
Fix Duplicates Security & Risk Analysis
wordpress.org/plugins/fix-duplicatesDo you run a site with user submitted content? Do users submit the same post again and again? Use the Fix Duplicates plugin to find and delete duplica …
Is Fix Duplicates Safe to Use in 2026?
Generally Safe
Score 85/100Fix Duplicates has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.
The 'fix-duplicates' plugin v1.0.4 exhibits a generally good security posture, primarily due to its diligent use of prepared statements for all SQL queries and the absence of known vulnerabilities. The static analysis reveals a limited attack surface with only two AJAX handlers, and importantly, zero unprotected entry points. This suggests developers have considered basic security measures. However, a significant concern lies in the output escaping, where only 60% of outputs are properly escaped. This could potentially lead to cross-site scripting (XSS) vulnerabilities if user-supplied data is rendered directly without sufficient sanitization. Furthermore, the taint analysis shows four flows with unsanitized paths, although they did not reach a critical or high severity level. This warrants careful review to ensure these paths don't become exploitable with minor modifications or in conjunction with other factors. The plugin's clean vulnerability history is a positive sign, indicating a commitment to security or a lack of past exploitation, but the identified code signals still present potential risks.
Key Concerns
- Output escaping is only 60% proper
- Taint analysis shows 4 unsanitized paths
Fix Duplicates Security Vulnerabilities
Fix Duplicates Code Analysis
SQL Query Safety
Output Escaping
Data Flow Analysis
Fix Duplicates Attack Surface
AJAX Handlers 2
WordPress Hooks 5
Maintenance & Trust
Fix Duplicates Maintenance & Trust
Maintenance Signals
Community Trust
Fix Duplicates Alternatives
Trash Duplicate and 301 Redirect
trash-duplicate-and-301-redirect
Find and delete duplicates posts, pages, custom post type posts and set 301 redirect to the new or old URL.
Delete Duplicate Posts
delete-duplicate-posts
Get rid of duplicate posts and pages (any post type) on your blog with manual or automatic modes.
Duplicate Post
copy-delete-posts
Duplicate post
Clone Posts
clone-posts
Easily clone (duplicate) Posts, Pages and Custom Post Types, including their custom fields (post_meta)
Duplica – Duplicate Posts, Pages, Custom Posts or Users
duplica
Duplicate posts, pages or custom posts with a single click.
Fix Duplicates Developer Profile
3 plugins · 8K total installs
How We Detect Fix Duplicates
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/fix-duplicates/images/fix-duplicates-icon-16.png/wp-content/plugins/fix-duplicates/includes/fix-duplicates.jsfix-duplicates/includes/fix-duplicates.css?ver=fix-duplicates/includes/fix-duplicates.js?ver=HTML / DOM Fingerprints
<!-- Start Fix Duplicates plugin additions --><!-- End Fix Duplicates plugin additions -->