
Coming Soon & Maintenance Mode Page & Under Construction Security & Risk Analysis
wordpress.org/plugins/nifty-coming-soon-and-under-construction-pageNifty Coming Soon & Maintenance Page creates awesome Coming Soon & Maintenance Pages.
Is Coming Soon & Maintenance Mode Page & Under Construction Safe to Use in 2026?
Generally Safe
Score 99/100Coming Soon & Maintenance Mode Page & Under Construction has a strong security track record. Known vulnerabilities have been patched promptly.
The "nifty-coming-soon-and-under-construction-page" plugin v3.0.17 exhibits a mixed security posture. On one hand, it demonstrates good practices by exclusively using prepared statements for SQL queries and having a high percentage of properly escaped output. It also shows no evidence of file operations or external HTTP requests, and the absence of dangerous functions and taint analysis findings is positive. However, significant security concerns arise from its attack surface. With two AJAX handlers, both completely lacking authentication checks, this plugin exposes potential entry points for unauthorized actions.
The vulnerability history reveals a past with two known CVEs, including one high and one medium severity vulnerability, primarily of the Cross-Site Request Forgery (CSRF) type. While there are currently no unpatched vulnerabilities, the historical pattern suggests that the plugin has had issues with securing against certain types of attacks, particularly those related to unauthorized actions. The lack of nonce checks on the identified AJAX handlers directly correlates with the historical prevalence of CSRF vulnerabilities, indicating a persistent blind spot in securing user-initiated actions.
In conclusion, while the plugin has strengths in its data handling and output sanitization, the presence of unprotected AJAX endpoints is a critical security weakness. This, combined with past CSRF vulnerabilities, creates a significant risk for unauthorized data modification or plugin setting changes. Users should be cautious, and further investigation into the specific functionality of these AJAX handlers is recommended to understand the full scope of potential impact.
Key Concerns
- Unprotected AJAX handlers
- No nonce checks on AJAX handlers
- High severity vulnerability in history
- Medium severity vulnerability in history
Coming Soon & Maintenance Mode Page & Under Construction Security Vulnerabilities
CVEs by Year
Severity Breakdown
2 total CVEs
Coming Soon & Maintenance Mode Page <= 1.57 - Cross-Site Request Forgery
Coming Soon & Maintenance Mode Page <= 1.57 - Cross-Site Request Forgery Bypass
Coming Soon & Maintenance Mode Page & Under Construction Code Analysis
SQL Query Safety
Output Escaping
Coming Soon & Maintenance Mode Page & Under Construction Attack Surface
AJAX Handlers 2
WordPress Hooks 25
Maintenance & Trust
Coming Soon & Maintenance Mode Page & Under Construction Maintenance & Trust
Maintenance Signals
Community Trust
Coming Soon & Maintenance Mode Page & Under Construction Alternatives
Maintenance
maintenance
Great looking maintenance, coming soon & under construction pages. Put your site under maintenance in minutes.
CMP – Coming Soon & Maintenance Plugin by NiteoThemes
cmp-coming-soon-maintenance
Beautiful Coming soon, Maintenance or Landing page on your website, packed with premium features for free.
Super Easy Maintenance Mode – Coming Soon & Under Construction
super-easy-maintenance-mode
Enable coming soon page, maintenance mode, under construction page in just one click toggle.
Perfect Coming Soon Page
perfect-coming-soon-page
Perfect Coming Soon page enables you to use a light weighted plugin for multiple needs of coming soon,underconstruction or offline mode.
WEN Maintenance Mode
wen-maintenance-mode
The fastest & simplest maintenance page for WordPress site. Super-easy to use!
Coming Soon & Maintenance Mode Page & Under Construction Developer Profile
6 plugins · 121K total installs
How We Detect Coming Soon & Maintenance Mode Page & Under Construction
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/nifty-coming-soon-and-under-construction-page/assets/css/main.css/wp-content/plugins/nifty-coming-soon-and-under-construction-page/assets/css/welcome.css/wp-content/plugins/nifty-coming-soon-and-under-construction-page/assets/js/main.js/wp-content/plugins/nifty-coming-soon-and-under-construction-page/assets/js/welcome.jsnifty-coming-soon-and-under-construction-page/assets/js/main.jsnifty-coming-soon-and-under-construction-page/assets/js/welcome.jsnifty-coming-soon-and-under-construction-page/assets/css/main.css?ver=nifty-coming-soon-and-under-construction-page/assets/css/welcome.css?ver=nifty-coming-soon-and-under-construction-page/assets/js/main.js?ver=nifty-coming-soon-and-under-construction-page/assets/js/welcome.js?ver=HTML / DOM Fingerprints
ncs-themencs-theme-featuredncs-themes-gridPlugin Name: Nifty Coming Soon & Maintenance PageEasy to set up Coming Soon, Maintenance and Under Construction page.Render welcome page sidebar content.Render themes tab content.data-tags