Super Simple Site Offline Security & Risk Analysis

wordpress.org/plugins/super-simple-site-offline-beta

Hide or redirect your website in an instant! The Super Simple Site Offline Plugin does exactly that and is above all easy to customize and track via Google Analytics or Google Tagmanager. But for your visitor just a nice little maintenance message or redirect. Nothing more.

6K active installs v2.2 PHP + WP + Updated Aug 4, 2022
85
A · Safe
CVEs total0
Unpatched0
Last CVENever
Safety Verdict

Is Super Simple Site Offline Safe to Use in 2026?

Generally Safe

Score 85/100

Super Simple Site Offline has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.

No known CVEs Updated 3yr ago
Risk Assessment

The "super-simple-site-offline-beta" v2.2 plugin exhibits a generally good security posture based on the provided static analysis. The absence of any registered AJAX handlers, REST API routes, shortcodes, or cron events significantly limits the plugin's attack surface. Furthermore, the code demonstrates a commitment to secure coding practices with 100% of SQL queries using prepared statements and the presence of nonce and capability checks. This indicates a thoughtful approach to preventing common WordPress vulnerabilities.

However, a critical concern arises from the taint analysis, which identified one flow with an unsanitized path. While no critical or high severity issues were reported, an unsanitized path can be a precursor to vulnerabilities like Local File Inclusion (LFI) or Path Traversal if the data is user-controlled and not properly validated or escaped before being used in file operations or other sensitive contexts. The plugin's vulnerability history is also clean, with no recorded CVEs, which is a positive indicator. Despite the small attack surface and good practices in other areas, the single unsanitized path flow presents a potential risk that warrants attention.

Key Concerns

  • Unsanitized path in taint analysis
  • Improper output escaping (59% escaped)
Vulnerabilities
None known

Super Simple Site Offline Security Vulnerabilities

No known vulnerabilities — this is a good sign.
Version History

Super Simple Site Offline Release Timeline

v2.2Current
v2.0.2
v2.0.1
v2.0
v1.10
v1.9
v1.8.1
v1.8
v1.7.7
v1.7.4
v1.6.1
v1.6
v1.4
v1.3.5
v1.3
v1.2
v1.1
v1.0
v0.9
Code Analysis
Analyzed Mar 16, 2026

Super Simple Site Offline Code Analysis

Dangerous Functions
0
Raw SQL Queries
0
0 prepared
Unescaped Output
18
26 escaped
Nonce Checks
1
Capability Checks
4
File Operations
0
External Requests
0
Bundled Libraries
0

Output Escaping

59% escaped44 total outputs
Data Flows · Security
1 unsanitized

Data Flow Analysis

1 flows1 with unsanitized paths
<wp-admin-access> (template\wp-admin-access.php:0)
Source (user input) Sink (dangerous op) Sanitizer Transform Unsanitized Sanitized
Attack Surface

Super Simple Site Offline Attack Surface

Entry Points0
Unprotected0
WordPress Hooks 10
actionload-post.phpclasses\post.php:10
actionload-post-new.phpclasses\post.php:11
actionadd_meta_boxesclasses\post.php:23
actionsave_postclasses\post.php:24
actionadmin_menufunctions\admin.php:20
actionadmin_bar_menufunctions\admin.php:51
actionadmin_enqueue_scriptsfunctions\admin.php:60
actionadmin_initfunctions\admin.php:116
actionadmin_enqueue_scriptsfunctions\admin.php:122
actiontemplate_redirectfunctions\offline.php:35
Maintenance & Trust

Super Simple Site Offline Maintenance & Trust

Maintenance Signals

WordPress version tested
Last updatedAug 4, 2022
PHP min version
Downloads86K

Community Trust

Rating96/100
Number of ratings18
Active installs6K
Alternatives

Super Simple Site Offline Alternatives

No alternatives data available yet.

Developer Profile

Super Simple Site Offline Developer Profile

Rik

5 plugins · 6K total installs

84
trust score
Avg Security Score
85/100
Avg Patch Time
30 days
View full developer profile
Detection Fingerprints

How We Detect Super Simple Site Offline

Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.

Asset Fingerprints

Asset Paths
/wp-content/plugins/super-simple-site-offline-beta/css/admin.css
Version Parameters
super-simple-site-offline-beta/css/admin.css?ver=

HTML / DOM Fingerprints

CSS Classes
bcSOFF_offline
Data Attributes
name="bcSOFF_site_offline"name="bcSOFF_offline_redirect"name="bcSOFF_offline_header"name="bcSOFF_offline_redirect_url"name="bcSOFF_offline_ip_exempt"name="bcSOFF_offline_background_image"+7 more
FAQ

Frequently Asked Questions about Super Simple Site Offline