Kandeshop Duplicate Post Manager Security & Risk Analysis

wordpress.org/plugins/kandeshop-duplicate-post-manager

Manage and clean up duplicate WordPress posts with ease. Delete duplicates, assign 301 redirects, and generate .htaccess rules.

0 active installs v1.3 PHP 7.4+ WP 5.0+ Updated Aug 30, 2025
301duplicate-postshtaccessredirectseo
100
A · Safe
CVEs total0
Unpatched0
Last CVENever
Download
Safety Verdict

Is Kandeshop Duplicate Post Manager Safe to Use in 2026?

Generally Safe

Score 100/100

Kandeshop Duplicate Post Manager has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.

No known CVEs Updated 7mo ago
Risk Assessment

The "kandeshop-duplicate-post-manager" plugin v1.3 exhibits a generally strong security posture based on the provided static analysis. The absence of any reported CVEs or known vulnerabilities in its history is a significant positive indicator. Furthermore, the code demonstrates good practices such as 100% output escaping and a high percentage of SQL queries utilizing prepared statements. The plugin also includes nonce and capability checks, which are essential for securing entry points.

However, the analysis reveals a complete lack of any identified attack surface, including AJAX handlers, REST API routes, shortcodes, or cron events. While this could indicate a well-designed plugin with minimal user interaction points, it also means there are no entry points to assess for authentication or authorization. The fact that there are zero flows identified in the taint analysis could be due to the limited scope of the analysis or a genuine absence of complex data flows. This lack of exposed functionality, while seemingly secure, might also limit its utility or indicate a very specialized function.

In conclusion, this plugin appears to be well-coded with a focus on security best practices. The lack of historical vulnerabilities and the robust output escaping are commendable. The primary "concern," if it can be called that, is the apparent lack of any exploitable attack surface which, while good for security, is an unusual finding and warrants further investigation if the plugin is intended to perform any interactive functions. The current data suggests a low-risk plugin, but the absence of any attack surface is atypical.

Vulnerabilities
None known

Kandeshop Duplicate Post Manager Security Vulnerabilities

No known vulnerabilities — this is a good sign.
Code Analysis
Analyzed Mar 17, 2026

Kandeshop Duplicate Post Manager Code Analysis

Dangerous Functions
0
Raw SQL Queries
2
4 prepared
Unescaped Output
0
13 escaped
Nonce Checks
2
Capability Checks
1
File Operations
0
External Requests
0
Bundled Libraries
0

SQL Query Safety

67% prepared6 total queries

Output Escaping

100% escaped13 total outputs
Attack Surface

Kandeshop Duplicate Post Manager Attack Surface

Entry Points0
Unprotected0
WordPress Hooks 1
actionadmin_menudupe-post-mgr.php:13
Maintenance & Trust

Kandeshop Duplicate Post Manager Maintenance & Trust

Maintenance Signals

WordPress version tested6.8.5
Last updatedAug 30, 2025
PHP min version7.4
Downloads192

Community Trust

Rating0/100
Number of ratings0
Active installs0
Developer Profile

Kandeshop Duplicate Post Manager Developer Profile

Darren Kandekore

3 plugins · 0 total installs

94
trust score
Avg Security Score
100/100
Avg Patch Time
30 days
View full developer profile
Detection Fingerprints

How We Detect Kandeshop Duplicate Post Manager

Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.

Asset Fingerprints

Script Paths
/wp-content/plugins/kandeshop-duplicate-post-manager/js/kandeshop-duplicate-post-manager.js
Version Parameters
kandeshop-duplicate-post-manager/js/kandeshop-duplicate-post-manager.js?ver=

HTML / DOM Fingerprints

CSS Classes
dpm-check
Data Attributes
name="bulk_delete_ids[]"name="redirect_select[]"name="redirect_manual[]"
JS Globals
jQuery
FAQ

Frequently Asked Questions about Kandeshop Duplicate Post Manager