CMP – Coming Soon & Maintenance Plugin by NiteoThemes Security & Risk Analysis

wordpress.org/plugins/cmp-coming-soon-maintenance

Beautiful Coming soon, Maintenance or Landing page on your website, packed with premium features for free.

200K active installs v4.1.16 PHP 5.6+ WP 3.0+ Updated Dec 2, 2025
coming-sooncoming-soon-pagelaunch-pagemaintenance-modeunder-construction
91
A · Safe
CVEs total6
Unpatched0
Last CVEApr 4, 2025
Safety Verdict

Is CMP – Coming Soon & Maintenance Plugin by NiteoThemes Safe to Use in 2026?

Generally Safe

Score 91/100

CMP – Coming Soon & Maintenance Plugin by NiteoThemes has a strong security track record. Known vulnerabilities have been patched promptly.

6 known CVEsLast CVE: Apr 4, 2025Updated 4mo ago
Risk Assessment

The "cmp-coming-soon-maintenance" v4.1.16 plugin presents a mixed security posture. On the positive side, the static analysis indicates a good effort in implementing security checks, with all AJAX handlers and REST API routes appearing to have authorization checks, and a high percentage of output escaping. The presence of numerous nonce and capability checks also suggests a developer mindful of WordPress security best practices. However, significant concerns arise from the analysis of SQL queries and taint flows. The complete lack of prepared statements for all three SQL queries is a major red flag, potentially exposing the site to SQL injection vulnerabilities. Furthermore, 13 flows with unsanitized paths detected in the taint analysis, despite no reported critical or high severity issues, suggest a potential for path traversal or file inclusion vulnerabilities that may not have been fully exposed or exploited in the analyzed context. The plugin's vulnerability history is also a significant concern. With a total of 6 known CVEs, including 2 high severity and 4 medium severity vulnerabilities, even though none are currently unpatched, it points to a history of security weaknesses. The common vulnerability types like Unrestricted Upload, SSRF, Improper Access Control, and Missing Authorization indicate recurring issues that require careful monitoring. While the current version appears to have addressed past CVEs and has a protected attack surface, the inherent risks from the SQL query practices and taint flow results, combined with its past vulnerability record, necessitate a cautious approach. The bundling of Select2 also warrants a check for its version and any known vulnerabilities.

Key Concerns

  • All SQL queries lack prepared statements
  • 13 taint flows with unsanitized paths
  • History of 6 known CVEs (2 high, 4 medium)
  • Bundled library: Select2
Vulnerabilities
6

CMP – Coming Soon & Maintenance Plugin by NiteoThemes Security Vulnerabilities

CVEs by Year

1 CVE in 2020
2020
1 CVE in 2022
2022
2 CVEs in 2023
2023
1 CVE in 2024
2024
1 CVE in 2025
2025
Patched Has unpatched

Severity Breakdown

High
2
Medium
4

6 total CVEs

CVE-2025-32118high · 7.2Unrestricted Upload of File with Dangerous Type

CMP – Coming Soon & Maintenance <= 4.1.13 - Authenticated (Admin+) Arbitrary File Upload

Apr 4, 2025 Patched in 4.1.15 (27d)
CVE-2023-50374medium · 5.5Server-Side Request Forgery (SSRF)

CMP – Coming Soon & Maintenance <= 4.1.10 - Authenticated (Admin+) Server-Side Request Forgery

Mar 27, 2024 Patched in 4.1.11 (8d)
CVE-2023-2159medium · 5.3Improper Access Control

CMP – Coming Soon & Maintenance <= 4.1.7 - Maintenance Mode Bypass

Apr 18, 2023 Patched in 4.1.8 (280d)
CVE-2023-1263medium · 5.3Exposure of Sensitive Information to an Unauthorized Actor

CMP – Coming Soon & Maintenance Plugin by NiteoThemes <= 4.1.6 - Information Exposure

Mar 7, 2023 Patched in 4.1.7 (322d)
CVE-2022-0188medium · 5.3Missing Authorization

CMP - Coming Soon & Maintenance Plugin <= 4.0.18 - Unauthenticated Arbitrary CSS Update

Jan 17, 2022 Patched in 4.0.19 (736d)
CVE-2020-36730high · 8.3Missing Authorization

CMP <= 3.8.1 - Missing Authorization

Aug 4, 2020 Patched in 3.8.2 (1267d)
Code Analysis
Analyzed Mar 16, 2026

CMP – Coming Soon & Maintenance Plugin by NiteoThemes Code Analysis

Dangerous Functions
0
Raw SQL Queries
3
0 prepared
Unescaped Output
222
986 escaped
Nonce Checks
27
Capability Checks
26
File Operations
5
External Requests
5
Bundled Libraries
1

Bundled Libraries

Select2

SQL Query Safety

0% prepared3 total queries

Output Escaping

82% escaped1208 total outputs
Data Flows
13 unsanitized

Data Flow Analysis

25 flows13 with unsanitized paths
niteo_unsplash (niteo-cmp.php:1524)
Source (user input) Sink (dangerous op) Sanitizer Transform Unsanitized Sanitized
Attack Surface

CMP – Coming Soon & Maintenance Plugin by NiteoThemes Attack Surface

Entry Points16
Unprotected0

AJAX Handlers 16

authwp_ajax_cmp_get_post_detailniteo-cmp.php:98
noprivwp_ajax_cmp_get_post_detailniteo-cmp.php:99
authwp_ajax_cmp_check_updateniteo-cmp.php:100
authwp_ajax_cmp_ajax_dismiss_activation_noticeniteo-cmp.php:101
authwp_ajax_niteo_themeinfoniteo-cmp.php:102
authwp_ajax_niteo_unsplashniteo-cmp.php:103
authwp_ajax_niteo_export_csvniteo-cmp.php:104
authwp_ajax_cmp_theme_update_installniteo-cmp.php:105
authwp_ajax_cmp_toggle_activationniteo-cmp.php:106
noprivwp_ajax_niteo_subscribeniteo-cmp.php:107
authwp_ajax_niteo_subscribeniteo-cmp.php:108
authwp_ajax_cmp_mailchimp_list_ajaxniteo-cmp.php:109
authwp_ajax_cmp_ajax_upload_fontniteo-cmp.php:110
authwp_ajax_cmp_ajax_export_settingsniteo-cmp.php:111
authwp_ajax_cmp_ajax_import_settingsniteo-cmp.php:112
noprivwp_ajax_cmp_disable_comingsoon_ajaxniteo-cmp.php:113
WordPress Hooks 22
actionadmin_initinc\class-cmp-feedback.php:53
actionadmin_initinc\class-cmp-feedback.php:54
actionadmin_noticesinc\class-cmp-feedback.php:128
actioninitniteo-cmp.php:88
actionplugins_loadedniteo-cmp.php:89
actiontemplate_redirectniteo-cmp.php:90
actionadmin_initniteo-cmp.php:91
actionadmin_menuniteo-cmp.php:92
actionadmin_noticesniteo-cmp.php:93
actionwp_before_admin_bar_renderniteo-cmp.php:94
actionadmin_enqueue_scriptsniteo-cmp.php:95
actionadmin_enqueue_scriptsniteo-cmp.php:96
actionwp_enqueue_scriptsniteo-cmp.php:97
actionadmin_headniteo-cmp.php:114
actionafter_setup_themeniteo-cmp.php:115
actionafter_setup_themeniteo-cmp.php:116
filterupload_mimesniteo-cmp.php:117
filterrest_authentication_errorsniteo-cmp.php:126
actioninitniteo-cmp.php:129
filterupload_mimesniteo-cmp.php:1351
filterupload_mimesniteo-cmp.php:1409
actioncmp_footerniteo-cmp.php:3229
Maintenance & Trust

CMP – Coming Soon & Maintenance Plugin by NiteoThemes Maintenance & Trust

Maintenance Signals

WordPress version tested6.7.5
Last updatedDec 2, 2025
PHP min version5.6
Downloads6.1M

Community Trust

Rating94/100
Number of ratings323
Active installs200K
Developer Profile

CMP – Coming Soon & Maintenance Plugin by NiteoThemes Developer Profile

NiteoThemes

9 plugins · 221K total installs

68
trust score
Avg Security Score
84/100
Avg Patch Time
440 days
View full developer profile
Detection Fingerprints

How We Detect CMP – Coming Soon & Maintenance Plugin by NiteoThemes

Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.

Asset Fingerprints

Asset Paths
/wp-content/plugins/cmp-coming-soon-maintenance/assets/css/coming-soon.css/wp-content/plugins/cmp-coming-soon-maintenance/assets/css/coming-soon-responsive.css/wp-content/plugins/cmp-coming-soon-maintenance/assets/css/animate.min.css/wp-content/plugins/cmp-coming-soon-maintenance/assets/css/magnific-popup.css/wp-content/plugins/cmp-coming-soon-maintenance/assets/css/owl.carousel.min.css/wp-content/plugins/cmp-coming-soon-maintenance/assets/css/owl.theme.default.min.css/wp-content/plugins/cmp-coming-soon-maintenance/assets/css/owl.transitions.css/wp-content/plugins/cmp-coming-soon-maintenance/assets/css/colorpicker.css+10 more
Generator Patterns
CMP Coming Soon & Maintenance by NiteoThemes
Script Paths
/wp-content/plugins/cmp-coming-soon-maintenance/assets/js/coming-soon.js/wp-content/plugins/cmp-coming-soon-maintenance/assets/js/colorpicker.js/wp-content/plugins/cmp-coming-soon-maintenance/assets/js/jquery.plugin.min.js/wp-content/plugins/cmp-coming-soon-maintenance/assets/js/jquery.countdown.min.js/wp-content/plugins/cmp-coming-soon-maintenance/assets/js/jquery.magnific-popup.min.js/wp-content/plugins/cmp-coming-soon-maintenance/assets/js/owl.carousel.min.js+4 more
Version Parameters
cmp-coming-soon-maintenance/assets/css/coming-soon.css?ver=cmp-coming-soon-maintenance/assets/css/coming-soon-responsive.css?ver=cmp-coming-soon-maintenance/assets/css/animate.min.css?ver=cmp-coming-soon-maintenance/assets/css/magnific-popup.css?ver=cmp-coming-soon-maintenance/assets/css/owl.carousel.min.css?ver=cmp-coming-soon-maintenance/assets/css/owl.theme.default.min.css?ver=cmp-coming-soon-maintenance/assets/css/owl.transitions.css?ver=cmp-coming-soon-maintenance/assets/css/colorpicker.css?ver=cmp-coming-soon-maintenance/assets/js/coming-soon.js?ver=cmp-coming-soon-maintenance/assets/js/colorpicker.js?ver=cmp-coming-soon-maintenance/assets/js/jquery.plugin.min.js?ver=cmp-coming-soon-maintenance/assets/js/jquery.countdown.min.js?ver=cmp-coming-soon-maintenance/assets/js/jquery.magnific-popup.min.js?ver=cmp-coming-soon-maintenance/assets/js/owl.carousel.min.js?ver=cmp-coming-soon-maintenance/assets/js/wow.min.js?ver=cmp-coming-soon-maintenance/assets/js/waypoints.min.js?ver=cmp-coming-soon-maintenance/assets/js/particles.min.js?ver=cmp-coming-soon-maintenance/assets/js/scripts.js?ver=

HTML / DOM Fingerprints

CSS Classes
cmp-coming-soon-pageniteo-coming-soon-wrapcmp-coming-soon-contentniteo-coming-soon-titlecmp-coming-soon-subscribe-formcmp-coming-soon-social-iconsniteo-coming-soon-countdown
HTML Comments
<!-- CMP Coming Soon & Maintenance by NiteoThemes --><!-- Countdown Timer --><!-- Social Icons --><!-- Subscribe Form -->+9 more
Data Attributes
data-wow-delaydata-wow-durationdata-particlesdata-particle-colordata-particle-shape-typedata-particle-shape-polygon-sides+11 more
JS Globals
wowparticlesJScountdown
FAQ

Frequently Asked Questions about CMP – Coming Soon & Maintenance Plugin by NiteoThemes