
SiteHandoff Security & Risk Analysis
wordpress.org/plugins/sitehandoffClient handoff tool for agencies: manage reviewer access, collect per-page feedback, and run a countdown page while the site is in progress.
Is SiteHandoff Safe to Use in 2026?
Generally Safe
Score 100/100SiteHandoff has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.
The "sitehandoff" plugin version 1.2.1 exhibits a generally strong security posture based on the provided static analysis. The plugin demonstrates excellent adherence to secure coding practices, with a high percentage of properly escaped output and a significant number of capability checks. Notably, there are no identified critical or high severity taint flows, and the plugin does not appear to make external HTTP requests, reducing the risk of certain types of attacks. The absence of known CVEs further bolsters confidence in its current security state.
However, a few areas warrant attention. While all identified AJAX handlers have authentication checks, the presence of 6 AJAX handlers indicates a potential attack surface that, if any vulnerabilities were discovered in the future, could be exploited. The SQL query usage, while showing a decent percentage of prepared statements, still leaves a portion vulnerable to SQL injection if not handled with extreme care in the remaining queries. The single file operation, though not inherently dangerous, could be a point of concern depending on its implementation and the input it processes.
Overall, "sitehandoff" v1.2.1 appears to be a well-secured plugin with no readily apparent critical vulnerabilities. The developers seem to have implemented good security practices, particularly around output escaping and authentication. The main areas for continued vigilance are the potential for future undiscovered vulnerabilities within the existing attack surface and ensuring the proper sanitization and preparation of all SQL queries.
Key Concerns
- SQL queries not using prepared statements
- Presence of file operations
SiteHandoff Security Vulnerabilities
SiteHandoff Release Timeline
SiteHandoff Code Analysis
SQL Query Safety
Output Escaping
Data Flow Analysis
SiteHandoff Attack Surface
AJAX Handlers 6
WordPress Hooks 12
Maintenance & Trust
SiteHandoff Maintenance & Trust
Maintenance Signals
Community Trust
SiteHandoff Alternatives
Maintenance
maintenance
Great looking maintenance, coming soon & under construction pages. Put your site under maintenance in minutes.
Website Builder by SeedProd — Theme Builder, Landing Page Builder, Coming Soon Page, Maintenance Mode
coming-soon
Easy Drag & Drop Page Builder. A complete solution to create a WordPress Website, Custom Themes, Landing Pages, Coming Soon & Maintenance Mode Pages.
LightStart – Maintenance Mode, Coming Soon and Landing Page Builder
wp-maintenance-mode
Easy Drag & Drop Page Builder that adds a splash page to your site that it's perfect for a coming soon page, maintenance or landing page.
CMP – Coming Soon & Maintenance Plugin by NiteoThemes
cmp-coming-soon-maintenance
Beautiful Coming soon, Maintenance or Landing page on your website, packed with premium features for free.
Minimal Coming Soon – Coming Soon Page
minimal-coming-soon-maintenance-mode
Minimal Coming Soon & Maintenance Mode page! Create awesome Coming Soon Pages in seconds.
SiteHandoff Developer Profile
1 plugin · 0 total installs
How We Detect SiteHandoff
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/sitehandoff/assets/css/working-progress.css/wp-content/plugins/sitehandoff/assets/js/working-progress-countdown.js/wp-content/plugins/sitehandoff/assets/js/working-progress-countdown.jssitehandoff/assets/css/working-progress.css?ver=sitehandoff/assets/js/working-progress-countdown.js?ver=HTML / DOM Fingerprints
sitehandoff__countdownsitehandoff__creditsiteHandoffAjaxSiteHandoffData/wp-json/sitehandoff/v1/feedback/wp-json/sitehandoff/v1/reviewer/wp-json/sitehandoff/v1/settings[sitehandoff_countdown]