
WP Delete Post Copies Security & Risk Analysis
wordpress.org/plugins/etruel-del-post-copiesDelete duplicate posts by title or content, including attachments, with powerful filters. Supports manual and scheduled cleanups.
Is WP Delete Post Copies Safe to Use in 2026?
Generally Safe
Score 98/100WP Delete Post Copies has a strong security track record. Known vulnerabilities have been patched promptly.
The "etruel-del-post-copies" plugin, version 6.0.3, presents a mixed security posture. While it demonstrates good practices by using prepared statements for all SQL queries and having a high rate of output escaping (81%), there are significant concerns. The plugin exposes 9 AJAX handlers, with a third (3) lacking authentication checks, creating a substantial attack surface for unauthorized actions.
Taint analysis reveals 3 flows with unsanitized paths, although these are not categorized as critical or high severity. The vulnerability history shows 2 previously disclosed medium severity CVEs, both related to Cross-Site Scripting and Missing Authorization. The fact that the last vulnerability was in 2025-11-20, while not yet patched, indicates a potential for ongoing security issues or a delay in addressing past problems, especially considering these were not minor vulnerabilities.
Overall, the plugin has strengths in its database interaction and output handling. However, the unprotected AJAX endpoints are a critical security flaw that could be exploited by attackers. The history of medium-severity vulnerabilities related to authorization and XSS further amplifies these concerns. While there are no currently unpatched CVEs, the past issues and the unauthenticated AJAX endpoints warrant careful consideration.
Key Concerns
- Unprotected AJAX handlers
- Flows with unsanitized paths
- Medium severity CVE history
- Missing Authorization vulnerabilities in history
- Cross-site Scripting vulnerabilities in history
WP Delete Post Copies Security Vulnerabilities
CVEs by Year
Severity Breakdown
2 total CVEs
WP Delete Post Copies <= 6.0.2 - Authenticated (Admin+) Stored Cross-Site Scripting
WP Delete Post Copies <= 5.5 - Missing Authorization
WP Delete Post Copies Code Analysis
Bundled Libraries
Output Escaping
Data Flow Analysis
WP Delete Post Copies Attack Surface
AJAX Handlers 9
WordPress Hooks 67
Scheduled Events 2
Maintenance & Trust
WP Delete Post Copies Maintenance & Trust
Maintenance Signals
Community Trust
WP Delete Post Copies Alternatives
Delete Duplicate Posts
delete-duplicate-posts
Get rid of duplicate posts and pages (any post type) on your blog with manual or automatic modes.
WOLF – WordPress Posts Bulk Editor and Manager Professional
bulk-editor
WOLF (formerly WPBE) - a WordPress plugin for managing posts, pages, and custom types easily. Perfect for real estate, cars, etc.
Delete Posts automatically
delete-old-posts-programmatically
The Delete Posts Automatically plugin keeps your website clean by programmatically deleting posts using a wide range of powerful filters.
Post Lockdown
post-lockdown
Allows admins to protect selected posts and pages so they cannot be trashed or deleted by non-admin users.
Trash Duplicate and 301 Redirect
trash-duplicate-and-301-redirect
Find and delete duplicates posts, pages, custom post type posts and set 301 redirect to the new or old URL.
WP Delete Post Copies Developer Profile
11 plugins · 13K total installs
How We Detect WP Delete Post Copies
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/etruel-del-post-copies/assets/css/select2.min.css/wp-content/plugins/etruel-del-post-copies/assets/js/select2.min.js/wp-content/plugins/etruel-del-post-copies/assets/js/wpedpc-admin.js/wp-content/plugins/etruel-del-post-copies/assets/js/wpedpc-frontend.js/wp-content/plugins/etruel-del-post-copies/assets/js/select2.min.js/wp-content/plugins/etruel-del-post-copies/assets/js/wpedpc-admin.js/wp-content/plugins/etruel-del-post-copies/assets/js/wpedpc-frontend.jsetruel-del-post-copies/assets/css/select2.min.css?ver=etruel-del-post-copies/assets/js/select2.min.js?ver=etruel-del-post-copies/assets/js/wpedpc-admin.js?ver=etruel-del-post-copies/assets/js/wpedpc-frontend.js?ver=HTML / DOM Fingerprints
wpedpcampaignwpedpc_campaign_settingsdata-wpedpc-campaign-idwpedpc_campaigns_data