DH – is Coming Soon Security & Risk Analysis

wordpress.org/plugins/dh-is-coming-soon

Showing coming soon page to guest but not to admin.

0 active installs v1.0 PHP + WP 4.0+ Updated May 19, 2018
coming-soonconstructiondhmaintenanceunder-construction
85
A · Safe
CVEs total0
Unpatched0
Last CVENever
Safety Verdict

Is DH – is Coming Soon Safe to Use in 2026?

Generally Safe

Score 85/100

DH – is Coming Soon has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.

No known CVEs Updated 7yr ago
Risk Assessment

The "dh-is-coming-soon" v1.0 plugin exhibits a seemingly strong security posture based on the provided static analysis. There are no identified attack surface points, no dangerous functions used, and all SQL queries leverage prepared statements. Taint analysis also shows no critical or high severity flows. Furthermore, the plugin has no recorded vulnerability history, which is a positive indicator of its current stability and the development team's attention to security.

However, the analysis does reveal a significant concern regarding output escaping. With 31% of outputs properly escaped out of 54 total, this leaves a substantial portion potentially vulnerable to cross-site scripting (XSS) attacks. The complete lack of nonce checks and capability checks on potential entry points (even though the analysis reports 0 entry points) is also a weakness. While the attack surface appears minimal, the absence of these fundamental security measures on any future or undiscovered entry points is a risk. The plugin's vulnerability history being empty is good, but it doesn't negate the identified code weaknesses.

In conclusion, while "dh-is-coming-soon" v1.0 benefits from no known CVEs and a lack of critical code signals like dangerous functions or raw SQL, the unescaped output presents a tangible risk. The absence of nonce and capability checks also indicates a potential for vulnerabilities if the attack surface were to expand or if certain functionalities were to be exposed in the future without proper authorization and validation. Addressing the output escaping is the most immediate and critical improvement needed.

Key Concerns

  • Significant portion of outputs not properly escaped
  • No nonce checks implemented
  • No capability checks implemented
Vulnerabilities
None known

DH – is Coming Soon Security Vulnerabilities

No known vulnerabilities — this is a good sign.
Code Analysis
Analyzed Mar 17, 2026

DH – is Coming Soon Code Analysis

Dangerous Functions
0
Raw SQL Queries
0
0 prepared
Unescaped Output
37
17 escaped
Nonce Checks
0
Capability Checks
0
File Operations
0
External Requests
0
Bundled Libraries
0

Output Escaping

31% escaped54 total outputs
Attack Surface

DH – is Coming Soon Attack Surface

Entry Points0
Unprotected0
WordPress Hooks 6
actionwp_enqueue_scriptsindex.php:331
actionwp_footerindex.php:332
actionadmin_menuindex.php:337
actionadmin_headindex.php:338
actionadmin_enqueue_scriptsindex.php:340
actioninitindex.php:343
Maintenance & Trust

DH – is Coming Soon Maintenance & Trust

Maintenance Signals

WordPress version tested4.9.29
Last updatedMay 19, 2018
PHP min version
Downloads1K

Community Trust

Rating0/100
Number of ratings0
Active installs0
Developer Profile

DH – is Coming Soon Developer Profile

Dannie Herdyawan

6 plugins · 60 total installs

87
trust score
Avg Security Score
90/100
Avg Patch Time
30 days
View full developer profile
Detection Fingerprints

How We Detect DH – is Coming Soon

Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.

Asset Fingerprints

Asset Paths
/wp-content/plugins/dh-is-coming-soon/assets/js/jquery.backstretch.min.js/wp-content/plugins/dh-is-coming-soon/assets/js/jquery.countdown.min.js/wp-content/plugins/dh-is-coming-soon/assets/css/pure-min.css/wp-content/plugins/dh-is-coming-soon/assets/css/style.css/wp-content/plugins/dh-is-coming-soon/assets/js/jquery.datetimepicker.full.min.js/wp-content/plugins/dh-is-coming-soon/assets/js/media-lib-uploader.js/wp-content/plugins/dh-is-coming-soon/assets/css/dhiscomingsoon-admin.css/wp-content/plugins/dh-is-coming-soon/assets/css/jquery.datetimepicker.min.css
Script Paths
/wp-content/plugins/dh-is-coming-soon/assets/js/jquery.backstretch.min.js/wp-content/plugins/dh-is-coming-soon/assets/js/jquery.countdown.min.js/wp-content/plugins/dh-is-coming-soon/assets/js/jquery.datetimepicker.full.min.js/wp-content/plugins/dh-is-coming-soon/assets/js/media-lib-uploader.js

HTML / DOM Fingerprints

CSS Classes
dhiscomingsoondh-success-messages
HTML Comments
<!-- Start of Donation Form --><!-- If using a Business or Company Logo Graphic, include the "cpp_header_image" variable in your View Cart code. --><!-- Replace "business" value with your PayPal Email Address or Account ID --><!-- Replace value with the web page you want the customer to return to after a successful transaction -->+3 more
Data Attributes
name="myform"name="os0"name="amount"name="item_number"name="cpp_header_image"name="on0"+19 more
JS Globals
CalculateOrderjQuery
FAQ

Frequently Asked Questions about DH – is Coming Soon