
Duplicate Post Page Menu & Custom Post Type Security & Risk Analysis
wordpress.org/plugins/duplicate-post-page-menu-custom-post-typeThe best plugin to duplicate post, page, menu and custom post type multiple times in a single click.
Is Duplicate Post Page Menu & Custom Post Type Safe to Use in 2026?
Generally Safe
Score 91/100Duplicate Post Page Menu & Custom Post Type has a strong security track record. Known vulnerabilities have been patched promptly.
The "duplicate-post-page-menu-custom-post-type" plugin v3.0.1 exhibits a mixed security posture. While it has a relatively small attack surface and no identified critical or high-severity vulnerabilities in its history, concerns arise from its static analysis. Specifically, two out of three AJAX handlers lack authentication checks, creating a significant entry point for unauthorized actions. The plugin also shows some weaknesses in output escaping, with only 60% being properly escaped, which could lead to cross-site scripting (XSS) vulnerabilities if untrusted data is involved. The presence of two medium-severity CVEs in its history, both related to missing authorization, reinforces the concern around unauthenticated access points. While the current version has no unpatched CVEs and a good rate of prepared SQL statements, the identified lack of authorization on AJAX endpoints is a notable weakness that needs to be addressed. The absence of dangerous functions, file operations, and external HTTP requests are positive security indicators. Overall, the plugin has strengths in its code hygiene but requires immediate attention to its authentication mechanisms for AJAX handlers.
Key Concerns
- Unprotected AJAX handlers
- Insufficient output escaping
- Medium severity CVEs in history
- Low number of nonce checks
Duplicate Post Page Menu & Custom Post Type Security Vulnerabilities
CVEs by Year
Severity Breakdown
2 total CVEs
Duplicate Post Page Menu & Custom Post Type <= 2.3.1 - Missing Authorization to Post Duplication
Duplicate Post Page Menu & Custom Post Type <= 2.3.1 - Missing Authorization
Duplicate Post Page Menu & Custom Post Type Code Analysis
SQL Query Safety
Output Escaping
Data Flow Analysis
Duplicate Post Page Menu & Custom Post Type Attack Surface
AJAX Handlers 3
WordPress Hooks 11
Maintenance & Trust
Duplicate Post Page Menu & Custom Post Type Maintenance & Trust
Maintenance Signals
Community Trust
Duplicate Post Page Menu & Custom Post Type Alternatives
Post DuplicateX – Advanced Post Duplicator
post-duplicatex
Duplicate posts, pages & custom post types with a single click. Save as draft, private, public, or pending with a powerful, user-friendly interface.
Duplicate Page and Post
duplicate-wp-page-post
Duplicate post, Duplicate page and Duplicate custom post or clone page and clone post.
WP Duplicate Page
wp-duplicate-page
Clone WordPress page, post, custom post types
Carbon Copy
carbon-copy
Copy pages, posts, menus quickly and conveniently.
WP Clone any post type
wp-clone-any-post-type
Cloning posts, pages and custom post types in WordPress.
Duplicate Post Page Menu & Custom Post Type Developer Profile
2 plugins · 10K total installs
How We Detect Duplicate Post Page Menu & Custom Post Type
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/duplicate-post-page-menu-custom-post-type/css/ppmc-style.css/wp-content/plugins/duplicate-post-page-menu-custom-post-type/js/ppmc-script.jsduplicate-post-page-menu-custom-post-type/css/ppmc-style.css?ver=duplicate-post-page-menu-custom-post-type/js/ppmc-script.js?ver=HTML / DOM Fingerprints
duplicate-ppmc-inpost-buttonPPMC_URLPPMC_V