
Rocket Maintenance Mode & Coming Soon Page Security & Risk Analysis
wordpress.org/plugins/rocket-maintenance-modeCreate great looking Maintenance Mode Page or Coming Soon Page that sets up in minutes.
Is Rocket Maintenance Mode & Coming Soon Page Safe to Use in 2026?
Generally Safe
Score 85/100Rocket Maintenance Mode & Coming Soon Page has a strong security track record. Known vulnerabilities have been patched promptly.
The rocket-maintenance-mode plugin v4.4 exhibits a mixed security posture. On the positive side, it has a very small attack surface with only one AJAX handler, and importantly, all identified entry points appear to have authorization checks. The absence of dangerous functions, file operations, and external HTTP requests is also encouraging. However, significant concerns arise from the handling of SQL queries and output escaping. The static analysis reveals that 100% of SQL queries are not using prepared statements, which is a critical vulnerability for potential SQL injection. Furthermore, only 38% of output is properly escaped, indicating a high risk of Cross-Site Scripting (XSS) vulnerabilities across various outputs.
The vulnerability history shows one past medium-severity CVE related to Cross-Site Scripting, last patched in December 2023. While there are no currently unpatched vulnerabilities, the historical occurrence of XSS, coupled with the static analysis findings of poor output escaping, suggests a recurring pattern of insecure input/output handling. The plugin also bundles Freemius v1.0, which, if outdated, could introduce additional risks, though its specific version doesn't immediately indicate a severe issue without further context on Freemius's security history.
In conclusion, while the plugin has a limited attack surface and has addressed past vulnerabilities, the lack of prepared statements for SQL and the low percentage of properly escaped output present substantial risks. The historical XSS vulnerability reinforces these concerns. Further investigation into the specific SQL queries and output points is highly recommended to mitigate these identified weaknesses.
Key Concerns
- 100% of SQL queries not using prepared statements
- Only 38% of output properly escaped
- Bundled library Freemius v1.0 potentially outdated
Rocket Maintenance Mode & Coming Soon Page Security Vulnerabilities
CVEs by Year
Severity Breakdown
1 total CVE
Rocket Maintenance Mode & Coming Soon Page <= 4.3 - Authenticated (Administrator+) Stored Cross-Site Scripting
Rocket Maintenance Mode & Coming Soon Page Code Analysis
Bundled Libraries
SQL Query Safety
Output Escaping
Rocket Maintenance Mode & Coming Soon Page Attack Surface
AJAX Handlers 1
WordPress Hooks 26
Maintenance & Trust
Rocket Maintenance Mode & Coming Soon Page Maintenance & Trust
Maintenance Signals
Community Trust
Rocket Maintenance Mode & Coming Soon Page Alternatives
Landing Page Builder – Coming Soon page, Maintenance Mode, Lead Page, WordPress Landing Pages
page-builder-add
Easily create high-converting, responsive landing pages with 120+ templates using the free PluginOps Page Builder for WordPress.
Perfect Coming Soon Page
perfect-coming-soon-page
Perfect Coming Soon page enables you to use a light weighted plugin for multiple needs of coming soon,underconstruction or offline mode.
Simple Custom Coming Soon/Maintenance Mode
simple-custom-coming-soonmaintenance-mode
A customizable Coming Soon/Maintenance Mode plugin for WordPress that lets you display a professional coming soon or under-construction page—with coun …
Maintenance
maintenance
Great looking maintenance, coming soon & under construction pages. Put your site under maintenance in minutes.
Website Builder by SeedProd — Theme Builder, Landing Page Builder, Coming Soon Page, Maintenance Mode
coming-soon
Easy Drag & Drop Page Builder. A complete solution to create a WordPress Website, Custom Themes, Landing Pages, Coming Soon & Maintenance Mode Pages.
Rocket Maintenance Mode & Coming Soon Page Developer Profile
84 plugins · 1.4M total installs
How We Detect Rocket Maintenance Mode & Coming Soon Page
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/rocket-maintenance-mode/css/admin-settings.css/wp-content/plugins/rocket-maintenance-mode/js/admin-settings.jsrocket-maintenance-mode/css/admin-settings.css?ver=rocket-maintenance-mode/js/admin-settings.js?ver=HTML / DOM Fingerprints
wpmmp-settings-pagewpmmpjs