Coming Soon & Maintenance Mode Page & Under Construction Security & Risk Analysis

wordpress.org/plugins/nifty-coming-soon-and-under-construction-page

Nifty Coming Soon & Maintenance Page creates awesome Coming Soon & Maintenance Pages.

20K active installs v3.0.17 PHP 5.6+ WP 4.9+ Updated Dec 27, 2025
coming-sooncoming-soon-pagelaunch-pagemaintenance-modemaintenance-page
99
A · Safe
CVEs total2
Unpatched0
Last CVESep 16, 2020
Safety Verdict

Is Coming Soon & Maintenance Mode Page & Under Construction Safe to Use in 2026?

Generally Safe

Score 99/100

Coming Soon & Maintenance Mode Page & Under Construction has a strong security track record. Known vulnerabilities have been patched promptly.

2 known CVEsLast CVE: Sep 16, 2020Updated 3mo ago
Risk Assessment

The "nifty-coming-soon-and-under-construction-page" plugin v3.0.17 exhibits a mixed security posture. On one hand, it demonstrates good practices by exclusively using prepared statements for SQL queries and having a high percentage of properly escaped output. It also shows no evidence of file operations or external HTTP requests, and the absence of dangerous functions and taint analysis findings is positive. However, significant security concerns arise from its attack surface. With two AJAX handlers, both completely lacking authentication checks, this plugin exposes potential entry points for unauthorized actions.

The vulnerability history reveals a past with two known CVEs, including one high and one medium severity vulnerability, primarily of the Cross-Site Request Forgery (CSRF) type. While there are currently no unpatched vulnerabilities, the historical pattern suggests that the plugin has had issues with securing against certain types of attacks, particularly those related to unauthorized actions. The lack of nonce checks on the identified AJAX handlers directly correlates with the historical prevalence of CSRF vulnerabilities, indicating a persistent blind spot in securing user-initiated actions.

In conclusion, while the plugin has strengths in its data handling and output sanitization, the presence of unprotected AJAX endpoints is a critical security weakness. This, combined with past CSRF vulnerabilities, creates a significant risk for unauthorized data modification or plugin setting changes. Users should be cautious, and further investigation into the specific functionality of these AJAX handlers is recommended to understand the full scope of potential impact.

Key Concerns

  • Unprotected AJAX handlers
  • No nonce checks on AJAX handlers
  • High severity vulnerability in history
  • Medium severity vulnerability in history
Vulnerabilities
2

Coming Soon & Maintenance Mode Page & Under Construction Security Vulnerabilities

CVEs by Year

2 CVEs in 2020
2020
Patched Has unpatched

Severity Breakdown

High
1
Medium
1

2 total CVEs

CVE-2020-36707high · 8.8Cross-Site Request Forgery (CSRF)

Coming Soon & Maintenance Mode Page <= 1.57 - Cross-Site Request Forgery

Sep 16, 2020 Patched in 1.58 (1224d)
CVE-2020-36752medium · 4.3Cross-Site Request Forgery (CSRF)

Coming Soon & Maintenance Mode Page <= 1.57 - Cross-Site Request Forgery Bypass

Sep 16, 2020 Patched in 1.58 (1224d)
Code Analysis
Analyzed Mar 16, 2026

Coming Soon & Maintenance Mode Page & Under Construction Code Analysis

Dangerous Functions
0
Raw SQL Queries
0
2 prepared
Unescaped Output
9
88 escaped
Nonce Checks
0
Capability Checks
0
File Operations
0
External Requests
0
Bundled Libraries
0

SQL Query Safety

100% prepared2 total queries

Output Escaping

91% escaped97 total outputs
Attack Surface
2 unprotected

Coming Soon & Maintenance Mode Page & Under Construction Attack Surface

Entry Points2
Unprotected2

AJAX Handlers 2

authwp_ajax_nifty_cs_subscribeinc\hooks\subscription.php:66
noprivwp_ajax_nifty_cs_subscribeinc\hooks\subscription.php:67
WordPress Hooks 25
actionwp_welcome_initinc\admin-page\admin-page.php:10
actionadmin_enqueue_scriptsinc\admin-page\admin-page.php:223
actioncustomize_registerinc\customizer\init.php:39
actioncustomize_controls_enqueue_scriptsinc\customizer\init.php:58
actioncustomize_preview_initinc\customizer\init.php:80
actionadmin_bar_menuinc\hooks\admin.php:31
actionadmin_enqueue_scriptsinc\hooks\admin.php:59
actionadmin_initinc\hooks\admin.php:75
actionwp_loadedinc\hooks\hooks.php:9
actionplugins_loadedinc\hooks\hooks.php:20
filternifty_cs_body_classinc\hooks\hooks.php:51
actionnifty_cs_headinc\hooks\hooks.php:72
actionnifty_cs_headinc\hooks\hooks.php:117
actionnifty_cs_headinc\hooks\hooks.php:120
actionnifty_cs_headinc\hooks\hooks.php:161
actionnifty_cs_headinc\hooks\hooks.php:201
actionnifty_cs_headinc\hooks\hooks.php:221
actionnifty_cs_headinc\hooks\hooks.php:338
actionnifty_cs_footerinc\hooks\hooks.php:358
actionnifty_cs_footerinc\hooks\hooks.php:371
actionnifty_cs_footerinc\hooks\hooks.php:382
actionwp_enqueue_scriptsinc\hooks\hooks.php:421
actiontemplate_redirectinc\hooks\redirect.php:72
actiontemplate_redirectinc\hooks\redirect.php:83
actioninitinc\hooks\redirect.php:87
Maintenance & Trust

Coming Soon & Maintenance Mode Page & Under Construction Maintenance & Trust

Maintenance Signals

WordPress version tested6.9.4
Last updatedDec 27, 2025
PHP min version5.6
Downloads667K

Community Trust

Rating98/100
Number of ratings305
Active installs20K
Developer Profile

Coming Soon & Maintenance Mode Page & Under Construction Developer Profile

hookandhook

6 plugins · 121K total installs

75
trust score
Avg Security Score
94/100
Avg Patch Time
478 days
View full developer profile
Detection Fingerprints

How We Detect Coming Soon & Maintenance Mode Page & Under Construction

Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.

Asset Fingerprints

Asset Paths
/wp-content/plugins/nifty-coming-soon-and-under-construction-page/assets/css/main.css/wp-content/plugins/nifty-coming-soon-and-under-construction-page/assets/css/welcome.css/wp-content/plugins/nifty-coming-soon-and-under-construction-page/assets/js/main.js/wp-content/plugins/nifty-coming-soon-and-under-construction-page/assets/js/welcome.js
Script Paths
nifty-coming-soon-and-under-construction-page/assets/js/main.jsnifty-coming-soon-and-under-construction-page/assets/js/welcome.js
Version Parameters
nifty-coming-soon-and-under-construction-page/assets/css/main.css?ver=nifty-coming-soon-and-under-construction-page/assets/css/welcome.css?ver=nifty-coming-soon-and-under-construction-page/assets/js/main.js?ver=nifty-coming-soon-and-under-construction-page/assets/js/welcome.js?ver=

HTML / DOM Fingerprints

CSS Classes
ncs-themencs-theme-featuredncs-themes-grid
HTML Comments
Plugin Name: Nifty Coming Soon & Maintenance PageEasy to set up Coming Soon, Maintenance and Under Construction page.Render welcome page sidebar content.Render themes tab content.
Data Attributes
data-tags
FAQ

Frequently Asked Questions about Coming Soon & Maintenance Mode Page & Under Construction