
FastDup – Fastest WordPress Migration & Duplicator Security & Risk Analysis
wordpress.org/plugins/fastdupFastDup - Fastest WordPress Migration & Duplicator
Is FastDup – Fastest WordPress Migration & Duplicator Safe to Use in 2026?
Generally Safe
Score 89/100FastDup – Fastest WordPress Migration & Duplicator has a strong security track record. Known vulnerabilities have been patched promptly.
The "fastdup" v2.7.2 plugin presents a mixed security posture. On the positive side, the static analysis indicates a relatively small attack surface with no identified AJAX handlers, REST API routes, or shortcodes that lack authentication or permission checks. The plugin also demonstrates good practices in its SQL query handling, with 83% utilizing prepared statements, and most output being properly escaped.
However, significant concerns arise from the presence of the `unserialize` function, a known source of critical vulnerabilities if not handled with extreme care. The vulnerability history of this plugin is also a major red flag, with four past CVEs, including one critical and one high severity. The common vulnerability types (Missing Authorization, Path Traversal, Information Exposure, and Log File Insertion) suggest recurring and potentially severe security flaws in the past. The fact that the last vulnerability was in 2026 suggests a history of ongoing security issues that may not have been fully addressed in prior versions or that new issues are being discovered with some regularity. The absence of nonce checks and a limited number of capability checks further elevate the risk profile, as these are fundamental security mechanisms often exploited in WordPress plugins.
In conclusion, while "fastdup" v2.7.2 shows some adherence to secure coding practices in specific areas like SQL and output escaping, the presence of dangerous functions, a history of critical vulnerabilities, and a lack of robust authentication/authorization checks on potential entry points represent significant security weaknesses. Users should proceed with extreme caution.
Key Concerns
- Dangerous function: unserialize used
- 0 Nonce checks found
- History of 1 critical CVE
- History of 1 high CVE
- History of 2 medium CVEs
- SQL queries with prepared statements at 83%
- Output escaping at 80%
FastDup – Fastest WordPress Migration & Duplicator Security Vulnerabilities
CVEs by Year
Severity Breakdown
4 total CVEs
FastDup – Fastest WordPress Migration & Duplicator <= 2.7.1 - Missing Authorization to Authenticated (Contributor+) Backup Creation and Download
FastDup <= 2.7 - Authenticated (Contributor+) Path Traversal via 'dir_path' REST Parameter
FastDup <= 2.1.9 - Sensitive Information Exposure via Directory Listing
FastDup <= 2.1.7 - Sensitive Information Exposure via Log File
FastDup – Fastest WordPress Migration & Duplicator Code Analysis
Dangerous Functions Found
SQL Query Safety
Output Escaping
FastDup – Fastest WordPress Migration & Duplicator Attack Surface
WordPress Hooks 9
Scheduled Events 1
Maintenance & Trust
FastDup – Fastest WordPress Migration & Duplicator Maintenance & Trust
Maintenance Signals
Community Trust
FastDup – Fastest WordPress Migration & Duplicator Alternatives
Folder Excluder for AIO WP Migration
aio-files-excluder
This plugin provides functionality to exclude extra folders like Updraft, WpBackup etc from been backed up in All in One WP Migration backup tool.
Media Type Excluder For AIOWP Migration
media-type-excluder-for-aiowp-migration
This plugin provides a simple way to exclude specific file extensions from your All-in-One WP Migration export.
UpdraftPlus: WP Backup & Migration Plugin
updraftplus
Backup, restore or migrate your WordPress website to another host or domain. Schedule backups or run manually. Migrate in minutes.
Duplicator – Backups & Migration Plugin – Cloud Backups, Scheduled Backups, & More
duplicator
The best WordPress backup and migration plugin. Quickly and easily backup ,migrate, copy, move, or clone your site from one location to another.
Backup Migration
backup-backup
Backup Migration
FastDup – Fastest WordPress Migration & Duplicator Developer Profile
13 plugins · 496K total installs
How We Detect FastDup – Fastest WordPress Migration & Duplicator
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/fastdup/assets/admin/build/js/app.js/wp-content/plugins/fastdup/assets/admin/build/js/app.jsnjt-fastdup?ver=HTML / DOM Fingerprints
data-njt-fastdup-noncedata-njt-fastdup-urlnjt_fastdupnjt_fastdup_data/wp-json/njt-fastdup/v1/packages/wp-json/njt-fastdup/v1/packages/scan-package/wp-json/njt-fastdup/v1/packages/download/wp-json/njt-fastdup/v1/packages/view-log/wp-json/njt-fastdup/v1/packages/update-status/wp-json/njt-fastdup/v1/packages/delete