
Fast Page & Post Duplicator Security & Risk Analysis
wordpress.org/plugins/page-or-post-cloneMake a copy of posts and pages with just one click.
Is Fast Page & Post Duplicator Safe to Use in 2026?
Generally Safe
Score 98/100Fast Page & Post Duplicator has a strong security track record. Known vulnerabilities have been patched promptly.
The plugin "page-or-post-clone" v9.3 exhibits a generally strong security posture based on the static analysis, with no identified vulnerabilities in the attack surface (AJAX, REST API, shortcodes, cron) or critical taint flows. The code demonstrates good practices such as a high percentage of properly escaped output and a reasonable use of prepared statements for SQL queries. The presence of nonce and capability checks, although limited, also indicates an awareness of security principles.
However, the vulnerability history presents a significant concern. Two known medium-severity CVEs, specifically SQL Injection and Authorization Bypass, have been recorded. The fact that these are currently unpatched, despite the "last vulnerability" date being in the future (2026-03-04), suggests potential issues with the reporting or the plugin's maintenance cycle. While the current analysis shows no direct evidence of these vulnerabilities being present in v9.3, the historical pattern warrants caution. The plugin's strengths lie in its controlled attack surface and internal code hygiene; its weakness is the demonstrated susceptibility to certain vulnerability types in its past, which could resurface if not carefully managed.
In conclusion, while v9.3 appears to be clean from a static analysis perspective, the historical vulnerability data cannot be ignored. Users should be aware of the plugin's past issues and ensure they are kept updated with any future patches, even if current scans are clean. The lack of unpatched CVEs for the current version is a positive sign, but the past record necessitates continued vigilance.
Key Concerns
- Previously known SQL Injection vulnerabilities
- Previously known Authorization Bypass vulnerabilities
- SQL queries not using prepared statements (50%)
Fast Page & Post Duplicator Security Vulnerabilities
CVEs by Year
Severity Breakdown
2 total CVEs
Page and Post Clone <= 6.3 - Authenticated (Contributor+) SQL Injection via 'meta_key' Parameter
Page and Post Clone <= 6.0 - Insecure Direct Object Reference to Authenticated (Author+) Sensitive Information Exposure
Fast Page & Post Duplicator Code Analysis
SQL Query Safety
Output Escaping
Data Flow Analysis
Fast Page & Post Duplicator Attack Surface
WordPress Hooks 9
Maintenance & Trust
Fast Page & Post Duplicator Maintenance & Trust
Maintenance Signals
Community Trust
Fast Page & Post Duplicator Alternatives
Duplicate Page and Post
duplicate-wp-page-post
Duplicate post, Duplicate page and Duplicate custom post or clone page and clone post.
WP Post Page Clone
wp-post-page-clone
Clone Post or Page with it's contents and settings in just one click.
WP Duplicate Page
wp-duplicate-page
Clone WordPress page, post, custom post types
Clone Posts
clone-posts
Easily clone (duplicate) Posts, Pages and Custom Post Types, including their custom fields (post_meta)
Duplicate Page or Post
duplicate-page-or-post
Duplicate Page or Post is an great tool that allow to duplicate pages and posts. Now you can do it in one click.
Fast Page & Post Duplicator Developer Profile
1 plugin · 60K total installs
How We Detect Fast Page & Post Duplicator
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/page-or-post-clone/assets/css/admin.css/wp-content/plugins/page-or-post-clone/assets/js/admin.jspage-or-post-clone/assets/css/admin.css?ver=page-or-post-clone/assets/js/admin.js?ver=HTML / DOM Fingerprints
cf-donation-modern-noticecf-donation-innercf-donation-imagecf-donation-text