
Fancy Coming Soon & Maintenance Mode Security & Risk Analysis
wordpress.org/plugins/fancy-coming-soon-maintenance-modeFancy Coming soon is a free WordPress plugin that allows you to create coming soon page qucikly via Live Customizer. Easily work on your site while t …
Is Fancy Coming Soon & Maintenance Mode Safe to Use in 2026?
Generally Safe
Score 85/100Fancy Coming Soon & Maintenance Mode has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.
The "fancy-coming-soon-maintenance-mode" plugin version 1.4.4 exhibits a mixed security posture. On the positive side, it demonstrates good practices by avoiding dangerous functions, making all SQL queries using prepared statements, and largely escaping output. The absence of file operations and external HTTP requests further reduces potential attack vectors. Furthermore, the plugin has no recorded vulnerabilities (CVEs), indicating a potentially stable and secure history.
However, a significant concern arises from the plugin's attack surface. It exposes two AJAX handlers, both of which lack authentication checks. This is a critical oversight, as it allows any authenticated user, regardless of their role or permissions, to potentially trigger these handlers, which could lead to unintended consequences or even exploit vulnerabilities if further logic flaws exist within them. The lack of nonce checks on these AJAX endpoints exacerbates this risk, making them susceptible to Cross-Site Request Forgery (CSRF) attacks.
While the taint analysis shows no critical or high severity flows, the unprotected AJAX endpoints represent a substantial risk that is not captured by taint analysis alone. The absence of capability checks on these entry points is a direct indicator of a vulnerability. In conclusion, despite good code hygiene in other areas and a clean vulnerability history, the unprotected AJAX handlers are a major weakness that significantly impacts the plugin's overall security.
Key Concerns
- AJAX handlers without authentication checks
- AJAX handlers without nonce checks
- Capability checks missing on entry points
Fancy Coming Soon & Maintenance Mode Security Vulnerabilities
Fancy Coming Soon & Maintenance Mode Code Analysis
Output Escaping
Fancy Coming Soon & Maintenance Mode Attack Surface
AJAX Handlers 2
WordPress Hooks 8
Maintenance & Trust
Fancy Coming Soon & Maintenance Mode Maintenance & Trust
Maintenance Signals
Community Trust
Fancy Coming Soon & Maintenance Mode Alternatives
TL Coming Soon – Maintenance Mode & Under Construction
tl-coming-soon
Coming Soon, Maintenance Mode and Under Construction plugin for WordPress.
CMP – Coming Soon & Maintenance Plugin by NiteoThemes
cmp-coming-soon-maintenance
Beautiful Coming soon, Maintenance or Landing page on your website, packed with premium features for free.
Ultimate Coming Soon & Maintenance
ultimate-coming-soon
Best Coming Soon, Under Construction, Maintenance Mode, and Landing Page for your website get advanced features for free.
Coming Soon & Maintenance Mode by Colorlib
colorlib-coming-soon-maintenance
Create a coming soon page or maintenance mode screen with 15 responsive templates, countdown timer, MailChimp subscribe form, and social media links.
WP Maintenance Mode & Site Under Construction
wp-maintenance-mode-site-under-construction
WP plugin for Under Construction, Maintenance Mode & Coming Soon Pages. Enable with one click & show a landing page to visitors easily.
Fancy Coming Soon & Maintenance Mode Developer Profile
3 plugins · 3K total installs
How We Detect Fancy Coming Soon & Maintenance Mode
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/fancy-coming-soon-maintenance-mode/assets/css/style.css/wp-content/plugins/fancy-coming-soon-maintenance-mode/assets/js/main.js/wp-content/plugins/fancy-coming-soon-maintenance-mode/assets/js/main.jsfancy-coming-soon-maintenance-mode/assets/css/style.css?v=HTML / DOM Fingerprints
body-color-lightbody-color-dark