
Coming soon and Maintenance mode Security & Risk Analysis
wordpress.org/plugins/coming-soon-pageComing soon and Maintenance mode plugin is an awesome tool to show your website visitors that you are working on your website for making it better.
Is Coming soon and Maintenance mode Safe to Use in 2026?
Generally Safe
Score 98/100Coming soon and Maintenance mode has a strong security track record. Known vulnerabilities have been patched promptly.
The 'coming-soon-page' plugin version 3.8.8 exhibits a mixed security posture. From a static analysis perspective, it demonstrates good practices with a very small attack surface consisting of only two AJAX handlers, neither of which are directly exposed without authentication checks. The plugin also correctly utilizes prepared statements for all SQL queries and generally adheres to proper output escaping. Furthermore, the presence of nonce and capability checks, along with no identified dangerous functions or file operations, are positive security indicators.
However, the plugin's historical vulnerability record presents a significant concern. With a total of four known CVEs, including one high and three medium severity vulnerabilities, and a recent one from December 2023, this suggests a recurring pattern of security flaws. The types of past vulnerabilities, such as protection mechanism failures, incorrect authorization, CSRF, and XSS, indicate a need for more robust and consistent security measures throughout the development lifecycle. While the current version shows improvements in static analysis, the historical context implies a potential for underlying weaknesses that may not be immediately apparent in this specific version's static scan.
In conclusion, while version 3.8.8 of 'coming-soon-page' shows positive signs in its current static analysis, particularly regarding its limited attack surface and secure coding practices for SQL and output escaping, its past vulnerability history is a substantial red flag. The recurring nature and types of past vulnerabilities necessitate a cautious approach and highlight the importance of ongoing security audits and robust testing to prevent future exploitation. The plugin's strengths lie in its current implementation's apparent security measures, but its weakness is heavily weighted by its documented history.
Key Concerns
- Historically high number of known CVEs
- Recent vulnerability (Dec 2023)
- Past vulnerabilities included high severity
- Past vulnerabilities included medium severity
- Small attack surface, but still has AJAX entry points
Coming soon and Maintenance mode Security Vulnerabilities
CVEs by Year
Severity Breakdown
4 total CVEs
Coming soon and Maintenance mode <= 3.7.3 - IP Address Spoofing via get_real_ip
Coming soon and Maintenance mode <= 3.6.6 - Missing Authorization to Arbitrary Email Send
Coming soon and Maintenance mode <= 3.6.7 - Cross-Site request Forgery to Arbitrary Email Send
Coming soon and Maintenance mode <= 3.5.2 - Authenticated Stored Cross-Site Scripting
Coming soon and Maintenance mode Code Analysis
Output Escaping
Data Flow Analysis
Coming soon and Maintenance mode Attack Surface
AJAX Handlers 2
WordPress Hooks 3
Maintenance & Trust
Coming soon and Maintenance mode Maintenance & Trust
Maintenance Signals
Community Trust
Coming soon and Maintenance mode Alternatives
Simple Coming Soon
simple-coming-soon
The ultimate free Coming Soon plugin. Features Auto-Launch countdown, Secret Client Access, Pro Action Button, plus a modern Glassmorphism design UI.
CMP – Coming Soon & Maintenance Plugin by NiteoThemes
cmp-coming-soon-maintenance
Beautiful Coming soon, Maintenance or Landing page on your website, packed with premium features for free.
Under Construction, Coming Soon & Maintenance Mode
under-construction-maintenance-mode
Under Construction is a simple plugin for setting up Under Construction, Coming Soon and Maintenance Mode using WordPress Customizer.
Ultimate Coming Soon & Maintenance
ultimate-coming-soon
Best Coming Soon, Under Construction, Maintenance Mode, and Landing Page for your website get advanced features for free.
Coming Soon & Maintenance Mode by Colorlib
colorlib-coming-soon-maintenance
Create a coming soon page or maintenance mode screen with 15 responsive templates, countdown timer, MailChimp subscribe form, and social media links.
Coming soon and Maintenance mode Developer Profile
45 plugins · 52K total installs
How We Detect Coming soon and Maintenance mode
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/coming-soon-page/includes/javascript/angular.min.js/wp-content/plugins/coming-soon-page/includes/javascript/admin_coming_soon.js/wp-content/plugins/coming-soon-page/includes/style/jquery-ui-style.css/wp-content/plugins/coming-soon-page/includes/style/admin-style.css/wp-content/plugins/coming-soon-page/includes/style/style.css/wp-content/plugins/coming-soon-page/includes/javascript/front_end_js.js/wp-content/plugins/coming-soon-page/includes/javascript/front_end_js.js/wp-content/plugins/coming-soon-page/includes/javascript/angular.min.js/wp-content/plugins/coming-soon-page/includes/javascript/admin_coming_soon.jsHTML / DOM Fingerprints
coming-soon-page-wrap<!--Coming Soon Page--><!--End Coming Soon Page-->coming_soon_optionscoming_soon_admin_optionscoming_soon_page/wp-json/coming-soon-page/v1/settings