
Really Simple Under Construction Page Security & Risk Analysis
wordpress.org/plugins/really-simple-under-constructionAdds a really simple version of a Under Construction page to your website. Use secret word in URL or IP addresses to a whitelist to by-pass for test p …
Is Really Simple Under Construction Page Safe to Use in 2026?
Use With Caution
Score 63/100Really Simple Under Construction Page has 1 unpatched vulnerability. Evaluate alternatives or apply available mitigations.
The 'really-simple-under-construction' plugin, version 1.4.6, exhibits a mixed security posture. On the positive side, the static analysis reveals a clean codebase with no identified dangerous functions, SQL queries executed with prepared statements, and a lack of file operations or external HTTP requests. The absence of a significant attack surface through AJAX, REST API, shortcodes, or cron events is also a strong positive. However, there are areas of concern. A notable weakness is the complete absence of nonce and capability checks, which could leave certain functionalities vulnerable if they were to be exposed in the future, although currently, there are no such exposed points. The output escaping, while mostly proper at 82%, still leaves a small percentage of outputs potentially vulnerable to cross-site scripting, especially given the plugin's history.
The vulnerability history is a significant concern. The presence of one unpatched medium severity CVE, specifically an Improper Neutralization of Input During Web Page Generation (Cross-site Scripting), indicates a persistent flaw. The recency of this vulnerability (May 2025) suggests that the issue may still be present in this version or a very recent update, and the fact that it's unpatched is a critical red flag. This pattern, even with only one recorded CVE, points to potential oversight in code review or a failure to address known security weaknesses in a timely manner. While the current static analysis doesn't reveal obvious vulnerabilities, the historical context, coupled with the minor output escaping concern and the lack of robust authorization checks, suggests a moderate risk that could be elevated if the plugin's functionality expands or if the unpatched CVE affects this version.
Key Concerns
- Unpatched medium severity CVE
- Missing nonce checks
- Missing capability checks
- Partially unsanitized output
Really Simple Under Construction Page Security Vulnerabilities
CVEs by Year
Severity Breakdown
1 total CVE
Really Simple Under Construction Page <= 1.4.6 - Authenticated (Administrator+) Stored Cross-Site Scripting
Really Simple Under Construction Page Code Analysis
Output Escaping
Really Simple Under Construction Page Attack Surface
WordPress Hooks 4
Maintenance & Trust
Really Simple Under Construction Page Maintenance & Trust
Maintenance Signals
Community Trust
Really Simple Under Construction Page Alternatives
Under Construction
under-construction-page
Easy to use Under Construction Page & Coming Soon Page. Enable Under Construction Mode in seconds & show you're Under Construction!
CMP – Coming Soon & Maintenance Plugin by NiteoThemes
cmp-coming-soon-maintenance
Beautiful Coming soon, Maintenance or Landing page on your website, packed with premium features for free.
Hide Page And Post Title
hide-page-and-post-title
Hide title on single pages and posts.
underConstruction
underconstruction
Creates a 'Coming Soon' page that will show for all users who are not logged in
Exclude Pages
exclude-pages
This plugin adds a checkbox, “include this page in menus”, uncheck this to exclude pages from the page navigation that users see on your site.
Really Simple Under Construction Page Developer Profile
3 plugins · 660 total installs
How We Detect Really Simple Under Construction Page
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/really-simple-under-construction/admin/css/rsuc-admin.css/wp-content/plugins/really-simple-under-construction/admin/js/rsuc-admin.jsreally-simple-under-construction/admin/css/rsuc-admin.css?ver=really-simple-under-construction/admin/js/rsuc-admin.js?ver=HTML / DOM Fingerprints
rsuc-admin-page