
Labinator Content Types Duplicator Security & Risk Analysis
wordpress.org/plugins/labinator-content-types-duplicatorDuplicate posts, pages, widgets, menus, and any content types with one click. Copy or clone your content without limitations. It is 100% free!
Is Labinator Content Types Duplicator Safe to Use in 2026?
Mostly Safe
Score 71/100Labinator Content Types Duplicator is generally safe to use though it hasn't been updated recently. 1 past CVE were resolved.
The "labinator-content-types-duplicator" plugin, version 1.1.3, exhibits a mixed security posture. On the positive side, the plugin demonstrates good practices by utilizing prepared statements for all SQL queries and including nonce and capability checks. The absence of a large attack surface through AJAX handlers, REST API routes, shortcodes, or cron events is also a strength, indicating a potentially more contained codebase.
However, several concerns warrant attention. The taint analysis reveals a high severity flow with unsanitized paths, posing a potential risk if this flow leads to an exploitable condition. Furthermore, the plugin has a history of vulnerabilities, including a medium severity CVE that is currently unpatched, and a past CSRF vulnerability. While the current version appears to have addressed some historical issues, the presence of an unpatched vulnerability and the previous occurrence of CSRF suggest a need for ongoing vigilance and prompt patching. The code also shows a significant percentage of improperly escaped output, which could lead to Cross-Site Scripting (XSS) vulnerabilities if user-supplied data is involved in these outputs.
In conclusion, while the plugin has made efforts to secure its code by using prepared statements and performing capability checks, the identified high severity taint flow, unpatched CVE, and a history of CSRF vulnerabilities indicate areas of significant risk. The improper output escaping further compounds these concerns. Users should be cautious and prioritize updating to a patched version if available, and the developers should address the identified taint flow and output escaping issues.
Key Concerns
- Unpatched medium severity CVE
- High severity taint flow with unsanitized paths
- Significant percentage of unescaped output
- History of CSRF vulnerability
Labinator Content Types Duplicator Security Vulnerabilities
CVEs by Year
Severity Breakdown
1 total CVE
Labinator Content Types Duplicator <= 1.1.3 - Cross-Site Request Forgery
Labinator Content Types Duplicator Release Timeline
Labinator Content Types Duplicator Code Analysis
SQL Query Safety
Output Escaping
Data Flow Analysis
Labinator Content Types Duplicator Attack Surface
WordPress Hooks 46
Maintenance & Trust
Labinator Content Types Duplicator Maintenance & Trust
Maintenance Signals
Community Trust
Labinator Content Types Duplicator Alternatives
Clone Posts
clone-posts
Easily clone (duplicate) Posts, Pages and Custom Post Types, including their custom fields (post_meta)
DupZap
dupzap
Clone posts, pages, and custom post types with one click. Lightweight and intuitive!
Duplicate Post
copy-delete-posts
Duplicate post
Duplicate Post – duplicate pages, copy content, clone posts
duplicate-post-rb
Duplicate Post RB makes it easy to duplicate posts, pages and custom post types. Create duplicate posts, clone content, automate duplication
Quick Copy – Duplicate Posts & Pages
duplicator-post-page
Easily duplicate any post or page, including all metadata and taxonomies, with just one click.
Labinator Content Types Duplicator Developer Profile
3 plugins · 900 total installs
How We Detect Labinator Content Types Duplicator
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/labinator-content-types-duplicator/assets/css/labinator-content-types-duplicator.css/wp-content/plugins/labinator-content-types-duplicator/assets/js/labinator-content-types-duplicator.js/wp-content/plugins/labinator-content-types-duplicator/assets/js/lct-duplicator-widgets.js/wp-content/plugins/labinator-content-types-duplicator/assets/js/labinator-content-types-duplicator.js/wp-content/plugins/labinator-content-types-duplicator/assets/js/lct-duplicator-widgets.jslabinator-content-types-duplicator/style.css?ver=labinator-content-types-duplicator/script.js?ver=HTML / DOM Fingerprints
lct_duplicator_duplicate_buttonAdded by WarmStalLCT_DUPLICATOR_AJAX_URLLCT_DUPLICATOR_POST_IDLCT_DUPLICATOR_IS_ADMIN