Publish Duplicate Post to Multisite Security & Risk Analysis

wordpress.org/plugins/duplicate-publish-multisite

Duplicates a post and publish in a subsite from multisite. Syncs Posts from Categories between sites.

10 active installs v1.7.1 PHP + WP 4.0+ Updated Nov 4, 2024
duplicatemultisitesync-posts
92
A · Safe
CVEs total0
Unpatched0
Last CVENever
Safety Verdict

Is Publish Duplicate Post to Multisite Safe to Use in 2026?

Generally Safe

Score 92/100

Publish Duplicate Post to Multisite has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.

No known CVEs Updated 1yr ago
Risk Assessment

The "duplicate-publish-multisite" plugin v1.7.1 demonstrates a strong security posture based on the provided static analysis. It effectively utilizes prepared statements for all SQL queries and ensures all output is properly escaped, significantly reducing the risk of common web vulnerabilities like SQL injection and cross-site scripting. The absence of any recorded vulnerabilities in its history further reinforces this positive assessment, indicating a mature and well-maintained codebase. The plugin also appears to have a limited attack surface with no direct REST API routes, shortcodes, or cron events, and importantly, all identified AJAX handlers have authentication checks. The presence of nonce checks, although not exhaustive, is a good practice for securing AJAX endpoints.

Despite these strengths, a few areas warrant attention. The code analysis reveals the use of two nonces, which is good, but the absence of explicit capability checks on AJAX handlers is a concern. While the analysis states there are no unprotected entry points, relying solely on nonces without verifying user capabilities could potentially allow privileged actions to be performed by users who should not have access, especially if a nonce is leaked or compromised. The single file operation is also an area to monitor, though its context isn't fully detailed. Overall, the plugin is secure in many critical aspects, but the lack of capability checks on its AJAX handlers represents the most significant potential risk.

Key Concerns

  • Missing capability checks on AJAX handlers
Vulnerabilities
None known

Publish Duplicate Post to Multisite Security Vulnerabilities

No known vulnerabilities — this is a good sign.
Code Analysis
Analyzed Mar 17, 2026

Publish Duplicate Post to Multisite Code Analysis

Dangerous Functions
0
Raw SQL Queries
0
0 prepared
Unescaped Output
0
66 escaped
Nonce Checks
2
Capability Checks
0
File Operations
1
External Requests
0
Bundled Libraries
0

Output Escaping

100% escaped66 total outputs
Data Flows
All sanitized

Data Flow Analysis

2 flows
sync_all_entries (includes\class-admin-publishmu.php:334)
Source (user input) Sink (dangerous op) Sanitizer Transform Unsanitized Sanitized
Attack Surface

Publish Duplicate Post to Multisite Attack Surface

Entry Points4
Unprotected0

AJAX Handlers 4

authwp_ajax_sync_all_entriesincludes\class-admin-publishmu.php:59
noprivwp_ajax_sync_all_entriesincludes\class-admin-publishmu.php:60
authwp_ajax_category_publishincludes\class-pubmult-settings.php:40
noprivwp_ajax_category_publishincludes\class-pubmult-settings.php:41
WordPress Hooks 6
actionsave_postincludes\class-admin-publishmu.php:56
actionadmin_enqueue_scriptsincludes\class-admin-publishmu.php:58
actionadmin_menuincludes\class-pubmult-settings.php:35
actionadmin_initincludes\class-pubmult-settings.php:36
actionadmin_enqueue_scriptsincludes\class-pubmult-settings.php:37
actionplugins_loadedpublish-multisite.php:31
Maintenance & Trust

Publish Duplicate Post to Multisite Maintenance & Trust

Maintenance Signals

WordPress version tested6.7.5
Last updatedNov 4, 2024
PHP min version
Downloads4K

Community Trust

Rating40/100
Number of ratings1
Active installs10
Developer Profile

Publish Duplicate Post to Multisite Developer Profile

closemarketing

10 plugins · 8K total installs

88
trust score
Avg Security Score
92/100
Avg Patch Time
30 days
View full developer profile
Detection Fingerprints

How We Detect Publish Duplicate Post to Multisite

Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.

Asset Fingerprints

Asset Paths
/wp-content/plugins/duplicate-publish-multisite/assets/css/publish-multisite-admin.css/wp-content/plugins/duplicate-publish-multisite/assets/js/publish-multisite-admin.js
Script Paths
/wp-content/plugins/duplicate-publish-multisite/assets/js/publish-multisite-admin.js
Version Parameters
duplicate-publish-multisite/assets/css/publish-multisite-admin.css?ver=duplicate-publish-multisite/assets/js/publish-multisite-admin.js?ver=

HTML / DOM Fingerprints

CSS Classes
publish-multisite-settings
Data Attributes
data-plugin-path
JS Globals
publishMultisiteAdmin
FAQ

Frequently Asked Questions about Publish Duplicate Post to Multisite