Duplicate & Translate Security & Risk Analysis

wordpress.org/plugins/duplicate-translate

Easily duplicate any post, then automatically translate it into your desired language with AI.

0 active installs v1.0.3 PHP 7.4+ WP 6.2+ Updated Jul 1, 2025
duplicategutenbergopenaitranslatetranslation
100
A · Safe
CVEs total0
Unpatched0
Last CVENever
Safety Verdict

Is Duplicate & Translate Safe to Use in 2026?

Generally Safe

Score 100/100

Duplicate & Translate has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.

No known CVEs Updated 9mo ago
Risk Assessment

The 'duplicate-translate' plugin version 1.0.3 exhibits a generally strong security posture based on the provided static analysis and vulnerability history. All identified entry points, specifically the 3 AJAX handlers, have associated nonce checks and capability checks, which is a positive indicator of secure coding practices. The complete absence of raw SQL queries, with all queries utilizing prepared statements, and a high percentage of properly escaped output further reinforce this. The lack of file operations and external HTTP requests minimizes common attack vectors. The plugin's vulnerability history is also clean, with no known CVEs, which suggests a well-maintained codebase.

However, while the plugin demonstrates good practices, there is a minor area for caution. The presence of one external HTTP request, although not flagged as a critical risk in the taint analysis, is an entry point for potential issues if the external service is compromised or introduces vulnerabilities. The taint analysis reporting zero flows with unsanitized paths is a strong positive, indicating that any data flowing through the plugin is handled securely. Overall, the plugin is assessed as low risk, but the single external HTTP request warrants careful monitoring.

Key Concerns

  • External HTTP request
Vulnerabilities
None known

Duplicate & Translate Security Vulnerabilities

No known vulnerabilities — this is a good sign.
Code Analysis
Analyzed Mar 17, 2026

Duplicate & Translate Code Analysis

Dangerous Functions
0
Raw SQL Queries
0
0 prepared
Unescaped Output
1
28 escaped
Nonce Checks
4
Capability Checks
5
File Operations
0
External Requests
1
Bundled Libraries
0

Output Escaping

97% escaped29 total outputs
Attack Surface

Duplicate & Translate Attack Surface

Entry Points3
Unprotected0

AJAX Handlers 3

authwp_ajax_duplamtr_initiate_jobincludes\progress-page.php:17
authwp_ajax_duplamtr_process_block_translationincludes\progress-page.php:18
authwp_ajax_duplamtr_finalize_jobincludes\progress-page.php:19
WordPress Hooks 4
actionadmin_menuincludes\admin-menu.php:16
actionadmin_initincludes\admin-menu.php:17
filterpost_row_actionsincludes\post-buttons.php:16
actionadmin_action_duplamtr_render_progress_pageincludes\progress-page.php:16
Maintenance & Trust

Duplicate & Translate Maintenance & Trust

Maintenance Signals

WordPress version tested6.8.5
Last updatedJul 1, 2025
PHP min version7.4
Downloads373

Community Trust

Rating80/100
Number of ratings1
Active installs0
Developer Profile

Duplicate & Translate Developer Profile

Judicael POUMAY

1 plugin · 0 total installs

94
trust score
Avg Security Score
100/100
Avg Patch Time
30 days
View full developer profile
Detection Fingerprints

How We Detect Duplicate & Translate

Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.

Asset Fingerprints

Asset Paths
/wp-content/plugins/duplicate-translate/assets/donation-button.css/wp-content/plugins/duplicate-translate/assets/admin-settings.js
Script Paths
https://fonts.googleapis.com/css?display=swap&family=Cookie
Version Parameters
duplicate-translate/assets/donation-button.css?ver=duplicate-translate/assets/admin-settings.js?ver=

HTML / DOM Fingerprints

Data Attributes
id="openai-key-div"id="gemini-key-div"id="claude-key-div"id="deepseek-key-div"
JS Globals
duplamtr_vars
FAQ

Frequently Asked Questions about Duplicate & Translate