
Duplicate It – Post & Page Duplicator for WordPress Security & Risk Analysis
wordpress.org/plugins/duplicate-itLightweight one-click duplicate plugin for WordPress. Easily duplicate posts, pages and custom post types with automatic website builder detection.
Is Duplicate It – Post & Page Duplicator for WordPress Safe to Use in 2026?
Generally Safe
Score 100/100Duplicate It – Post & Page Duplicator for WordPress has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.
The static analysis of the "duplicate-it" v2.3 plugin indicates a generally good security posture with no critical or high-severity code signals identified. The absence of dangerous functions, file operations, and external HTTP requests is a positive sign. Furthermore, the plugin demonstrates a commitment to security by including nonce checks and capability checks, and a high percentage of output escaping is a strong defense against XSS vulnerabilities. The vulnerability history being clean suggests the developers have a good track record of maintaining secure code.
However, a significant concern arises from the single SQL query found, which is not using prepared statements. This represents a potential for SQL injection vulnerabilities, although the lack of taint flow analysis makes it difficult to quantify the exact risk. The attack surface is reported as zero for entry points, which is excellent, but this could be an artifact of the analysis tool or a true testament to the plugin's design.
In conclusion, the "duplicate-it" plugin exhibits several strengths in its security implementation. The lack of known vulnerabilities and the presence of good practices like output escaping and nonce checks are commendable. The primary area for improvement and potential risk lies in the handling of the SQL query. While the plugin appears robust, this single un-prepared SQL query warrants attention to ensure complete security.
Key Concerns
- SQL query not using prepared statements
Duplicate It – Post & Page Duplicator for WordPress Security Vulnerabilities
Duplicate It – Post & Page Duplicator for WordPress Code Analysis
SQL Query Safety
Output Escaping
Duplicate It – Post & Page Duplicator for WordPress Attack Surface
WordPress Hooks 15
Maintenance & Trust
Duplicate It – Post & Page Duplicator for WordPress Maintenance & Trust
Maintenance Signals
Community Trust
Duplicate It – Post & Page Duplicator for WordPress Alternatives
Just Duplicate
just-duplicate
Easily duplicate WordPress pages, posts, custom post types, and WooCommerce products with one click.
WP Clone any post type
wp-clone-any-post-type
Cloning posts, pages and custom post types in WordPress.
Duplicate Posts & Page
duplicate-posts-page
A simple plugin to duplicate your posts, page or any custom post types in just one click.
Custom Post Manager – Duplicate or Clone Posts, Pages, and Custom Post Types
custom-posts-manager
Quickly clone or duplicate Posts, Pages, and Custom Post Types with a single click.
Post DuplicateX – Advanced Post Duplicator
post-duplicatex
Duplicate posts, pages & custom post types with a single click. Save as draft, private, public, or pending with a powerful, user-friendly interface.
Duplicate It – Post & Page Duplicator for WordPress Developer Profile
2 plugins · 180 total installs
How We Detect Duplicate It – Post & Page Duplicator for WordPress
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/duplicate-it/css/duplicate-it.cssHTML / DOM Fingerprints
<!-- AUTO DETECT ACTIVE BUILDER --><!-- AUTO DETECT & APPLY BUILDER --><!-- APPLY EDITOR SETTING --><!-- All Editors ke liye kuch nahi karna -->