
Coming Soon – Under Construction Security & Risk Analysis
wordpress.org/plugins/coming-soonsComing Soon is advanced solution for WordPress construction users. Your website with our efforts will be perfectly.
Is Coming Soon – Under Construction Safe to Use in 2026?
Use With Caution
Score 64/100Coming Soon – Under Construction has 1 unpatched vulnerability. Evaluate alternatives or apply available mitigations.
The "coming-soons" v1.2.0 plugin exhibits a generally strong security posture based on the provided static analysis. The plugin extensively utilizes prepared statements for SQL queries, has a high percentage of properly escaped output, and performs a good number of nonce and capability checks. The absence of dangerous functions, file operations, and critical/high severity taint flows suggests a diligent approach to secure coding. The limited attack surface, with only two AJAX entry points and no shortcodes or cron events, further contributes to its safety.
However, the presence of one unpatched medium severity vulnerability from 2022, specifically related to Cross-Site Scripting (XSS), is a significant concern. This indicates a past issue that has not been remediated, potentially leaving active installations vulnerable. While the static analysis doesn't reveal any current XSS flaws or other critical issues, the historical pattern of an XSS vulnerability requires careful attention. The plugin's reliance on a bundled version of TinyMCE also introduces a potential risk if this library itself has known vulnerabilities that are not addressed by the plugin's vendor.
In conclusion, the "coming-soons" plugin demonstrates good development practices with its secure handling of data and entry points. The main weakness lies in its past vulnerability history, specifically the unpatched XSS issue. While the current version appears to have addressed past flaws or the static analysis didn't pick them up, the historical context necessitates vigilance. Users should verify if the unpatched vulnerability has been addressed by the developer or consider alternatives if it remains a concern.
Key Concerns
- Unpatched medium severity CVE
- Bundled outdated library (TinyMCE v1.0)
Coming Soon – Under Construction Security Vulnerabilities
CVEs by Year
Severity Breakdown
1 total CVE
Coming Soon – Under Construction <= 1.2.0 - Authenticated (Administrator+) Stored Cross-Site Scripting
Coming Soon – Under Construction Code Analysis
Bundled Libraries
SQL Query Safety
Output Escaping
Data Flow Analysis
Coming Soon – Under Construction Attack Surface
AJAX Handlers 2
WordPress Hooks 10
Maintenance & Trust
Coming Soon – Under Construction Maintenance & Trust
Maintenance Signals
Community Trust
Coming Soon – Under Construction Alternatives
Under Construction
under-construction-page
Easy to use Under Construction Page & Coming Soon Page. Enable Under Construction Mode in seconds & show you're Under Construction!
CMP – Coming Soon & Maintenance Plugin by NiteoThemes
cmp-coming-soon-maintenance
Beautiful Coming soon, Maintenance or Landing page on your website, packed with premium features for free.
Site Offline Or Coming Soon Or Maintenance Mode
site-offline
Site Offline plugin manage your WordPress website in under construction or maintenance mode or coming soon or landing page.
Coming Soon, Under Construction & Maintenance Mode By Dazzler
coming-soon-wp
An awesome wordpress coming soon plugin to manage your under construction website, under maintenance mode website and offline website
Maintenance Page
maintenance-page
Allows you to quickly create a maintenance/coming-soon page. Use this plugin whenever your site is down for maintenance or undergoing development.
Coming Soon – Under Construction Developer Profile
7 plugins · 9K total installs
How We Detect Coming Soon – Under Construction
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/coming-soons/theme/js/particles.js/wp-content/plugins/coming-soons/theme/js/app.js/wp-content/plugins/coming-soons/theme/js/bubble.js/wp-content/plugins/coming-soons/theme/js/constellation.js/wp-content/plugins/coming-soons/theme/js/constallationLib.js/wp-content/plugins/coming-soons/theme/js/constallationStats.js/wp-content/plugins/coming-soons/theme/js/Constindex.js/wp-content/plugins/coming-soons/theme/js/plugins.js+22 more/wp-content/plugins/coming-soons/theme/js/particles.js/wp-content/plugins/coming-soons/theme/js/app.js/wp-content/plugins/coming-soons/theme/js/bubble.js/wp-content/plugins/coming-soons/theme/js/constellation.js/wp-content/plugins/coming-soons/theme/js/constallationLib.js/wp-content/plugins/coming-soons/theme/js/constallationStats.js+17 morecoming-soons/theme/js/particles.js?ver=coming-soons/theme/js/app.js?ver=coming-soons/theme/js/bubble.js?ver=coming-soons/theme/js/constellation.js?ver=coming-soons/theme/js/constallationLib.js?ver=coming-soons/theme/js/constallationStats.js?ver=coming-soons/theme/js/Constindex.js?ver=coming-soons/theme/js/plugins.js?ver=coming-soons/theme/js/main.js?ver=coming-soons/theme/js/hover.js?ver=coming-soons/theme/js/youtube.js?ver=coming-soons/theme/js/script.js?ver=coming-soons/theme/js/scriptvsl.js?ver=coming-soons/theme/js/global.js?ver=coming-soons/theme/js/jquery.countdown.js?ver=coming-soons/theme/js/jquery.knob.js?ver=coming-soons/theme/js/jquery.throttle.js?ver=coming-soons/theme/js/jquery.classycountdown.js?ver=coming-soons/theme/js/intlTelInput.min.js?ver=coming-soons/theme/js/countrySelect.min.js?ver=coming-soons/theme/js/contact_form.js?ver=coming-soons/theme/js/init.js?ver=coming-soons/backend/js/alpha-color-picker-cs.js?ver=coming-soons/backend/css/alpha-color-picker-cs.css?ver=coming-soons/backend/css/richwebicons.css?ver=coming-soons/theme/css/jquery.classycountdown.css?ver=coming-soons/theme/css/jquery-ui.css?ver=coming-soons/theme/css/countrySelect.min.css?ver=coming-soons/theme/css/intlTelInput.css?ver=coming-soons/theme/css/styles.css?ver=HTML / DOM Fingerprints
rw_cs_admin_bar_button_csrich-web-coming-soondata-titledata-percentdata-valuedata-readRW_PLUGIN_URLRich_Web_CS_wp_activateRich_Web_CS_Admin_MenuManage_Rich_Web_CS_Adminrw_cs_dirManage_Rich_Web_Coming_Soon_Products+3 more