TL Coming Soon – Maintenance Mode & Under Construction Security & Risk Analysis

wordpress.org/plugins/tl-coming-soon

Coming Soon, Maintenance Mode and Under Construction plugin for WordPress.

100 active installs v1.0.2 PHP 5.6+ WP 4.0+ Updated Apr 22, 2021
coming-soonlanding-pagelaunch-pagemaintenance-modeunder-construction
85
A · Safe
CVEs total0
Unpatched0
Last CVENever
Safety Verdict

Is TL Coming Soon – Maintenance Mode & Under Construction Safe to Use in 2026?

Generally Safe

Score 85/100

TL Coming Soon – Maintenance Mode & Under Construction has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.

No known CVEs Updated 5yr ago
Risk Assessment

The 'tl-coming-soon' plugin v1.0.2 presents a concerning security posture primarily due to its unprotected AJAX handlers, which constitute a significant portion of its attack surface. While the plugin demonstrates good practices in other areas, such as the exclusive use of prepared statements for SQL queries and a lack of critical or high severity taint flows, the absence of authentication checks on all 14 AJAX endpoints creates a substantial risk. This could allow unauthenticated users to trigger unintended actions or potentially exploit vulnerabilities that might be present but not immediately obvious in the static analysis. The plugin's clean vulnerability history is a positive indicator, suggesting a general lack of discovered security flaws. However, this does not negate the inherent risk posed by the exposed AJAX endpoints, which represent a clear vulnerability in its security design. Overall, the plugin has strengths in its handling of database operations and output sanitation but suffers from a critical weakness in its access control for its AJAX interface.

Key Concerns

  • Unprotected AJAX handlers
  • Unsanitized paths in taint analysis
  • Limited capability checks
  • Bundled outdated library (Select2)
Vulnerabilities
None known

TL Coming Soon – Maintenance Mode & Under Construction Security Vulnerabilities

No known vulnerabilities — this is a good sign.
Version History

TL Coming Soon – Maintenance Mode & Under Construction Release Timeline

v1.0.2Current
v1.0.1
v1.0.0
Code Analysis
Analyzed Mar 16, 2026

TL Coming Soon – Maintenance Mode & Under Construction Code Analysis

Dangerous Functions
0
Raw SQL Queries
0
0 prepared
Unescaped Output
116
176 escaped
Nonce Checks
0
Capability Checks
1
File Operations
1
External Requests
5
Bundled Libraries
1

Bundled Libraries

Select2

Output Escaping

60% escaped292 total outputs
Data Flows · Security
2 unsanitized

Data Flow Analysis

3 flows2 with unsanitized paths
render_settings_page_content (admin\class-tl-coming-soon-settings.php:40)
Source (user input) Sink (dangerous op) Sanitizer Transform Unsanitized Sanitized
Attack Surface
14 unprotected

TL Coming Soon – Maintenance Mode & Under Construction Attack Surface

Entry Points14
Unprotected14

AJAX Handlers 14

authwp_ajax_campaign_monitorfunctions.php:30
noprivwp_ajax_campaign_monitorfunctions.php:31
authwp_ajax_convertkitfunctions.php:97
noprivwp_ajax_convertkitfunctions.php:98
authwp_ajax_getresponsefunctions.php:146
noprivwp_ajax_getresponsefunctions.php:147
authwp_ajax_mailchimpfunctions.php:194
noprivwp_ajax_mailchimpfunctions.php:195
authwp_ajax_sendinbluefunctions.php:239
noprivwp_ajax_sendinbluefunctions.php:240
authwp_ajax_subscribe_formfunctions.php:324
noprivwp_ajax_subscribe_formfunctions.php:325
authwp_ajax_tlcs_togglefunctions.php:665
noprivwp_ajax_tlcs_togglefunctions.php:666
WordPress Hooks 18
actionadmin_enqueue_scriptsfunctions.php:10
actiontlcs_subscribe_form_ajaxfunctions.php:299
actionadmin_enqueue_scriptsfunctions.php:645
actionwp_enqueue_scriptsfunctions.php:646
actionadmin_bar_menufunctions.php:744
actionplugins_loadedincludes\class-tl-coming-soon.php:196
actionadmin_enqueue_scriptsincludes\class-tl-coming-soon.php:214
actionadmin_enqueue_scriptsincludes\class-tl-coming-soon.php:217
actionwp_enqueue_scriptsincludes\class-tl-coming-soon.php:218
actionadmin_menuincludes\class-tl-coming-soon.php:220
actionadmin_initincludes\class-tl-coming-soon.php:221
actionadmin_initincludes\class-tl-coming-soon.php:222
actionadmin_initincludes\class-tl-coming-soon.php:223
actionadmin_initincludes\class-tl-coming-soon.php:224
actionadmin_initincludes\class-tl-coming-soon.php:225
actionadmin_initincludes\class-tl-coming-soon.php:226
actiontemplate_includeincludes\class-tl-coming-soon.php:244
actiontemplate_includeincludes\class-tl-coming-soon.php:244
Maintenance & Trust

TL Coming Soon – Maintenance Mode & Under Construction Maintenance & Trust

Maintenance Signals

WordPress version tested5.6.17
Last updatedApr 22, 2021
PHP min version5.6
Downloads19K

Community Trust

Rating100/100
Number of ratings2
Active installs100
Developer Profile

TL Coming Soon – Maintenance Mode & Under Construction Developer Profile

ThemeLuxury

1 plugin · 100 total installs

84
trust score
Avg Security Score
85/100
Avg Patch Time
30 days
View full developer profile
Detection Fingerprints

How We Detect TL Coming Soon – Maintenance Mode & Under Construction

Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.

Asset Fingerprints

Asset Paths
/wp-content/plugins/tl-coming-soon/admin/assets/css/jquery.datetimepicker.min.css/wp-content/plugins/tl-coming-soon/admin/assets/css/select2.min.css/wp-content/plugins/tl-coming-soon/admin/assets/css/tl-coming-soon-admin.css/wp-content/plugins/tl-coming-soon/admin/assets/js/jquery.datetimepicker.full.min.js/wp-content/plugins/tl-coming-soon/admin/assets/js/select2.min.js/wp-content/plugins/tl-coming-soon/admin/assets/js/upload.js/wp-content/plugins/tl-coming-soon/admin/assets/js/tl-coming-soon-admin.js/wp-content/plugins/tl-coming-soon/admin/assets/js/subscribe.js
Script Paths
admin/assets/js/jquery.datetimepicker.full.min.jsadmin/assets/js/select2.min.jsadmin/assets/js/upload.jsadmin/assets/js/tl-coming-soon-admin.jsadmin/assets/js/subscribe.js
Version Parameters
tl-coming-soon/assets/css/jquery.datetimepicker.min.css?ver=tl-coming-soon/assets/css/select2.min.css?ver=tl-coming-soon/assets/css/tl-coming-soon-admin.css?ver=tl-coming-soon/assets/js/jquery.datetimepicker.full.min.js?ver=tl-coming-soon/assets/js/select2.min.js?ver=tl-coming-soon/assets/js/upload.js?ver=tl-coming-soon/assets/js/tl-coming-soon-admin.js?ver=tl-coming-soon/assets/js/subscribe.js?ver=

HTML / DOM Fingerprints

CSS Classes
tl-coming-soon-admin
HTML Comments
<!-- The code that runs during plugin activation. --><!-- The code that runs during plugin deactivation. --><!-- The class responsible for orchestrating the actions and filters of the * core plugin.+11 more
Data Attributes
data-nonce="subscribe-nonce"
JS Globals
doSubscribe
REST Endpoints
/wp-json/tl-coming-soon/v1/settings
FAQ

Frequently Asked Questions about TL Coming Soon – Maintenance Mode & Under Construction