
Post Duplicator Plus Security & Risk Analysis
wordpress.org/plugins/post-duplicator-plusDuplicate a post or page with one click. Simple plugin. Just a few lines of code.
Is Post Duplicator Plus Safe to Use in 2026?
Generally Safe
Score 85/100Post Duplicator Plus has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.
The "post-duplicator-plus" v1.0.1 plugin exhibits an exceptionally strong security posture based on the provided static analysis and vulnerability history. The complete absence of exploitable entry points like AJAX handlers, REST API routes, and shortcodes, coupled with 100% secure coding practices in SQL queries and output escaping, indicates a highly robust development approach. The presence of a nonce check further reinforces this good practice. The plugin's vulnerability history is equally impressive, with zero recorded CVEs of any severity, suggesting a mature and well-maintained codebase that has historically avoided common security pitfalls.
While the static analysis reveals no immediate flaws, it's important to note that the analysis itself is based on the data provided. The absence of critical or high-severity taint flows, dangerous functions, file operations, or external HTTP requests further solidifies the plugin's clean bill of health. The zero recorded vulnerabilities and the lack of any common vulnerability types are significant strengths, implying a proactive approach to security throughout its development and maintenance lifecycle. This plugin, according to the data, appears to be a very safe choice for WordPress users.
In conclusion, the "post-duplicator-plus" v1.0.1 plugin demonstrates excellent security hygiene. The comprehensive static analysis shows no exploitable attack surface and adherence to secure coding standards. The clean vulnerability history is a strong indicator of ongoing security diligence. While no software is entirely risk-free, the data presented here suggests a minimal security risk associated with this plugin, highlighting its strengths in secure development and maintenance.
Post Duplicator Plus Security Vulnerabilities
Post Duplicator Plus Code Analysis
Post Duplicator Plus Attack Surface
WordPress Hooks 3
Maintenance & Trust
Post Duplicator Plus Maintenance & Trust
Maintenance Signals
Community Trust
Post Duplicator Plus Alternatives
WP Admin UI Customize
wp-admin-ui-customize
Customize the management screen UI.
LH Archived Post Status
lh-archived-post-status
Allows posts and pages to be archived so you can remove content from the main loop and feed without having to trash it.
HiFi (Head Injection, Foot Injection)
hifi
HiFi is a head and foot injection plugin. It allows you to inject code into the head and foot areas of your posts and pages on a per-page basis.
Sortable Word Count Reloaded
sortable-word-count-reloaded
Adds a sortable column to the posts and pages admin list with the word count of each page/post.
Post Category Filter (WP Admin)
admin-category-filter
Quickly search and filter categories and taxonomies inside the WordPress admin.
Post Duplicator Plus Developer Profile
3 plugins · 1K total installs
How We Detect Post Duplicator Plus
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
HTML / DOM Fingerprints
<a href=".*duplicate_post_id=[0-9]*&_wpnonce=[a-z0-9]*">Duplicate</a>