
Publish Duplicate Post to Multisite Security & Risk Analysis
wordpress.org/plugins/duplicate-publish-multisiteDuplicates a post and publish in a subsite from multisite. Syncs Posts from Categories between sites.
Is Publish Duplicate Post to Multisite Safe to Use in 2026?
Generally Safe
Score 92/100Publish Duplicate Post to Multisite has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.
The "duplicate-publish-multisite" plugin v1.7.1 demonstrates a strong security posture based on the provided static analysis. It effectively utilizes prepared statements for all SQL queries and ensures all output is properly escaped, significantly reducing the risk of common web vulnerabilities like SQL injection and cross-site scripting. The absence of any recorded vulnerabilities in its history further reinforces this positive assessment, indicating a mature and well-maintained codebase. The plugin also appears to have a limited attack surface with no direct REST API routes, shortcodes, or cron events, and importantly, all identified AJAX handlers have authentication checks. The presence of nonce checks, although not exhaustive, is a good practice for securing AJAX endpoints.
Despite these strengths, a few areas warrant attention. The code analysis reveals the use of two nonces, which is good, but the absence of explicit capability checks on AJAX handlers is a concern. While the analysis states there are no unprotected entry points, relying solely on nonces without verifying user capabilities could potentially allow privileged actions to be performed by users who should not have access, especially if a nonce is leaked or compromised. The single file operation is also an area to monitor, though its context isn't fully detailed. Overall, the plugin is secure in many critical aspects, but the lack of capability checks on its AJAX handlers represents the most significant potential risk.
Key Concerns
- Missing capability checks on AJAX handlers
Publish Duplicate Post to Multisite Security Vulnerabilities
Publish Duplicate Post to Multisite Code Analysis
Output Escaping
Data Flow Analysis
Publish Duplicate Post to Multisite Attack Surface
AJAX Handlers 4
WordPress Hooks 6
Maintenance & Trust
Publish Duplicate Post to Multisite Maintenance & Trust
Maintenance Signals
Community Trust
Publish Duplicate Post to Multisite Alternatives
Multisite Post Duplicator
multisite-post-duplicator
Duplicate/Copy/Clone any individual page, post or custom post type from one site on your multisite network to another.
HashAgile Multisite Content Duplicator & Translator
hashagile-multisite-content-duplicator-translator
Duplicate multisite posts across network sites with automatic DeepL translation support.
Multisite Network Repost
multisite-network-repost
Repost your stories to selected sites in the multisite network, preserving attachments, custom fields, categories, tags etc.
Yoast Duplicate Post
duplicate-post
The go-to tool for cloning posts and pages, including the powerful Rewrite & Republish feature.
Duplicate Page
duplicate-page
Duplicate Posts, Pages and Custom Posts easily using single click
Publish Duplicate Post to Multisite Developer Profile
10 plugins · 8K total installs
How We Detect Publish Duplicate Post to Multisite
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/duplicate-publish-multisite/assets/css/publish-multisite-admin.css/wp-content/plugins/duplicate-publish-multisite/assets/js/publish-multisite-admin.js/wp-content/plugins/duplicate-publish-multisite/assets/js/publish-multisite-admin.jsduplicate-publish-multisite/assets/css/publish-multisite-admin.css?ver=duplicate-publish-multisite/assets/js/publish-multisite-admin.js?ver=HTML / DOM Fingerprints
publish-multisite-settingsdata-plugin-pathpublishMultisiteAdmin