Coming Soon Express Security & Risk Analysis

wordpress.org/plugins/coming-soon-express

The fastest, easiest 'Coming Soon' page for your website! Use the WP Customizer to see a Live Preview of your page as you edit.

60 active installs v1.0.7 PHP + WP 4.9+ Updated Sep 9, 2021
coming-sooncoming-soon-pagelaunchlaunch-pageunder-construction
85
A · Safe
CVEs total0
Unpatched0
Last CVENever
Download
Safety Verdict

Is Coming Soon Express Safe to Use in 2026?

Generally Safe

Score 85/100

Coming Soon Express has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.

No known CVEs Updated 4yr ago
Risk Assessment

Based on the provided static analysis and vulnerability history, the "coming-soon-express" v1.0.7 plugin exhibits a generally strong security posture. The absence of any identified CVEs, combined with no recorded historical vulnerabilities, is a very positive indicator. The plugin also demonstrates good coding practices in several areas, including the complete absence of dangerous functions and all SQL queries utilizing prepared statements, which significantly mitigates the risk of SQL injection vulnerabilities.

However, there are areas that warrant attention. The lack of nonce checks and capability checks, particularly in conjunction with the presence of file operations, introduces potential risks if any entry points were to be discovered or if the plugin's functionality expands in future versions. While no direct taint flows or unsanitized paths were identified in this analysis, a lack of input validation and capability checks could allow for vulnerabilities to be introduced through other means. The percentage of properly escaped output, while not critically low, suggests a moderate risk of cross-site scripting (XSS) vulnerabilities if the unescaped outputs are handled by user-controlled input.

In conclusion, the plugin is currently in a good state, with no known severe vulnerabilities and evidence of secure coding practices in critical areas like database interaction. The primary concerns stem from the absence of robust authentication and authorization checks on certain operations and the moderate rate of output escaping. These aspects, while not indicating immediate critical threats based on the current analysis, represent areas for potential improvement to further harden the plugin's security.

Key Concerns

  • Missing nonce checks
  • Missing capability checks
  • Moderate output escaping (66% proper)
Vulnerabilities
None known

Coming Soon Express Security Vulnerabilities

No known vulnerabilities — this is a good sign.
Code Analysis
Analyzed Mar 16, 2026

Coming Soon Express Code Analysis

Dangerous Functions
0
Raw SQL Queries
0
0 prepared
Unescaped Output
14
27 escaped
Nonce Checks
0
Capability Checks
0
File Operations
1
External Requests
0
Bundled Libraries
0

Output Escaping

66% escaped41 total outputs
Attack Surface

Coming Soon Express Attack Surface

Entry Points0
Unprotected0
WordPress Hooks 19
actioncustomize_preview_initadmin\class-coming-soon-express-customizer-settings.php:36
actionwp_headadmin\class-coming-soon-express-customizer-settings.php:41
actioncsx_extension_activationcoming-soon-express.php:41
actionwpincludes\class-coming-soon-express.php:24
actionadmin_bar_menuincludes\class-coming-soon-express.php:27
filterstyle_loader_srcincludes\class-coming-soon-express.php:33
actioncustomize_controls_print_stylesincludes\class-coming-soon-express.php:38
actioncustomize_controls_print_stylesincludes\class-coming-soon-express.php:41
actionadmin_enqueue_scriptsincludes\class-coming-soon-express.php:42
actionwp_enqueue_scriptsincludes\class-coming-soon-express.php:43
actionadmin_enqueue_scriptsincludes\class-coming-soon-express.php:46
actionwp_enqueue_scriptsincludes\class-coming-soon-express.php:47
actioncustomize_controls_print_stylesincludes\class-coming-soon-express.php:50
actionwidgets_initincludes\class-coming-soon-express.php:53
filtercustomizer_widgets_section_argsincludes\class-coming-soon-express.php:56
actiontemplate_redirectincludes\class-coming-soon-express.php:75
actiontemplate_redirectincludes\class-coming-soon-express.php:86
actioncustomize_registerincludes\class-coming-soon-express.php:151
actioncustomize_registerincludes\class-coming-soon-express.php:154
Maintenance & Trust

Coming Soon Express Maintenance & Trust

Maintenance Signals

WordPress version tested5.8.13
Last updatedSep 9, 2021
PHP min version
Downloads3K

Community Trust

Rating100/100
Number of ratings1
Active installs60
Developer Profile

Coming Soon Express Developer Profile

alexmustin

4 plugins · 100 total installs

86
trust score
Avg Security Score
89/100
Avg Patch Time
30 days
View full developer profile
Detection Fingerprints

How We Detect Coming Soon Express

Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.

Asset Fingerprints

Asset Paths
/wp-content/plugins/coming-soon-express/admin/js/coming-soon-express-customizer-preview.js/wp-content/plugins/coming-soon-express/template/css/coming-soon-express.css/wp-content/plugins/coming-soon-express/template/js/coming-soon-express.js
Script Paths
admin/js/coming-soon-express-customizer-preview.jstemplate/js/coming-soon-express.js
Version Parameters
coming-soon-express/admin/js/coming-soon-express-customizer-preview.js?ver=coming-soon-express/template/css/coming-soon-express.css?ver=coming-soon-express/template/js/coming-soon-express.js?ver=

HTML / DOM Fingerprints

CSS Classes
coming-soon-express-pagecoming-soon-express-widget-container
Data Attributes
id="coming-soon-express-page"id="coming-soon-express-page-container"id="background-overlay"
JS Globals
Coming_Soon_Express_Customizer_Preview
FAQ

Frequently Asked Questions about Coming Soon Express