Super SEO Content Cloner Security & Risk Analysis

wordpress.org/plugins/super-seo-content-cloner

Quickly duplicate posts/pages with built‑in Find & Replace, or bulk‑create new posts from a CSV/TXT keyword list. Fast, safe, and SEO‑friendly.

200 active installs v1.0.3 PHP 6.2+ WP 4.4.0+ Updated Mar 13, 2026
bulk-post-generatorclone-wordpress-contentduplicate-pageduplicate-postwoocommerce-product-duplicator
99
A · Safe
CVEs total1
Unpatched0
Last CVEJan 31, 2025
Safety Verdict

Is Super SEO Content Cloner Safe to Use in 2026?

Generally Safe

Score 99/100

Super SEO Content Cloner has a strong security track record. Known vulnerabilities have been patched promptly. It's a solid choice for most WordPress installations.

1 known CVELast CVE: Jan 31, 2025Updated 2mo ago
Risk Assessment

The "super-seo-content-cloner" plugin exhibits a generally good security posture, with several positive indicators. The absence of critical or high-severity vulnerabilities in the code analysis and taint flow, combined with the use of prepared statements for all SQL queries and a high percentage of properly escaped output, suggests a solid development practice. The presence of nonce and capability checks on all identified entry points further strengthens its security. The plugin's vulnerability history, while showing one medium-severity issue in the past, is currently unpatched, indicating a proactive approach to fixing reported problems. The fact that there are no currently unpatched vulnerabilities is a strong positive sign.

However, there are minor areas for consideration. The plugin utilizes a bundled library, Select2, which could potentially be a vector for vulnerabilities if it's an outdated version. While no specific issues were flagged in the static analysis regarding this, it's a general security practice to keep bundled libraries up-to-date. The single external HTTP request, while not inherently risky without further context, is an entry point for potential external manipulation or data leakage if not handled with extreme care and validation. Overall, the plugin appears to be relatively secure, with a focus on standard security best practices, but vigilance regarding bundled libraries and external interactions would be prudent.

Key Concerns

  • Bundled library (Select2)
  • External HTTP request
Vulnerabilities
1 published

Super SEO Content Cloner Security Vulnerabilities

CVEs by Year

1 CVE in 2025
2025
Patched Has unpatched

Severity Breakdown

Medium
1

1 total CVE

CVE-2025-22681medium · 5.3Missing Authorization

Content Cloner <= 1.0.1 - Missing Authorization

Jan 31, 2025 Patched in 1.0.2 (4d)
Version History

Super SEO Content Cloner Release Timeline

v1.0.3Current
v1.0.2
v1.0.11 CVE
v1.0.01 CVE
Code Analysis
Analyzed Mar 16, 2026

Super SEO Content Cloner Code Analysis

Dangerous Functions
0
Raw SQL Queries
0
0 prepared
Unescaped Output
4
43 escaped
Nonce Checks
5
Capability Checks
4
File Operations
0
External Requests
1
Bundled Libraries
1

Bundled Libraries

Select2

Output Escaping

91% escaped47 total outputs
Attack Surface

Super SEO Content Cloner Attack Surface

Entry Points4
Unprotected0

AJAX Handlers 4

authwp_ajax_xsspd_load_duplicator_modalincludes\class-xsspd-main.php:50
authwp_ajax_xsspd_load_new_accordinincludes\class-xsspd-main.php:53
authwp_ajax_xsspd_process_duplicationincludes\class-xsspd-main.php:56
authwp_ajax_xsspd_send_mailincludes\class-xsspd-main.php:73
WordPress Hooks 9
actionadmin_enqueue_scriptsincludes\class-xsspd-main.php:59
actionwp_before_admin_bar_renderincludes\class-xsspd-main.php:63
actionadd_meta_boxesincludes\class-xsspd-main.php:65
filterplugin_action_linksincludes\class-xsspd.php:36
actioninitincludes\class-xsspd.php:37
actioninitincludes\class-xsspd.php:38
actionadmin_menuincludes\class-xsspd.php:39
actionadmin_initsuper-seo-content-cloner.php:93
actionadmin_noticessuper-seo-content-cloner.php:110
Maintenance & Trust

Super SEO Content Cloner Maintenance & Trust

Maintenance Signals

WordPress version tested6.9.4
Last updatedMar 13, 2026
PHP min version6.2
Downloads3K

Community Trust

Rating100/100
Number of ratings1
Active installs200
Developer Profile

Super SEO Content Cloner Developer Profile

Xfinitysoft

9 plugins · 4K total installs

99
trust score
Avg Security Score
98/100
Avg Patch Time
6 days
View full developer profile
Detection Fingerprints

How We Detect Super SEO Content Cloner

Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.

Asset Fingerprints

Asset Paths
/wp-content/plugins/super-seo-content-cloner/assets/css/xsspd-admin-style.css/wp-content/plugins/super-seo-content-cloner/assets/css/select2.min.css/wp-content/plugins/super-seo-content-cloner/assets/js/xsspd-admin-script.js/wp-content/plugins/super-seo-content-cloner/assets/js/select2.full.min.js/wp-content/plugins/super-seo-content-cloner/assets/css/xsspd-support.css/wp-content/plugins/super-seo-content-cloner/assets/js/xsspd-support.js
Version Parameters
super-seo-content-cloner/assets/css/select2.min.css?ver=super-seo-content-cloner/assets/css/xsspd-admin-style.css?ver=super-seo-content-cloner/assets/js/select2.full.min.js?ver=super-seo-content-cloner/assets/js/xsspd-admin-script.js?ver=time()super-seo-content-cloner/assets/css/xsspd-support.css?ver=super-seo-content-cloner/assets/js/xsspd-support.js?ver=

HTML / DOM Fingerprints

CSS Classes
xsspd_spinnerxsspd_duplicate
Data Attributes
data-post-id
JS Globals
xsspd_script_var
REST Endpoints
/wp-json/xsspd/v1/process-duplication
FAQ

Frequently Asked Questions about Super SEO Content Cloner