
BoomDevs WordPress Coming Soon Plugin Security & Risk Analysis
wordpress.org/plugins/coming-soon-by-boomdevsThe best free WordPress coming soon plugin with unlimited customizations, additional pages and sexy design.
Is BoomDevs WordPress Coming Soon Plugin Safe to Use in 2026?
Mostly Safe
Score 70/100BoomDevs WordPress Coming Soon Plugin is generally safe to use though it hasn't been updated recently. 1 past CVE were resolved.
The "coming-soon-by-boomdevs" plugin version 1.0.4 exhibits a mixed security posture. On the positive side, it demonstrates good practices by using prepared statements for all SQL queries and a high percentage of properly escaped outputs, indicating an awareness of common web vulnerabilities. There are no identified dangerous functions or file operations, and no external HTTP requests are made, further reducing the attack surface in those areas. The presence of a nonce check is also a positive sign.
However, significant concerns arise from the static analysis of its attack surface. With two AJAX handlers, both are found to be unprotected and lack authentication checks. This creates a direct pathway for unauthenticated users to interact with plugin functionalities, potentially leading to unintended consequences or exploits. The absence of any taint analysis results is not necessarily a strength; it could indicate that the analysis was incomplete or that complex data flows were not thoroughly examined. The plugin's vulnerability history, specifically a medium severity CVE related to exposure of sensitive information that remains unpatched, is a critical red flag. This indicates a known weakness that malicious actors could exploit.
In conclusion, while the plugin incorporates some secure coding practices, the presence of two unprotected AJAX endpoints and a known, unpatched vulnerability for sensitive information exposure significantly elevate the risk. The lack of complete taint analysis results also leaves some uncertainty. Users should exercise extreme caution, and developers should prioritize patching the known CVE and implementing robust authentication and authorization for all AJAX endpoints.
Key Concerns
- Unpatched CVE (medium severity)
- 2 AJAX handlers without auth checks
- 2 Capability checks, but unprotected AJAX handlers bypass
BoomDevs WordPress Coming Soon Plugin Security Vulnerabilities
CVEs by Year
Severity Breakdown
1 total CVE
BoomDevs WordPress Coming Soon <= 1.0.4 - Unauthenticated Information Exposure
BoomDevs WordPress Coming Soon Plugin Release Timeline
BoomDevs WordPress Coming Soon Plugin Code Analysis
Output Escaping
BoomDevs WordPress Coming Soon Plugin Attack Surface
AJAX Handlers 2
WordPress Hooks 7
Maintenance & Trust
BoomDevs WordPress Coming Soon Plugin Maintenance & Trust
Maintenance Signals
Community Trust
BoomDevs WordPress Coming Soon Plugin Alternatives
Under Construction
under-construction-page
Easy to use Under Construction Page & Coming Soon Page. Enable Under Construction Mode in seconds & show you're Under Construction!
Siteready Coming Soon Under Construction
siteready-coming-soon-under-construction
Create stunning Coming Soon or Maintenance pages fast! Hide your site, add countdowns & forms, and keep SEO intact while you prepare to launch.
Coming Soon – Under Construction
coming-soons
Coming Soon is advanced solution for WordPress construction users. Your website with our efforts will be perfectly.
Coming Soon Mode
coming-soon-mode
Coming Soon Mode is easy to use. Coming Soon Mode WordPress plugin.
Entro WordPress Coming Soon per post/page or global
entro-coming-soon-per-postpage-or-global
Wordpress Coming Soon, Under Construction per post/page or global
BoomDevs WordPress Coming Soon Plugin Developer Profile
12 plugins · 27K total installs
How We Detect BoomDevs WordPress Coming Soon Plugin
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/coming-soon-by-boomdevs/admin/css/csts-admin.css/wp-content/plugins/coming-soon-by-boomdevs/admin/js/csts-admin.jscoming-soon-by-boomdevs/admin/css/csts-admin.css?ver=coming-soon-by-boomdevs/admin/js/csts-admin.js?ver=HTML / DOM Fingerprints
csts-admin-wrap<!-- BOOMDEVS START --><!-- BOOMDEVS END -->data-wpr-cs-iddata-wpr-cs-redirectdata-wpr-cs-target