
Theme Duplicator Security & Risk Analysis
wordpress.org/plugins/theme-duplicatorThis plugin creates a duplicate copy of you selected theme.
Is Theme Duplicator Safe to Use in 2026?
Mostly Safe
Score 71/100Theme Duplicator is generally safe to use though it hasn't been updated recently. 1 past CVE were resolved.
The theme-duplicator plugin v1.1 exhibits a mixed security posture. On the positive side, the static analysis reveals no identified dangerous functions, a complete reliance on prepared statements for SQL queries, and no external HTTP requests. This indicates some good development practices. However, there are significant areas of concern. The taint analysis shows two flows with unsanitized paths, which, while not flagged as critical or high severity, represent potential vulnerabilities that could lead to unintended data manipulation or disclosure if exploited. Furthermore, the complete absence of nonce checks and capability checks across all entry points is a major weakness, leaving the plugin susceptible to various attacks, particularly CSRF, as suggested by its vulnerability history.
The vulnerability history is a critical indicator of ongoing security issues. With one known CVE, currently unpatched and categorized as medium severity, and a history of common CSRF vulnerabilities, it suggests a pattern of insecure coding practices that have resulted in exploitable flaws. The fact that the last vulnerability was dated as recent (2025-04-01) further amplifies the risk. While the plugin avoids some common pitfalls like raw SQL and has a limited attack surface, the identified unsanitized paths and the complete lack of robust authorization and integrity checks, coupled with a recent unpatched vulnerability, make this plugin a significant security risk that requires immediate attention.
Key Concerns
- Unpatched medium severity CVE
- Taint analysis: 2 flows with unsanitized paths
- No nonce checks implemented
- No capability checks implemented
- Output escaping only 67% proper
Theme Duplicator Security Vulnerabilities
CVEs by Year
Severity Breakdown
1 total CVE
Theme Duplicator <= 1.1 - Cross-Site Request Forgery
Theme Duplicator Code Analysis
Output Escaping
Data Flow Analysis
Theme Duplicator Attack Surface
WordPress Hooks 1
Maintenance & Trust
Theme Duplicator Maintenance & Trust
Maintenance Signals
Community Trust
Theme Duplicator Alternatives
Simple Social Icons
simple-social-icons
This plugin provides two ways to display social icons: a traditional widget (available on all WordPress versions) and block variations for the core So …
BuddyPress
buddypress
Get together safely, in your own way, in WordPress.
Fast Page & Post Duplicator
page-or-post-clone
Make a copy of posts and pages with just one click.
Lightweight Social Icons
lightweight-social-icons
Looking to add simple social icons to your widget areas? Choose the size and color of your icons, and then choose from 47 different social profiles.
Hubbub Lite – Fast, free social sharing and follow buttons
social-pug
Your content is worth sharing. Let's makes it easier!
Theme Duplicator Developer Profile
1 plugin · 400 total installs
How We Detect Theme Duplicator
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/theme-duplicator/theme-duplicator.phpHTML / DOM Fingerprints
name="td_source_theme"name="td_dest_theme"name="td_new_name"name="td_create_theme"