
WP Duplicate posts pages & CPT Security & Risk Analysis
wordpress.org/plugins/wp-duplicate-posts-pages-cptDuplicate posts, pages and CPT with all custom data.
Is WP Duplicate posts pages & CPT Safe to Use in 2026?
Generally Safe
Score 85/100WP Duplicate posts pages & CPT has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.
The static analysis of wp-duplicate-posts-pages-cpt v1.0 reveals a strong security posture with no identified critical or high-risk code signals. The absence of dangerous functions, SQL injection vulnerabilities (all queries use prepared statements), and unsanitized taint flows is commendable. Furthermore, all identified output points are properly escaped, mitigating cross-site scripting risks. The plugin also demonstrates good practice by utilizing capability checks for its entry points.
However, a significant concern arises from the complete lack of nonce checks, particularly in conjunction with the presence of capability checks. While capability checks ensure that only authenticated users with sufficient privileges can access certain functions, the absence of nonces leaves these endpoints vulnerable to Cross-Site Request Forgery (CSRF) attacks. An attacker could trick a logged-in administrator into triggering an unintended action by simply crafting a malicious link or form. The vulnerability history, showing no known CVEs, is a positive sign, suggesting a generally well-maintained codebase. Nevertheless, the potential CSRF vulnerability, though not reflected in the CVE history, warrants attention.
In conclusion, wp-duplicate-posts-pages-cpt v1.0 exhibits excellent practices regarding data sanitization and SQL security. Its vulnerability history is clean, which is a strong indicator of diligent development. The primary weakness identified is the lack of CSRF protection due to missing nonce checks on its protected entry points, which presents a moderate risk that should be addressed.
Key Concerns
- Missing nonce checks on entry points
WP Duplicate posts pages & CPT Security Vulnerabilities
WP Duplicate posts pages & CPT Release Timeline
WP Duplicate posts pages & CPT Code Analysis
Output Escaping
WP Duplicate posts pages & CPT Attack Surface
WordPress Hooks 3
Maintenance & Trust
WP Duplicate posts pages & CPT Maintenance & Trust
Maintenance Signals
Community Trust
WP Duplicate posts pages & CPT Alternatives
Duplicate Post
copy-delete-posts
Duplicate post
Clone Posts
clone-posts
Easily clone (duplicate) Posts, Pages and Custom Post Types, including their custom fields (post_meta)
Duplicate Post – duplicate pages, copy content, clone posts
duplicate-post-rb
Duplicate Post RB makes it easy to duplicate posts, pages and custom post types. Create duplicate posts, clone content, automate duplication
Quick Copy – Duplicate Posts & Pages
duplicator-post-page
Easily duplicate any post or page, including all metadata and taxonomies, with just one click.
Labinator Content Types Duplicator
labinator-content-types-duplicator
Duplicate posts, pages, widgets, menus, and any content types with one click. Copy or clone your content without limitations. It is 100% free!
WP Duplicate posts pages & CPT Developer Profile
2 plugins · 110 total installs
How We Detect WP Duplicate posts pages & CPT
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/wp-duplicate-posts-pages-cpt/HTML / DOM Fingerprints
duplicate