it" plugin exhibits several strengths in its security implementation. The lack of known vulnerabilities and the presence of good practices like output escaping and nonce checks are commendable. The primary area for improvement and potential risk lies in the handling of the SQL query. While the plugin appears robust, this single un-prepared SQL query warrants attention to ensure complete security.

Key Concerns

  • SQL query not using prepared statements
Vulnerabilities
None known

Duplicate It – Post & Page Duplicator for WordPress Security Vulnerabilities

No known vulnerabilities — this is a good sign.
Code Analysis
Analyzed Mar 16, 2026

Duplicate It – Post & Page Duplicator for WordPress Code Analysis

Dangerous Functions
0
Raw SQL Queries
1
0 prepared
Unescaped Output
2
14 escaped
Nonce Checks
1
Capability Checks
3
File Operations
0
External Requests
0
Bundled Libraries
0

SQL Query Safety

0% prepared1 total queries

Output Escaping

88% escaped16 total outputs
Attack Surface

Duplicate It – Post & Page Duplicator for WordPress Attack Surface

Entry Points0
Unprotected0
WordPress Hooks 15
actionadmin_initduplicate-post-setting.php:41
actionadmin_menuduplicate-post-setting.php:42
actionadmin_enqueue_scriptspost-duplicate.php:16
actionadmin_action_rd_duplicate_post_as_draftpost-duplicate.php:278
filterbulk_actions-edit-postpost-duplicate.php:301
filterbulk_actions-edit-pagepost-duplicate.php:302
actionadmin_action_duplicatepost-duplicate.php:324
filterpage_row_actionspost-duplicate.php:439
filterpost_row_actionspost-duplicate.php:456
actionadmin_action_rd_duplicate_post_as_draftpost-duplicate.php:512
actionadmin_enqueue_scriptspost-duplicate.php:519
actionadmin_headpost-duplicate.php:522
actionadmin_initpost-duplicate.php:530
actionadmin_noticespost-duplicate.php:590
filterpage_row_actionspost-duplicate.php:604
Maintenance & Trust

Duplicate It – Post & Page Duplicator for WordPress Maintenance & Trust

Maintenance Signals

WordPress version tested6.9.4
Last updatedMar 11, 2026
PHP min version5.2.4
Downloads6K

Community Trust

Rating100/100
Number of ratings6
Active installs100
Developer Profile

Duplicate It – Post & Page Duplicator for WordPress Developer Profile

Smartz Minds

2 plugins · 180 total installs

93
trust score
Avg Security Score
99/100
Avg Patch Time
14 days
View full developer profile
Detection Fingerprints

How We Detect Duplicate It – Post & Page Duplicator for WordPress

Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.

Asset Fingerprints

Asset Paths
/wp-content/plugins/duplicate-it/css/duplicate-it.css

HTML / DOM Fingerprints

HTML Comments
<!-- AUTO DETECT ACTIVE BUILDER --><!-- AUTO DETECT & APPLY BUILDER --><!-- APPLY EDITOR SETTING --><!-- All Editors ke liye kuch nahi karna -->
FAQ

Frequently Asked Questions about Duplicate It – Post & Page Duplicator for WordPress