
Multisite Cloner Security & Risk Analysis
wordpress.org/plugins/multisite-clonerWhen creating a new blog on WordPress Multisite, copies all the posts, settings and files, from a selected blog into the new one.
Is Multisite Cloner Safe to Use in 2026?
Generally Safe
Score 85/100Multisite Cloner has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.
The multisite-cloner plugin v0.2.2.1 exhibits a mixed security posture. While the static analysis indicates a very small attack surface with zero identified entry points and no external HTTP requests, several concerning code signals raise red flags. The presence of the dangerous `unserialize` function, coupled with 2 high-severity taint flows with unsanitized paths, points to a significant potential for remote code execution or data manipulation if these flows can be triggered by an attacker. The limited output escaping (22% proper) further exacerbates this risk, as sensitive data could be exposed. Notably, the plugin has no recorded vulnerability history, which might suggest it has not been widely targeted or thoroughly audited. However, this lack of history should not be interpreted as a guarantee of absolute security, especially given the identified code weaknesses. The absence of nonce and capability checks on any potential implicit entry points (even though none are explicitly listed in the attack surface) is also a concern that could be exploited if functionality is discovered that bypasses the listed entry points.
Key Concerns
- High severity taint flows found
- Unsanitized paths in taint flows
- Dangerous unserialize function used
- Low percentage of properly escaped output
- No capability checks implemented
- No nonce checks implemented
Multisite Cloner Security Vulnerabilities
Multisite Cloner Code Analysis
Dangerous Functions Found
SQL Query Safety
Output Escaping
Data Flow Analysis
Multisite Cloner Attack Surface
WordPress Hooks 6
Maintenance & Trust
Multisite Cloner Maintenance & Trust
Maintenance Signals
Community Trust
Multisite Cloner Alternatives
Yoast Duplicate Post
duplicate-post
The go-to tool for cloning posts and pages, including the powerful Rewrite & Republish feature.
Migrate Guru – Site Migration & Cloning
migrate-guru
Effortlessly migrate, clone, or transfer your WordPress site to over 5,000 web hosts with Migrate Guru, trusted by Cloudways, Pantheon, and Dreamhost.
Duplicate Menu
duplicate-menu
Easily duplicate your WordPress menus with one click.
WP Duplicate Page
wp-duplicate-page
Clone WordPress page, post, custom post types
Clone Posts
clone-posts
Easily clone (duplicate) Posts, Pages and Custom Post Types, including their custom fields (post_meta)
Multisite Cloner Developer Profile
2 plugins · 110 total installs
How We Detect Multisite Cloner
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/multisite-cloner/css/settings.css/wp-content/plugins/multisite-cloner/js/settings.js/wp-content/plugins/multisite-cloner/js/settings.jsmultisite-cloner/css/settings.css?ver=multisite-cloner/js/settings.js?ver=HTML / DOM Fingerprints
settings_page_wp_mu_clone_settings Copyright 2014 Tipit.net (email: manuel@tipit.net)data-cloner-source-blogdata-cloner-dest-blogdata-cloner-source-iddata-cloner-dest-idmultisite_cloner_var