Simple clone widget Security & Risk Analysis

wordpress.org/plugins/simple-clone-widget

Simple clone widget plugin add a 'Clone this!'' link of every widget. Simply click 'Clone it!' to make a copy of the widget.

30 active installs v1.0 PHP + WP 4.1+ Updated Mar 12, 2018
cloneduplicate-widgetduplicate-widget-pluginwidget-clonewidget-duplicator
85
A · Safe
CVEs total0
Unpatched0
Last CVENever
Safety Verdict

Is Simple clone widget Safe to Use in 2026?

Generally Safe

Score 85/100

Simple clone widget has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.

No known CVEs Updated 8yr ago
Risk Assessment

The static analysis of the "simple-clone-widget" plugin v1.0 reveals an exceptionally clean codebase with no identified attack surface entry points, dangerous functions, or vulnerable code patterns such as raw SQL queries or unescaped output. Taint analysis also yielded no critical or high severity flows, indicating a strong initial security posture from a code perspective. The plugin's vulnerability history is also clean, with zero recorded CVEs, suggesting a lack of past security incidents.

However, the complete absence of nonces and capability checks across all potential, albeit zero, entry points presents a theoretical concern. While the current implementation might not necessitate these checks due to its limited functionality and attack surface, this lack of defensive programming could become a risk if the plugin's features were expanded without proper security considerations. The analysis indicates a plugin that is currently secure due to its simplicity, but it does not demonstrate robust security practices that would scale with complexity.

In conclusion, "simple-clone-widget" v1.0 appears to be a secure plugin for its current functionality, primarily due to its minimal footprint and lack of complex interactions. The absence of identified vulnerabilities or exploitable code is a significant strength. The main weakness is the lack of established security checks (nonces, capabilities) that, while not currently exploitable, could be a blind spot for future development.

Key Concerns

  • No nonce checks found
  • No capability checks found
Vulnerabilities
None known

Simple clone widget Security Vulnerabilities

No known vulnerabilities — this is a good sign.
Code Analysis
Analyzed Mar 16, 2026

Simple clone widget Code Analysis

Dangerous Functions
0
Raw SQL Queries
0
0 prepared
Unescaped Output
0
0 escaped
Nonce Checks
0
Capability Checks
0
File Operations
0
External Requests
0
Bundled Libraries
0
Attack Surface

Simple clone widget Attack Surface

Entry Points0
Unprotected0
WordPress Hooks 2
actioninitsimple-clone-widget.php:32
filteradmin_headsimple-clone-widget.php:37
Maintenance & Trust

Simple clone widget Maintenance & Trust

Maintenance Signals

WordPress version tested4.9.29
Last updatedMar 12, 2018
PHP min version
Downloads2K

Community Trust

Rating60/100
Number of ratings2
Active installs30
Developer Profile

Simple clone widget Developer Profile

Yaroslava

1 plugin · 30 total installs

84
trust score
Avg Security Score
85/100
Avg Patch Time
30 days
View full developer profile
Detection Fingerprints

How We Detect Simple clone widget

Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.

Asset Fingerprints

Asset Paths
/wp-content/plugins/simple-clone-widget/css/simple-clone-widget.css

HTML / DOM Fingerprints

CSS Classes
clone-widgetclone-widget-activeSimple-cloneablewidget-title-action
Data Attributes
data-widget-name
JS Globals
window.Simple.CloneWidgets
FAQ

Frequently Asked Questions about Simple clone widget