BoomDevs WordPress Coming Soon Plugin Security & Risk Analysis

wordpress.org/plugins/coming-soon-by-boomdevs

The best free WordPress coming soon plugin with unlimited customizations, additional pages and sexy design.

400 active installs v1.0.4 PHP 7.0+ WP 5.0+ Updated May 2, 2025
coming-soon-plugincoming-soon-templateunder-construction-mode
70
B · Generally Safe
CVEs total1
Unpatched1
Last CVEDec 31, 2025
Safety Verdict

Is BoomDevs WordPress Coming Soon Plugin Safe to Use in 2026?

Mostly Safe

Score 70/100

BoomDevs WordPress Coming Soon Plugin is generally safe to use though it hasn't been updated recently. 1 past CVE were resolved.

1 known CVE 1 unpatched Last CVE: Dec 31, 2025Updated 1yr ago
Risk Assessment

The "coming-soon-by-boomdevs" plugin version 1.0.4 exhibits a mixed security posture. On the positive side, it demonstrates good practices by using prepared statements for all SQL queries and a high percentage of properly escaped outputs, indicating an awareness of common web vulnerabilities. There are no identified dangerous functions or file operations, and no external HTTP requests are made, further reducing the attack surface in those areas. The presence of a nonce check is also a positive sign.

However, significant concerns arise from the static analysis of its attack surface. With two AJAX handlers, both are found to be unprotected and lack authentication checks. This creates a direct pathway for unauthenticated users to interact with plugin functionalities, potentially leading to unintended consequences or exploits. The absence of any taint analysis results is not necessarily a strength; it could indicate that the analysis was incomplete or that complex data flows were not thoroughly examined. The plugin's vulnerability history, specifically a medium severity CVE related to exposure of sensitive information that remains unpatched, is a critical red flag. This indicates a known weakness that malicious actors could exploit.

In conclusion, while the plugin incorporates some secure coding practices, the presence of two unprotected AJAX endpoints and a known, unpatched vulnerability for sensitive information exposure significantly elevate the risk. The lack of complete taint analysis results also leaves some uncertainty. Users should exercise extreme caution, and developers should prioritize patching the known CVE and implementing robust authentication and authorization for all AJAX endpoints.

Key Concerns

  • Unpatched CVE (medium severity)
  • 2 AJAX handlers without auth checks
  • 2 Capability checks, but unprotected AJAX handlers bypass
Vulnerabilities
1 published

BoomDevs WordPress Coming Soon Plugin Security Vulnerabilities

CVEs by Year

1 CVE in 2025 · unpatched
2025
Patched Has unpatched

Severity Breakdown

Medium
1

1 total CVE

CVE-2025-62083medium · 5.3Exposure of Sensitive Information to an Unauthorized Actor

BoomDevs WordPress Coming Soon <= 1.0.4 - Unauthenticated Information Exposure

Dec 31, 2025Unpatched
Version History

BoomDevs WordPress Coming Soon Plugin Release Timeline

v1.0.4Current1 CVE
v1.0.31 CVE
v1.0.21 CVE
v1.0.11 CVE
Code Analysis
Analyzed Mar 16, 2026

BoomDevs WordPress Coming Soon Plugin Code Analysis

Dangerous Functions
0
Raw SQL Queries
0
0 prepared
Unescaped Output
9
65 escaped
Nonce Checks
1
Capability Checks
2
File Operations
0
External Requests
0
Bundled Libraries
0

Output Escaping

88% escaped74 total outputs
Attack Surface
2 unprotected

BoomDevs WordPress Coming Soon Plugin Attack Surface

Entry Points2
Unprotected2

AJAX Handlers 2

noprivwp_ajax_get_postincludes\class-csts.php:209
authwp_ajax_get_postincludes\class-csts.php:210
WordPress Hooks 7
actionplugins_loadedincludes\class-csts.php:170
actionadmin_enqueue_scriptsincludes\class-csts.php:195
actionadmin_enqueue_scriptsincludes\class-csts.php:196
actionwp_enqueue_scriptsincludes\class-csts.php:224
actionwp_enqueue_scriptsincludes\class-csts.php:225
actiontemplate_redirectincludes\class-csts.php:227
actionwp_footerincludes\class-csts.php:228
Maintenance & Trust

BoomDevs WordPress Coming Soon Plugin Maintenance & Trust

Maintenance Signals

WordPress version tested6.8.5
Last updatedMay 2, 2025
PHP min version7.0
Downloads4K

Community Trust

Rating0/100
Number of ratings0
Active installs400
Developer Profile

BoomDevs WordPress Coming Soon Plugin Developer Profile

WP Messiah

12 plugins · 27K total installs

71
trust score
Avg Security Score
88/100
Avg Patch Time
129 days
View full developer profile
Detection Fingerprints

How We Detect BoomDevs WordPress Coming Soon Plugin

Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.

Asset Fingerprints

Asset Paths
/wp-content/plugins/coming-soon-by-boomdevs/admin/css/csts-admin.css/wp-content/plugins/coming-soon-by-boomdevs/admin/js/csts-admin.js
Version Parameters
coming-soon-by-boomdevs/admin/css/csts-admin.css?ver=coming-soon-by-boomdevs/admin/js/csts-admin.js?ver=

HTML / DOM Fingerprints

CSS Classes
csts-admin-wrap
HTML Comments
<!-- BOOMDEVS START --><!-- BOOMDEVS END -->
Data Attributes
data-wpr-cs-iddata-wpr-cs-redirectdata-wpr-cs-target
FAQ

Frequently Asked Questions about BoomDevs WordPress Coming Soon Plugin