Rocket Maintenance Mode & Coming Soon Page Security & Risk Analysis

wordpress.org/plugins/rocket-maintenance-mode

Create great looking Maintenance Mode Page or Coming Soon Page that sets up in minutes.

4K active installs v4.4 PHP 7.0+ WP 3.1+ Updated Mar 18, 2024
coming-sooncoming-soon-pagemaintenancemaintenance-modemaintenance-mode-page
85
A · Safe
CVEs total1
Unpatched0
Last CVEDec 6, 2023
Safety Verdict

Is Rocket Maintenance Mode & Coming Soon Page Safe to Use in 2026?

Generally Safe

Score 85/100

Rocket Maintenance Mode & Coming Soon Page has a strong security track record. Known vulnerabilities have been patched promptly.

1 known CVELast CVE: Dec 6, 2023Updated 2yr ago
Risk Assessment

The rocket-maintenance-mode plugin v4.4 exhibits a mixed security posture. On the positive side, it has a very small attack surface with only one AJAX handler, and importantly, all identified entry points appear to have authorization checks. The absence of dangerous functions, file operations, and external HTTP requests is also encouraging. However, significant concerns arise from the handling of SQL queries and output escaping. The static analysis reveals that 100% of SQL queries are not using prepared statements, which is a critical vulnerability for potential SQL injection. Furthermore, only 38% of output is properly escaped, indicating a high risk of Cross-Site Scripting (XSS) vulnerabilities across various outputs.

The vulnerability history shows one past medium-severity CVE related to Cross-Site Scripting, last patched in December 2023. While there are no currently unpatched vulnerabilities, the historical occurrence of XSS, coupled with the static analysis findings of poor output escaping, suggests a recurring pattern of insecure input/output handling. The plugin also bundles Freemius v1.0, which, if outdated, could introduce additional risks, though its specific version doesn't immediately indicate a severe issue without further context on Freemius's security history.

In conclusion, while the plugin has a limited attack surface and has addressed past vulnerabilities, the lack of prepared statements for SQL and the low percentage of properly escaped output present substantial risks. The historical XSS vulnerability reinforces these concerns. Further investigation into the specific SQL queries and output points is highly recommended to mitigate these identified weaknesses.

Key Concerns

  • 100% of SQL queries not using prepared statements
  • Only 38% of output properly escaped
  • Bundled library Freemius v1.0 potentially outdated
Vulnerabilities
1

Rocket Maintenance Mode & Coming Soon Page Security Vulnerabilities

CVEs by Year

1 CVE in 2023
2023
Patched Has unpatched

Severity Breakdown

Medium
1

1 total CVE

CVE-2023-49842medium · 4.4Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')

Rocket Maintenance Mode & Coming Soon Page <= 4.3 - Authenticated (Administrator+) Stored Cross-Site Scripting

Dec 6, 2023 Patched in 4.4 (108d)
Code Analysis
Analyzed Mar 16, 2026

Rocket Maintenance Mode & Coming Soon Page Code Analysis

Dangerous Functions
0
Raw SQL Queries
1
0 prepared
Unescaped Output
86
53 escaped
Nonce Checks
3
Capability Checks
3
File Operations
0
External Requests
0
Bundled Libraries
1

Bundled Libraries

Freemius1.0

SQL Query Safety

0% prepared1 total queries

Output Escaping

38% escaped139 total outputs
Attack Surface

Rocket Maintenance Mode & Coming Soon Page Attack Surface

Entry Points1
Unprotected0

AJAX Handlers 1

authwp_ajax_wpmmp_reset_settingsincludes\classes\class-wpmmp-settings.php:29
WordPress Hooks 26
actionwpmmp_headincludes\classes\class-wpmmp-cs-simple-theme.php:25
actionwpmmp_footerincludes\classes\class-wpmmp-cs-simple-theme.php:28
actionadmin_menuincludes\classes\class-wpmmp-settings.php:25
actioninitincludes\classes\class-wpmmp-settings.php:27
actioninitincludes\classes\class-wpmmp-settings.php:31
actionadmin_initincludes\classes\class-wpmmp-settings.php:33
filterwpmmp_themesincludes\classes\class-wpmmp-theme-handler.php:51
actionshutdownincludes\classes\class-wpmmp-theme-handler.php:175
actiontemplate_redirectincludes\classes\class-wpmmp-theme-handler.php:177
actionshutdownincludes\classes\class-wpmmp-theme-handler.php:197
actiontemplate_redirectincludes\classes\class-wpmmp-theme-handler.php:199
actiondo_feedincludes\classes\class-wpmmp-theme-handler.php:282
actiondo_feed_rdfincludes\classes\class-wpmmp-theme-handler.php:283
actiondo_feed_rssincludes\classes\class-wpmmp-theme-handler.php:284
actiondo_feed_rss2includes\classes\class-wpmmp-theme-handler.php:285
actiondo_feed_atomincludes\classes\class-wpmmp-theme-handler.php:286
actiondo_feed_rss2_commentsincludes\classes\class-wpmmp-theme-handler.php:287
actiondo_feed_atom_commentsincludes\classes\class-wpmmp-theme-handler.php:288
filterplugins_api_resultincludes\functions.php:44
actionplugins_loadedincludes\functions.php:154
filterrest_pre_dispatchincludes\functions.php:155
filterinstall_plugins_table_api_args_featuredincludes\functions.php:156
actionadmin_action_install_notificationxincludes\functions.php:265
actionadmin_menuincludes\tabs.php:3
actionadmin_initincludes\tabs.php:7
actionadmin_enqueue_scriptsincludes\tabs.php:103
Maintenance & Trust

Rocket Maintenance Mode & Coming Soon Page Maintenance & Trust

Maintenance Signals

WordPress version tested6.4.8
Last updatedMar 18, 2024
PHP min version7.0
Downloads393K

Community Trust

Rating84/100
Number of ratings24
Active installs4K
Developer Profile

Rocket Maintenance Mode & Coming Soon Page Developer Profile

Saad Iqbal

84 plugins · 1.4M total installs

76
trust score
Avg Security Score
96/100
Avg Patch Time
287 days
View full developer profile
Detection Fingerprints

How We Detect Rocket Maintenance Mode & Coming Soon Page

Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.

Asset Fingerprints

Asset Paths
/wp-content/plugins/rocket-maintenance-mode/css/admin-settings.css/wp-content/plugins/rocket-maintenance-mode/js/admin-settings.js
Version Parameters
rocket-maintenance-mode/css/admin-settings.css?ver=rocket-maintenance-mode/js/admin-settings.js?ver=

HTML / DOM Fingerprints

CSS Classes
wpmmp-settings-page
JS Globals
wpmmpjs
FAQ

Frequently Asked Questions about Rocket Maintenance Mode & Coming Soon Page