Coming Soon – Under Construction Security & Risk Analysis

wordpress.org/plugins/coming-soons

Coming Soon is advanced solution for WordPress construction users. Your website with our efforts will be perfectly.

200 active installs v1.2.0 PHP + WP 4.2+ Updated Aug 16, 2022
coming-sooncoming-soon-pagecoming-soon-plugincoming-soon-wordpress-pluginunder-construction
64
C · Use Caution
CVEs total1
Unpatched1
Last CVEJul 26, 2022
Safety Verdict

Is Coming Soon – Under Construction Safe to Use in 2026?

Use With Caution

Score 64/100

Coming Soon – Under Construction has 1 unpatched vulnerability. Evaluate alternatives or apply available mitigations.

1 known CVE 1 unpatched Last CVE: Jul 26, 2022Updated 3yr ago
Risk Assessment

The "coming-soons" v1.2.0 plugin exhibits a generally strong security posture based on the provided static analysis. The plugin extensively utilizes prepared statements for SQL queries, has a high percentage of properly escaped output, and performs a good number of nonce and capability checks. The absence of dangerous functions, file operations, and critical/high severity taint flows suggests a diligent approach to secure coding. The limited attack surface, with only two AJAX entry points and no shortcodes or cron events, further contributes to its safety.

However, the presence of one unpatched medium severity vulnerability from 2022, specifically related to Cross-Site Scripting (XSS), is a significant concern. This indicates a past issue that has not been remediated, potentially leaving active installations vulnerable. While the static analysis doesn't reveal any current XSS flaws or other critical issues, the historical pattern of an XSS vulnerability requires careful attention. The plugin's reliance on a bundled version of TinyMCE also introduces a potential risk if this library itself has known vulnerabilities that are not addressed by the plugin's vendor.

In conclusion, the "coming-soons" plugin demonstrates good development practices with its secure handling of data and entry points. The main weakness lies in its past vulnerability history, specifically the unpatched XSS issue. While the current version appears to have addressed past flaws or the static analysis didn't pick them up, the historical context necessitates vigilance. Users should verify if the unpatched vulnerability has been addressed by the developer or consider alternatives if it remains a concern.

Key Concerns

  • Unpatched medium severity CVE
  • Bundled outdated library (TinyMCE v1.0)
Vulnerabilities
1

Coming Soon – Under Construction Security Vulnerabilities

CVEs by Year

1 CVE in 2022 · unpatched
2022
Patched Has unpatched

Severity Breakdown

Medium
1

1 total CVE

CVE-2022-1322medium · 5.5Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')

Coming Soon – Under Construction <= 1.2.0 - Authenticated (Administrator+) Stored Cross-Site Scripting

Jul 26, 2022Unpatched
Code Analysis
Analyzed Mar 16, 2026

Coming Soon – Under Construction Code Analysis

Dangerous Functions
0
Raw SQL Queries
0
119 prepared
Unescaped Output
80
3464 escaped
Nonce Checks
35
Capability Checks
4
File Operations
0
External Requests
1
Bundled Libraries
1

Bundled Libraries

TinyMCE1.0

SQL Query Safety

100% prepared119 total queries

Output Escaping

98% escaped3544 total outputs
Data Flows
All sanitized

Data Flow Analysis

4 flows
<Rich_Web_Forms_General_Options> (backend\Rich_Web_Forms_General_Options.php:0)
Source (user input) Sink (dangerous op) Sanitizer Transform Unsanitized Sanitized
Attack Surface

Coming Soon – Under Construction Attack Surface

Entry Points2
Unprotected0

AJAX Handlers 2

authwp_ajax_Rich_Web_CS_Forms_Submittheme\Rich-Web-CS-Ajax.php:2
noprivwp_ajax_Rich_Web_CS_Forms_Submittheme\Rich-Web-CS-Ajax.php:3
WordPress Hooks 10
filterupload_size_limitbackend\Rich-Web-CS-Admin.php:7
filterwp_mail_content_typebackend\Rich_Web_Forms_Messages_Manager.php:107
actionadmin_menucoming-soon.php:21
actiontemplate_redirectcoming-soon.php:138
actionadmin_bar_menucoming-soon.php:142
actionadmin_enqueue_scriptscoming-soon.php:172
actionwp_enqueue_scriptscoming-soon.php:174
actionwp_headtheme\index.php:77
filterwp_mail_content_typetheme\Rich-Web-CS-Ajax.php:215
filterwp_mail_content_typetheme\Rich-Web-CS-Ajax.php:243
Maintenance & Trust

Coming Soon – Under Construction Maintenance & Trust

Maintenance Signals

WordPress version tested6.0.11
Last updatedAug 16, 2022
PHP min version
Downloads26K

Community Trust

Rating100/100
Number of ratings15
Active installs200
Developer Profile

Coming Soon – Under Construction Developer Profile

richteam

7 plugins · 9K total installs

64
trust score
Avg Security Score
79/100
Avg Patch Time
549 days
View full developer profile
Detection Fingerprints

How We Detect Coming Soon – Under Construction

Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.

Asset Fingerprints

Asset Paths
/wp-content/plugins/coming-soons/theme/js/particles.js/wp-content/plugins/coming-soons/theme/js/app.js/wp-content/plugins/coming-soons/theme/js/bubble.js/wp-content/plugins/coming-soons/theme/js/constellation.js/wp-content/plugins/coming-soons/theme/js/constallationLib.js/wp-content/plugins/coming-soons/theme/js/constallationStats.js/wp-content/plugins/coming-soons/theme/js/Constindex.js/wp-content/plugins/coming-soons/theme/js/plugins.js+22 more
Script Paths
/wp-content/plugins/coming-soons/theme/js/particles.js/wp-content/plugins/coming-soons/theme/js/app.js/wp-content/plugins/coming-soons/theme/js/bubble.js/wp-content/plugins/coming-soons/theme/js/constellation.js/wp-content/plugins/coming-soons/theme/js/constallationLib.js/wp-content/plugins/coming-soons/theme/js/constallationStats.js+17 more
Version Parameters
coming-soons/theme/js/particles.js?ver=coming-soons/theme/js/app.js?ver=coming-soons/theme/js/bubble.js?ver=coming-soons/theme/js/constellation.js?ver=coming-soons/theme/js/constallationLib.js?ver=coming-soons/theme/js/constallationStats.js?ver=coming-soons/theme/js/Constindex.js?ver=coming-soons/theme/js/plugins.js?ver=coming-soons/theme/js/main.js?ver=coming-soons/theme/js/hover.js?ver=coming-soons/theme/js/youtube.js?ver=coming-soons/theme/js/script.js?ver=coming-soons/theme/js/scriptvsl.js?ver=coming-soons/theme/js/global.js?ver=coming-soons/theme/js/jquery.countdown.js?ver=coming-soons/theme/js/jquery.knob.js?ver=coming-soons/theme/js/jquery.throttle.js?ver=coming-soons/theme/js/jquery.classycountdown.js?ver=coming-soons/theme/js/intlTelInput.min.js?ver=coming-soons/theme/js/countrySelect.min.js?ver=coming-soons/theme/js/contact_form.js?ver=coming-soons/theme/js/init.js?ver=coming-soons/backend/js/alpha-color-picker-cs.js?ver=coming-soons/backend/css/alpha-color-picker-cs.css?ver=coming-soons/backend/css/richwebicons.css?ver=coming-soons/theme/css/jquery.classycountdown.css?ver=coming-soons/theme/css/jquery-ui.css?ver=coming-soons/theme/css/countrySelect.min.css?ver=coming-soons/theme/css/intlTelInput.css?ver=coming-soons/theme/css/styles.css?ver=

HTML / DOM Fingerprints

CSS Classes
rw_cs_admin_bar_button_csrich-web-coming-soon
Data Attributes
data-titledata-percentdata-valuedata-read
JS Globals
RW_PLUGIN_URLRich_Web_CS_wp_activateRich_Web_CS_Admin_MenuManage_Rich_Web_CS_Adminrw_cs_dirManage_Rich_Web_Coming_Soon_Products+3 more
FAQ

Frequently Asked Questions about Coming Soon – Under Construction