Minimal Coming Soon – Coming Soon Page Security & Risk Analysis

wordpress.org/plugins/minimal-coming-soon-maintenance-mode

Minimal Coming Soon & Maintenance Mode page! Create awesome Coming Soon Pages in seconds.

100K active installs v2.43 PHP 5.2+ WP 4.0+ Updated Dec 3, 2025
coming-sooncoming-soon-buildercoming-soon-modecoming-soon-pagemaintenance-mode
94
A · Safe
CVEs total7
Unpatched0
Last CVEJun 7, 2024
Safety Verdict

Is Minimal Coming Soon – Coming Soon Page Safe to Use in 2026?

Generally Safe

Score 94/100

Minimal Coming Soon – Coming Soon Page has a strong security track record. Known vulnerabilities have been patched promptly.

7 known CVEsLast CVE: Jun 7, 2024Updated 4mo ago
Risk Assessment

The plugin 'minimal-coming-soon-maintenance-mode' v2.43 exhibits a mixed security posture. On the positive side, the code demonstrates good practices by exclusively using prepared statements for SQL queries and maintaining a high percentage of properly escaped output. The absence of dangerous functions, file operations, and critical or high severity taint flows are also encouraging signs. However, significant concerns arise from the plugin's attack surface. With 6 AJAX handlers, 3 of which lack authentication checks, there's a clear avenue for unauthorized actions. The vulnerability history is a major red flag, with a total of 7 known CVEs, including 2 high severity and 4 medium severity vulnerabilities. The presence of past issues like Authorization Bypass, Cross-site Scripting, Missing Authorization, and CSRF indicates recurring security weaknesses. While there are currently no unpatched CVEs, the pattern of past vulnerabilities, coupled with the unprotected AJAX endpoints, suggests a persistent risk that requires careful monitoring and prompt patching of any new issues. The plugin has a significant attack surface with unprotected AJAX endpoints. Its history of multiple high and medium severity vulnerabilities, including authorization bypass and XSS, indicates a recurring pattern of security weaknesses. Although no CVEs are currently unpatched, the overall historical trend suggests potential for future exploitation if not actively managed. The plugin shows strengths in its SQL handling and output escaping, but the unprotected AJAX endpoints and past vulnerability record are considerable weaknesses that elevate its risk profile.

Key Concerns

  • Unprotected AJAX handlers
  • History of 2 High severity CVEs
  • History of 4 Medium severity CVEs
  • History of 1 Low severity CVE
  • History of Authorization Bypass
  • History of Cross-site Scripting (XSS)
  • History of Missing Authorization
  • History of Cross-Site Request Forgery (CSRF)
Vulnerabilities
7

Minimal Coming Soon – Coming Soon Page Security Vulnerabilities

CVEs by Year

1 CVE in 2019
2019
2 CVEs in 2020
2020
2 CVEs in 2022
2022
2 CVEs in 2024
2024
Patched Has unpatched

Severity Breakdown

High
2
Medium
4
Low
1

7 total CVEs

CVE-2024-5087medium · 6.3Missing Authorization

Minimal Coming Soon – Coming Soon Page <= 2.38 - Missing Authorization to Limited Settings Change

Jun 7, 2024 Patched in 2.39 (1d)
CVE-2024-1075low · 3.7Authorization Bypass Through User-Controlled Key

Minimal Coming Soon – Coming Soon Page <= 2.37 - Unauthenticated Maintenance Mode Bypass

Feb 5, 2024 Patched in 2.38 (1d)
WF-d592b81d-48c7-4b48-948d-f2b98719fdfc-minimal-coming-soon-maintenance-modemedium · 5.5Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')

Minimal Coming Soon – Coming Soon Page <= 2.33 - Authenticated (Administrator+) Cross-Site Scripting

Nov 21, 2022 Patched in 2.35 (428d)
WF-ecde34f7-4624-4361-8d95-56fd4b08b476-minimal-coming-soon-maintenance-modemedium · 5.5Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')

Minimal Coming Soon – Coming Soon Page <= 2.33 - Authenticated (Admin+) Stored Cross-Site Scripting

Aug 5, 2022 Patched in 2.35 (536d)
CVE-2020-6166medium · 5.4Missing Authorization

Minimal Coming Soon & Maintenance Mode <= 2.16 - Missing Authorization to Export Settings/Theme Change

Jan 8, 2020 Patched in 2.17 (1476d)
CVE-2020-6167high · 8.8Cross-Site Request Forgery (CSRF)

Minimal Coming Soon & Maintenance Mode <= 2.10 - Cross-Site Request Forgery to Stored Cross-Site Scripting and Setting Changes

Jan 8, 2020 Patched in 2.15 (1476d)
CVE-2020-6168high · 7.1Missing Authorization

Minimal Coming Soon & Maintenance Mode <= 2.10 - Missing Authorization

Dec 18, 2019 Patched in 2.15 (1497d)
Code Analysis
Analyzed Mar 16, 2026

Minimal Coming Soon – Coming Soon Page Code Analysis

Dangerous Functions
0
Raw SQL Queries
0
0 prepared
Unescaped Output
11
280 escaped
Nonce Checks
16
Capability Checks
8
File Operations
0
External Requests
2
Bundled Libraries
0

Output Escaping

96% escaped291 total outputs
Data Flows
All sanitized

Data Flow Analysis

4 flows
csmm_admin_settings (framework\admin\settings.php:14)
Source (user input) Sink (dangerous op) Sanitizer Transform Unsanitized Sanitized
Attack Surface
3 unprotected

Minimal Coming Soon – Coming Soon Page Attack Surface

Entry Points6
Unprotected3

AJAX Handlers 6

authwp_ajax_signals_csmm_supportframework\admin\settings.php:278
authwp_ajax_csmm_rate_hideframework\admin\settings.php:279
authwp_ajax_csmm_welcome_hideframework\admin\settings.php:280
authwp_ajax_csmm_olduser_hideframework\admin\settings.php:281
authwp_ajax_csmm_dismiss_pointerframework\admin\settings.php:282
authwp_ajax_csmm_subscribe_hideframework\public\init.php:26
WordPress Hooks 20
actionadmin_menuframework\admin\init.php:31
actionadmin_enqueue_scriptsframework\admin\init.php:90
filterplugin_row_metaframework\admin\init.php:205
actionadmin_enqueue_scriptsframework\admin\init.php:207
actionadmin_action_csmm_activate_themeframework\admin\init.php:209
actioninitframework\admin\init.php:212
actionadmin_action_csmm_change_statusframework\init.php:9
actionwp_before_admin_bar_renderframework\init.php:13
actionwp_headframework\init.php:14
actionadmin_headframework\init.php:15
filtersafe_style_cssframework\init.php:141
filtersafe_style_cssframework\init.php:380
actioninitframework\init.php:449
actioninitframework\public\init.php:106
actioninitframework\wf-licensing.php:50
actionadmin_enqueue_scriptsframework\wf-licensing.php:70
actionadmin_initwf-flyout\wf-flyout.php:26
actionadmin_enqueue_scriptswf-flyout\wf-flyout.php:72
actionadmin_headwf-flyout\wf-flyout.php:73
actionadmin_footerwf-flyout\wf-flyout.php:74
Maintenance & Trust

Minimal Coming Soon – Coming Soon Page Maintenance & Trust

Maintenance Signals

WordPress version tested6.9.4
Last updatedDec 3, 2025
PHP min version5.2
Downloads2.5M

Community Trust

Rating88/100
Number of ratings280
Active installs100K
Developer Profile

Minimal Coming Soon – Coming Soon Page Developer Profile

WebFactory

28 plugins · 3.5M total installs

78
trust score
Avg Security Score
98/100
Avg Patch Time
699 days
View full developer profile
Detection Fingerprints

How We Detect Minimal Coming Soon – Coming Soon Page

Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.

Asset Fingerprints

Asset Paths
/wp-content/plugins/minimal-coming-soon-maintenance-mode/framework/public/css/font-awesome.min.css/wp-content/plugins/minimal-coming-soon-maintenance-mode/framework/public/css/coming-soon.css/wp-content/plugins/minimal-coming-soon-maintenance-mode/framework/public/js/coming-soon.js
Script Paths
/wp-content/plugins/minimal-coming-soon-maintenance-mode/framework/public/js/coming-soon.js
Version Parameters
minimal-coming-soon-maintenance-mode/framework/public/css/font-awesome.min.css?ver=minimal-coming-soon-maintenance-mode/framework/public/css/coming-soon.css?ver=minimal-coming-soon-maintenance-mode/framework/public/js/coming-soon.js?ver=

HTML / DOM Fingerprints

CSS Classes
csmm-logocsmm-header-textcsmm-secondary-textcsmm-formcsmm-inputcsmm-buttoncsmm-gdpr-checkbox
Data Attributes
data-csmm-content-widthdata-csmm-bg-colordata-csmm-content-positiondata-csmm-content-alignmentdata-csmm-header-fontdata-csmm-secondary-font+16 more
JS Globals
csmm_script_vars
FAQ

Frequently Asked Questions about Minimal Coming Soon – Coming Soon Page