Coming soon and Maintenance mode Security & Risk Analysis

wordpress.org/plugins/coming-soon-page

Coming soon and Maintenance mode plugin is an awesome tool to show your website visitors that you are working on your website for making it better.

9K active installs v3.8.8 PHP + WP 3.4.0+ Updated Feb 2, 2026
coming-soonmaintenancemaintenance-modeunder-constructionwordpress-coming-soon
98
A · Safe
CVEs total4
Unpatched0
Last CVEDec 1, 2023
Safety Verdict

Is Coming soon and Maintenance mode Safe to Use in 2026?

Generally Safe

Score 98/100

Coming soon and Maintenance mode has a strong security track record. Known vulnerabilities have been patched promptly.

4 known CVEsLast CVE: Dec 1, 2023Updated 2mo ago
Risk Assessment

The 'coming-soon-page' plugin version 3.8.8 exhibits a mixed security posture. From a static analysis perspective, it demonstrates good practices with a very small attack surface consisting of only two AJAX handlers, neither of which are directly exposed without authentication checks. The plugin also correctly utilizes prepared statements for all SQL queries and generally adheres to proper output escaping. Furthermore, the presence of nonce and capability checks, along with no identified dangerous functions or file operations, are positive security indicators.

However, the plugin's historical vulnerability record presents a significant concern. With a total of four known CVEs, including one high and three medium severity vulnerabilities, and a recent one from December 2023, this suggests a recurring pattern of security flaws. The types of past vulnerabilities, such as protection mechanism failures, incorrect authorization, CSRF, and XSS, indicate a need for more robust and consistent security measures throughout the development lifecycle. While the current version shows improvements in static analysis, the historical context implies a potential for underlying weaknesses that may not be immediately apparent in this specific version's static scan.

In conclusion, while version 3.8.8 of 'coming-soon-page' shows positive signs in its current static analysis, particularly regarding its limited attack surface and secure coding practices for SQL and output escaping, its past vulnerability history is a substantial red flag. The recurring nature and types of past vulnerabilities necessitate a cautious approach and highlight the importance of ongoing security audits and robust testing to prevent future exploitation. The plugin's strengths lie in its current implementation's apparent security measures, but its weakness is heavily weighted by its documented history.

Key Concerns

  • Historically high number of known CVEs
  • Recent vulnerability (Dec 2023)
  • Past vulnerabilities included high severity
  • Past vulnerabilities included medium severity
  • Small attack surface, but still has AJAX entry points
Vulnerabilities
4

Coming soon and Maintenance mode Security Vulnerabilities

CVEs by Year

1 CVE in 2021
2021
2 CVEs in 2022
2022
1 CVE in 2023
2023
Patched Has unpatched

Severity Breakdown

High
1
Medium
3

4 total CVEs

CVE-2023-49741medium · 5.3Protection Mechanism Failure

Coming soon and Maintenance mode <= 3.7.3 - IP Address Spoofing via get_real_ip

Dec 1, 2023 Patched in 3.7.4 (188d)
CVE-2022-0164medium · 4.3Incorrect Authorization

Coming soon and Maintenance mode <= 3.6.6 - Missing Authorization to Arbitrary Email Send

Jan 24, 2022 Patched in 3.6.7 (729d)
CVE-2022-0199high · 8.8Cross-Site Request Forgery (CSRF)

Coming soon and Maintenance mode <= 3.6.7 - Cross-Site request Forgery to Arbitrary Email Send

Jan 23, 2022 Patched in 3.6.8 (730d)
CVE-2021-24577medium · 6.4Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')

Coming soon and Maintenance mode <= 3.5.2 - Authenticated Stored Cross-Site Scripting

Sep 13, 2021 Patched in 3.5.3 (862d)
Code Analysis
Analyzed Mar 16, 2026

Coming soon and Maintenance mode Code Analysis

Dangerous Functions
0
Raw SQL Queries
0
0 prepared
Unescaped Output
8
151 escaped
Nonce Checks
3
Capability Checks
2
File Operations
0
External Requests
0
Bundled Libraries
0

Output Escaping

95% escaped159 total outputs
Data Flows
All sanitized

Data Flow Analysis

2 flows
save_in_databese (includes\admin_menu.php:111)
Source (user input) Sink (dangerous op) Sanitizer Transform Unsanitized Sanitized
Attack Surface

Coming soon and Maintenance mode Attack Surface

Entry Points2
Unprotected0

AJAX Handlers 2

authwp_ajax_coming_soon_page_saveincludes\admin_menu.php:35
authwp_ajax_coming_soon_send_mailincludes\admin_menu.php:36
WordPress Hooks 3
actionadmin_menucoming_soon.php:49
actiontemplate_redirectcoming_soon.php:71
actioninitcoming_soon.php:89
Maintenance & Trust

Coming soon and Maintenance mode Maintenance & Trust

Maintenance Signals

WordPress version tested6.9.4
Last updatedFeb 2, 2026
PHP min version
Downloads1.4M

Community Trust

Rating84/100
Number of ratings83
Active installs9K
Developer Profile

Coming soon and Maintenance mode Developer Profile

wpdevart

45 plugins · 52K total installs

78
trust score
Avg Security Score
99/100
Avg Patch Time
581 days
View full developer profile
Detection Fingerprints

How We Detect Coming soon and Maintenance mode

Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.

Asset Fingerprints

Asset Paths
/wp-content/plugins/coming-soon-page/includes/javascript/angular.min.js/wp-content/plugins/coming-soon-page/includes/javascript/admin_coming_soon.js/wp-content/plugins/coming-soon-page/includes/style/jquery-ui-style.css/wp-content/plugins/coming-soon-page/includes/style/admin-style.css/wp-content/plugins/coming-soon-page/includes/style/style.css/wp-content/plugins/coming-soon-page/includes/javascript/front_end_js.js
Script Paths
/wp-content/plugins/coming-soon-page/includes/javascript/front_end_js.js/wp-content/plugins/coming-soon-page/includes/javascript/angular.min.js/wp-content/plugins/coming-soon-page/includes/javascript/admin_coming_soon.js

HTML / DOM Fingerprints

CSS Classes
coming-soon-page-wrap
HTML Comments
<!--Coming Soon Page--><!--End Coming Soon Page-->
JS Globals
coming_soon_optionscoming_soon_admin_optionscoming_soon_page
REST Endpoints
/wp-json/coming-soon-page/v1/settings
FAQ

Frequently Asked Questions about Coming soon and Maintenance mode