Fast Page & Post Duplicator Security & Risk Analysis

wordpress.org/plugins/page-or-post-clone

Make a copy of posts and pages with just one click.

60K active installs v9.3 PHP 5.6+ WP 4.5+ Updated Mar 6, 2026
clone-pageclone-postduplicate-postpagepost-duplicator
98
A · Safe
CVEs total2
Unpatched0
Last CVEMar 4, 2026
Safety Verdict

Is Fast Page & Post Duplicator Safe to Use in 2026?

Generally Safe

Score 98/100

Fast Page & Post Duplicator has a strong security track record. Known vulnerabilities have been patched promptly.

2 known CVEsLast CVE: Mar 4, 2026Updated 28d ago
Risk Assessment

The plugin "page-or-post-clone" v9.3 exhibits a generally strong security posture based on the static analysis, with no identified vulnerabilities in the attack surface (AJAX, REST API, shortcodes, cron) or critical taint flows. The code demonstrates good practices such as a high percentage of properly escaped output and a reasonable use of prepared statements for SQL queries. The presence of nonce and capability checks, although limited, also indicates an awareness of security principles.

However, the vulnerability history presents a significant concern. Two known medium-severity CVEs, specifically SQL Injection and Authorization Bypass, have been recorded. The fact that these are currently unpatched, despite the "last vulnerability" date being in the future (2026-03-04), suggests potential issues with the reporting or the plugin's maintenance cycle. While the current analysis shows no direct evidence of these vulnerabilities being present in v9.3, the historical pattern warrants caution. The plugin's strengths lie in its controlled attack surface and internal code hygiene; its weakness is the demonstrated susceptibility to certain vulnerability types in its past, which could resurface if not carefully managed.

In conclusion, while v9.3 appears to be clean from a static analysis perspective, the historical vulnerability data cannot be ignored. Users should be aware of the plugin's past issues and ensure they are kept updated with any future patches, even if current scans are clean. The lack of unpatched CVEs for the current version is a positive sign, but the past record necessitates continued vigilance.

Key Concerns

  • Previously known SQL Injection vulnerabilities
  • Previously known Authorization Bypass vulnerabilities
  • SQL queries not using prepared statements (50%)
Vulnerabilities
2

Fast Page & Post Duplicator Security Vulnerabilities

CVEs by Year

1 CVE in 2024
2024
1 CVE in 2026
2026
Patched Has unpatched

Severity Breakdown

Medium
2

2 total CVEs

CVE-2026-2893medium · 6.5Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')

Page and Post Clone <= 6.3 - Authenticated (Contributor+) SQL Injection via 'meta_key' Parameter

Mar 4, 2026 Patched in 6.4 (1d)
CVE-2024-5942medium · 4.3Authorization Bypass Through User-Controlled Key

Page and Post Clone <= 6.0 - Insecure Direct Object Reference to Authenticated (Author+) Sensitive Information Exposure

Jun 28, 2024 Patched in 6.1 (1d)
Code Analysis
Analyzed Mar 16, 2026

Fast Page & Post Duplicator Code Analysis

Dangerous Functions
0
Raw SQL Queries
4
4 prepared
Unescaped Output
1
11 escaped
Nonce Checks
1
Capability Checks
2
File Operations
0
External Requests
0
Bundled Libraries
0

SQL Query Safety

50% prepared8 total queries

Output Escaping

92% escaped12 total outputs
Data Flows
All sanitized

Data Flow Analysis

2 flows
content_clone (page-or-post-clone.php:78)
Source (user input) Sink (dangerous op) Sanitizer Transform Unsanitized Sanitized
Attack Surface

Fast Page & Post Duplicator Attack Surface

Entry Points0
Unprotected0
WordPress Hooks 9
actionplugins_loadedpage-or-post-clone.php:61
actionadmin_action_content_clonepage-or-post-clone.php:181
filterpost_row_actionspage-or-post-clone.php:198
filterpage_row_actionspage-or-post-clone.php:199
actionadmin_footerpage-or-post-clone.php:258
actionadmin_menupage-or-post-clone.php:274
actionadmin_enqueue_scriptspage-or-post-clone.php:413
actionadmin_enqueue_scriptspage-or-post-clone.php:439
filterplugin_row_metapage-or-post-clone.php:453
Maintenance & Trust

Fast Page & Post Duplicator Maintenance & Trust

Maintenance Signals

WordPress version tested6.7.5
Last updatedMar 6, 2026
PHP min version5.6
Downloads620K

Community Trust

Rating94/100
Number of ratings13
Active installs60K
Developer Profile

Fast Page & Post Duplicator Developer Profile

carlosfazenda

1 plugin · 60K total installs

99
trust score
Avg Security Score
98/100
Avg Patch Time
1 days
View full developer profile
Detection Fingerprints

How We Detect Fast Page & Post Duplicator

Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.

Asset Fingerprints

Asset Paths
/wp-content/plugins/page-or-post-clone/assets/css/admin.css/wp-content/plugins/page-or-post-clone/assets/js/admin.js
Version Parameters
page-or-post-clone/assets/css/admin.css?ver=page-or-post-clone/assets/js/admin.js?ver=

HTML / DOM Fingerprints

CSS Classes
cf-donation-modern-noticecf-donation-innercf-donation-imagecf-donation-text
FAQ

Frequently Asked Questions about Fast Page & Post Duplicator