
WP Clone any post type Security & Risk Analysis
wordpress.org/plugins/wp-clone-any-post-typeCloning posts, pages and custom post types in WordPress.
Is WP Clone any post type Safe to Use in 2026?
Use With Caution
Score 58/100WP Clone any post type has 2 unpatched vulnerabilities. Evaluate alternatives or apply available mitigations.
The "wp-clone-any-post-type" v3.6 plugin exhibits a mixed security posture. While it demonstrates good practices in avoiding dangerous functions and SQL injection vulnerabilities by using prepared statements, significant concerns arise from its attack surface. The presence of four AJAX handlers, all of which lack authentication checks, creates a considerable risk of unauthorized access and manipulation of plugin functionalities.
Taint analysis reveals flows with unsanitized paths, although no critical or high-severity issues were flagged in this specific analysis. However, the plugin's vulnerability history is a major red flag. With two known CVEs, both currently unpatched and classified as medium severity, and past vulnerabilities including 'Open Redirect' and 'Missing Authorization,' there's a clear pattern of authorization and input validation weaknesses. The most recent vulnerability from April 2025 further emphasizes the ongoing nature of these security flaws.
In conclusion, while the plugin's internal code hygiene for SQL and dangerous functions is commendable, the lack of authentication on critical entry points and a history of unpatched, authorization-related vulnerabilities make it a high-risk plugin. Users should exercise extreme caution and consider alternatives until these issues are addressed.
Key Concerns
- Unprotected AJAX handlers
- Unpatched CVEs (2 medium)
- Flows with unsanitized paths
- Low output escaping percentage
WP Clone any post type Security Vulnerabilities
CVEs by Year
Severity Breakdown
2 total CVEs
WP Clone any post type <= 3.5 - Open Redirect
WP Clone any post type <= 3.6 - Missing Authorization
WP Clone any post type Code Analysis
Output Escaping
Data Flow Analysis
WP Clone any post type Attack Surface
AJAX Handlers 4
WordPress Hooks 22
Maintenance & Trust
WP Clone any post type Maintenance & Trust
Maintenance Signals
Community Trust
WP Clone any post type Alternatives
Duplicate Post
copy-delete-posts
Duplicate post
Duplicate Post – duplicate pages, copy content, clone posts
duplicate-post-rb
Duplicate Post RB makes it easy to duplicate posts, pages and custom post types. Create duplicate posts, clone content, automate duplication
Quick Copy – Duplicate Posts & Pages
duplicator-post-page
Easily duplicate any post or page, including all metadata and taxonomies, with just one click.
WP Duplicate Posts And Pages
wp-duplicate-posts-and-pages
License: GPLv2 or later Duplicate posts and pages, including custom post types.
Easy Post Duplicator
easy-post-duplicator
Plugin duplicates the posts, pages all at once based on the post type,post status and even year of posts created.
WP Clone any post type Developer Profile
40 plugins · 25K total installs
How We Detect WP Clone any post type
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/wp-clone-any-post-type/includes/css/wp-clone-any-post-type-style.css/wp-content/plugins/wp-clone-any-post-type/includes/js/wp-clone-any-post-type-main.js/wp-content/plugins/wp-clone-any-post-type/includes/js/wp-clone-any-post-type-main.jswp-clone-any-post-type/includes/css/wp-clone-any-post-type-style.css?ver=wp-clone-any-post-type/includes/js/wp-clone-any-post-type-main.js?ver=HTML / DOM Fingerprints
wp_any_posts_clone_noticewcapt_clone_post_typeswpclone_ajax_object