Really Simple Under Construction Page Security & Risk Analysis

wordpress.org/plugins/really-simple-under-construction

Adds a really simple version of a Under Construction page to your website. Use secret word in URL or IP addresses to a whitelist to by-pass for test p …

600 active installs v1.4.6 PHP 7.4+ WP 6.0.0+ Updated Aug 3, 2023
constructionhidehide-pagetemporary-siteunder-construction
63
C · Use Caution
CVEs total1
Unpatched1
Last CVEMay 7, 2025
Safety Verdict

Is Really Simple Under Construction Page Safe to Use in 2026?

Use With Caution

Score 63/100

Really Simple Under Construction Page has 1 unpatched vulnerability. Evaluate alternatives or apply available mitigations.

1 known CVE 1 unpatched Last CVE: May 7, 2025Updated 2yr ago
Risk Assessment

The 'really-simple-under-construction' plugin, version 1.4.6, exhibits a mixed security posture. On the positive side, the static analysis reveals a clean codebase with no identified dangerous functions, SQL queries executed with prepared statements, and a lack of file operations or external HTTP requests. The absence of a significant attack surface through AJAX, REST API, shortcodes, or cron events is also a strong positive. However, there are areas of concern. A notable weakness is the complete absence of nonce and capability checks, which could leave certain functionalities vulnerable if they were to be exposed in the future, although currently, there are no such exposed points. The output escaping, while mostly proper at 82%, still leaves a small percentage of outputs potentially vulnerable to cross-site scripting, especially given the plugin's history.

The vulnerability history is a significant concern. The presence of one unpatched medium severity CVE, specifically an Improper Neutralization of Input During Web Page Generation (Cross-site Scripting), indicates a persistent flaw. The recency of this vulnerability (May 2025) suggests that the issue may still be present in this version or a very recent update, and the fact that it's unpatched is a critical red flag. This pattern, even with only one recorded CVE, points to potential oversight in code review or a failure to address known security weaknesses in a timely manner. While the current static analysis doesn't reveal obvious vulnerabilities, the historical context, coupled with the minor output escaping concern and the lack of robust authorization checks, suggests a moderate risk that could be elevated if the plugin's functionality expands or if the unpatched CVE affects this version.

Key Concerns

  • Unpatched medium severity CVE
  • Missing nonce checks
  • Missing capability checks
  • Partially unsanitized output
Vulnerabilities
1

Really Simple Under Construction Page Security Vulnerabilities

CVEs by Year

1 CVE in 2025 · unpatched
2025
Patched Has unpatched

Severity Breakdown

Medium
1

1 total CVE

CVE-2025-47593medium · 5.5Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')

Really Simple Under Construction Page <= 1.4.6 - Authenticated (Administrator+) Stored Cross-Site Scripting

May 7, 2025Unpatched
Code Analysis
Analyzed Mar 16, 2026

Really Simple Under Construction Page Code Analysis

Dangerous Functions
0
Raw SQL Queries
0
0 prepared
Unescaped Output
2
9 escaped
Nonce Checks
0
Capability Checks
0
File Operations
0
External Requests
0
Bundled Libraries
0

Output Escaping

82% escaped11 total outputs
Attack Surface

Really Simple Under Construction Page Attack Surface

Entry Points0
Unprotected0
WordPress Hooks 4
actionplugins_loadedreally-simple-under-construction.php:17
actionadmin_menureally-simple-under-construction.php:109
actionadmin_initreally-simple-under-construction.php:117
filterplugin_action_links_really-simple-under-construction/really-simple-under-construction.phpreally-simple-under-construction.php:233
Maintenance & Trust

Really Simple Under Construction Page Maintenance & Trust

Maintenance Signals

WordPress version tested6.2.9
Last updatedAug 3, 2023
PHP min version7.4
Downloads8K

Community Trust

Rating96/100
Number of ratings9
Active installs600
Developer Profile

Really Simple Under Construction Page Developer Profile

Jonas Hjalmarsson

3 plugins · 660 total installs

79
trust score
Avg Security Score
78/100
Avg Patch Time
30 days
View full developer profile
Detection Fingerprints

How We Detect Really Simple Under Construction Page

Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.

Asset Fingerprints

Asset Paths
/wp-content/plugins/really-simple-under-construction/admin/css/rsuc-admin.css/wp-content/plugins/really-simple-under-construction/admin/js/rsuc-admin.js
Version Parameters
really-simple-under-construction/admin/css/rsuc-admin.css?ver=really-simple-under-construction/admin/js/rsuc-admin.js?ver=

HTML / DOM Fingerprints

CSS Classes
rsuc-admin-page
FAQ

Frequently Asked Questions about Really Simple Under Construction Page