Maintenance Mode with Timer Security & Risk Analysis

wordpress.org/plugins/maintenance-mode-with-timer

A quick, easy way to add and display maintenance mode with countdown timer on your website.

100 active installs v1.3 PHP + WP 4.0+ Updated Feb 20, 2026
coming-soon-with-countdown-timermaintenance-modemaintenance-mode-with-countdown-timersite-is-offlineunder-construction
100
A · Safe
CVEs total0
Unpatched0
Last CVENever
Safety Verdict

Is Maintenance Mode with Timer Safe to Use in 2026?

Generally Safe

Score 100/100

Maintenance Mode with Timer has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.

No known CVEs Updated 1mo ago
Risk Assessment

The maintenance-mode-with-timer v1.3 plugin exhibits a generally strong security posture based on the provided static analysis and vulnerability history. The absence of AJAX handlers, REST API routes, shortcodes, and cron events significantly limits its attack surface. Furthermore, the code signals indicate a commitment to secure coding practices, with all SQL queries utilizing prepared statements and a high percentage of output being properly escaped. The presence of a nonce check is also a positive sign. The plugin's vulnerability history is clean, with no recorded CVEs, which suggests a well-maintained and secure codebase over time.

Despite the positive indicators, the analysis reveals a complete lack of capability checks for its functions. While the current version might not expose sensitive operations, this omission represents a potential weakness. If future updates introduce administrative or sensitive functionalities, the lack of proper capability checks could lead to privilege escalation vulnerabilities. The taint analysis reporting zero flows is excellent, but it's important to note that the total flows analyzed is also zero, which might indicate a limited scope of analysis or a very straightforward plugin that inherently avoids complex data handling.

In conclusion, maintenance-mode-with-timer v1.3 appears to be a secure plugin with a robust foundation. Its limited attack surface and adherence to secure coding practices for critical areas like SQL queries and output escaping are commendable. However, the absence of capability checks is a notable concern that should be addressed to ensure long-term security, especially as the plugin evolves.

Key Concerns

  • Missing capability checks on entry points
Vulnerabilities
None known

Maintenance Mode with Timer Security Vulnerabilities

No known vulnerabilities — this is a good sign.
Code Analysis
Analyzed Mar 16, 2026

Maintenance Mode with Timer Code Analysis

Dangerous Functions
0
Raw SQL Queries
0
0 prepared
Unescaped Output
7
70 escaped
Nonce Checks
1
Capability Checks
0
File Operations
0
External Requests
0
Bundled Libraries
0

Output Escaping

91% escaped77 total outputs
Attack Surface

Maintenance Mode with Timer Attack Surface

Entry Points0
Unprotected0
WordPress Hooks 7
actionadmin_menuincludes\admin\class-mtm-admin.php:20
actionadmin_initincludes\admin\class-mtm-admin.php:23
actionwp_loadedincludes\admin\class-mtm-admin.php:26
actionadmin_menuincludes\admin\mtm-how-it-work.php:14
actionadmin_enqueue_scriptsincludes\class-mtm-script.php:20
actionadmin_enqueue_scriptsincludes\class-mtm-script.php:23
actionplugins_loadedmaintenance-mode-by-wpos.php:74
Maintenance & Trust

Maintenance Mode with Timer Maintenance & Trust

Maintenance Signals

WordPress version tested6.9.4
Last updatedFeb 20, 2026
PHP min version
Downloads9K

Community Trust

Rating100/100
Number of ratings1
Active installs100
Developer Profile

Maintenance Mode with Timer Developer Profile

Essential Plugin

33 plugins · 205K total installs

78
trust score
Avg Security Score
99/100
Avg Patch Time
219 days
View full developer profile
Detection Fingerprints

How We Detect Maintenance Mode with Timer

Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.

Asset Fingerprints

Asset Paths
/wp-content/plugins/maintenance-mode-with-timer/assets/css/mmt-time-picker.css/wp-content/plugins/maintenance-mode-with-timer/assets/css/mtm-pro-admin.css/wp-content/plugins/maintenance-mode-with-timer/assets/js/mtm-pro-admin.js/wp-content/plugins/maintenance-mode-with-timer/assets/js/mmt-ui-timepicker-addon.js
Script Paths
/wp-content/plugins/maintenance-mode-with-timer/assets/js/mtm-pro-admin.js/wp-content/plugins/maintenance-mode-with-timer/assets/js/mmt-ui-timepicker-addon.js
Version Parameters
maintenance-mode-with-timer/assets/css/mmt-time-picker.css?ver=maintenance-mode-with-timer/assets/css/mtm-pro-admin.css?ver=maintenance-mode-with-timer/assets/js/mtm-pro-admin.js?ver=maintenance-mode-with-timer/assets/js/mmt-ui-timepicker-addon.js?ver=

HTML / DOM Fingerprints

CSS Classes
wpcdt-wrapwpos-pro-boxwpos-list
Data Attributes
data-current-datedata-current-time
JS Globals
MtmAdmin
FAQ

Frequently Asked Questions about Maintenance Mode with Timer