Fancy Coming Soon & Maintenance Mode Security & Risk Analysis

wordpress.org/plugins/fancy-coming-soon-maintenance-mode

Fancy Coming soon is a free WordPress plugin that allows you to create coming soon page qucikly via Live Customizer. Easily work on your site while t …

200 active installs v1.4.4 PHP + WP 4.0+ Updated Aug 4, 2021
coming-soonlanding-pagelaunchmaintenance-modeunder-construction
85
A · Safe
CVEs total0
Unpatched0
Last CVENever
Safety Verdict

Is Fancy Coming Soon & Maintenance Mode Safe to Use in 2026?

Generally Safe

Score 85/100

Fancy Coming Soon & Maintenance Mode has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.

No known CVEs Updated 4yr ago
Risk Assessment

The "fancy-coming-soon-maintenance-mode" plugin version 1.4.4 exhibits a mixed security posture. On the positive side, it demonstrates good practices by avoiding dangerous functions, making all SQL queries using prepared statements, and largely escaping output. The absence of file operations and external HTTP requests further reduces potential attack vectors. Furthermore, the plugin has no recorded vulnerabilities (CVEs), indicating a potentially stable and secure history.

However, a significant concern arises from the plugin's attack surface. It exposes two AJAX handlers, both of which lack authentication checks. This is a critical oversight, as it allows any authenticated user, regardless of their role or permissions, to potentially trigger these handlers, which could lead to unintended consequences or even exploit vulnerabilities if further logic flaws exist within them. The lack of nonce checks on these AJAX endpoints exacerbates this risk, making them susceptible to Cross-Site Request Forgery (CSRF) attacks.

While the taint analysis shows no critical or high severity flows, the unprotected AJAX endpoints represent a substantial risk that is not captured by taint analysis alone. The absence of capability checks on these entry points is a direct indicator of a vulnerability. In conclusion, despite good code hygiene in other areas and a clean vulnerability history, the unprotected AJAX handlers are a major weakness that significantly impacts the plugin's overall security.

Key Concerns

  • AJAX handlers without authentication checks
  • AJAX handlers without nonce checks
  • Capability checks missing on entry points
Vulnerabilities
None known

Fancy Coming Soon & Maintenance Mode Security Vulnerabilities

No known vulnerabilities — this is a good sign.
Code Analysis
Analyzed Mar 16, 2026

Fancy Coming Soon & Maintenance Mode Code Analysis

Dangerous Functions
0
Raw SQL Queries
0
0 prepared
Unescaped Output
5
43 escaped
Nonce Checks
0
Capability Checks
1
File Operations
0
External Requests
0
Bundled Libraries
0

Output Escaping

90% escaped48 total outputs
Attack Surface
2 unprotected

Fancy Coming Soon & Maintenance Mode Attack Surface

Entry Points2
Unprotected2

AJAX Handlers 2

authwp_ajax_add_mailchimptemplates\ajax-class.php:65
noprivwp_ajax_add_mailchimptemplates\ajax-class.php:66
WordPress Hooks 8
actionplugins_loadedfancy-coming-soon.php:25
actiontemplate_redirectfancy-coming-soon.php:39
actioninitfancy-coming-soon.php:42
actionadmin_menufancy-coming-soon.php:96
filterplugin_action_linksfancy-coming-soon.php:112
actioninitfancy-coming-soon.php:161
actionadmin_noticesfancy-coming-soon.php:195
actioncustomize_registertemplates\fancy-customizer.php:441
Maintenance & Trust

Fancy Coming Soon & Maintenance Mode Maintenance & Trust

Maintenance Signals

WordPress version tested5.8.13
Last updatedAug 4, 2021
PHP min version
Downloads37K

Community Trust

Rating60/100
Number of ratings10
Active installs200
Developer Profile

Fancy Coming Soon & Maintenance Mode Developer Profile

FancyThemes

3 plugins · 3K total installs

73
trust score
Avg Security Score
92/100
Avg Patch Time
388 days
View full developer profile
Detection Fingerprints

How We Detect Fancy Coming Soon & Maintenance Mode

Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.

Asset Fingerprints

Asset Paths
/wp-content/plugins/fancy-coming-soon-maintenance-mode/assets/css/style.css/wp-content/plugins/fancy-coming-soon-maintenance-mode/assets/js/main.js
Script Paths
/wp-content/plugins/fancy-coming-soon-maintenance-mode/assets/js/main.js
Version Parameters
fancy-coming-soon-maintenance-mode/assets/css/style.css?v=

HTML / DOM Fingerprints

CSS Classes
body-color-lightbody-color-dark
FAQ

Frequently Asked Questions about Fancy Coming Soon & Maintenance Mode