WCS Web Maintenance Security & Risk Analysis

wordpress.org/plugins/wcs-web-maintenance

Add feature "Under Construction" or "Site closed for maintenance"

200 active installs v0.1 PHP + WP 4.3+ Updated Nov 28, 2017
constructionmaintenancemaintenance-modemantenimientounder-construction
85
A · Safe
CVEs total0
Unpatched0
Last CVENever
Download
Safety Verdict

Is WCS Web Maintenance Safe to Use in 2026?

Generally Safe

Score 85/100

WCS Web Maintenance has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.

No known CVEs Updated 8yr ago
Risk Assessment

The wcs-web-maintenance plugin version 0.1 exhibits a mixed security posture. On the positive side, it demonstrates good practices by using prepared statements for all SQL queries, properly escaping a high percentage of output, and including nonce and capability checks for some entry points. There are no recorded vulnerabilities (CVEs) or critical issues flagged in the taint analysis, indicating a potentially clean code base from known exploits and severe data handling flaws.

However, a significant concern arises from the presence of one unprotected AJAX handler. This represents a direct attack vector that any unauthenticated user could potentially leverage, leading to unauthorized actions or information disclosure. While the overall taint analysis and SQL handling are strong, this single unprotected entry point significantly elevates the risk profile. The absence of any recorded vulnerabilities in its history is a positive sign, but it doesn't negate the immediate risks presented by the current code's exposed functionality.

In conclusion, the plugin shows strengths in data handling and output sanitization. The primary weakness lies in the single AJAX handler lacking authentication. This unprotected entry point is the most critical finding and requires immediate attention. While the lack of historical vulnerabilities is encouraging, it's crucial to address the identified security gap to maintain a robust security posture.

Key Concerns

  • AJAX handler without authentication
Vulnerabilities
None known

WCS Web Maintenance Security Vulnerabilities

No known vulnerabilities — this is a good sign.
Code Analysis
Analyzed Mar 16, 2026

WCS Web Maintenance Code Analysis

Dangerous Functions
0
Raw SQL Queries
0
0 prepared
Unescaped Output
7
40 escaped
Nonce Checks
2
Capability Checks
3
File Operations
0
External Requests
0
Bundled Libraries
0

Output Escaping

85% escaped47 total outputs
Data Flows
All sanitized

Data Flow Analysis

2 flows
settings_page (wcs-web-maintenance.php:228)
Source (user input) Sink (dangerous op) Sanitizer Transform Unsanitized Sanitized
Attack Surface
1 unprotected

WCS Web Maintenance Attack Surface

Entry Points1
Unprotected1

AJAX Handlers 1

authwp_ajax_maintenance_mode_change_statewcs-web-maintenance.php:176
WordPress Hooks 9
actionadmin_initwcs-web-maintenance.php:46
actionadmin_menuwcs-web-maintenance.php:52
actiontemplate_redirectwcs-web-maintenance.php:55
actionplugins_loadedwcs-web-maintenance.php:61
actionadmin_enqueue_scriptswcs-web-maintenance.php:64
actionadmin_footerwcs-web-maintenance.php:174
actionwp_dashboard_setupwcs-web-maintenance.php:175
actionadmin_bar_menuwcs-web-maintenance.php:178
actionadmin_headwcs-web-maintenance.php:432
Maintenance & Trust

WCS Web Maintenance Maintenance & Trust

Maintenance Signals

WordPress version tested4.9.29
Last updatedNov 28, 2017
PHP min version
Downloads4K

Community Trust

Rating0/100
Number of ratings0
Active installs200
Developer Profile

WCS Web Maintenance Developer Profile

zipbreake

1 plugin · 200 total installs

84
trust score
Avg Security Score
85/100
Avg Patch Time
30 days
View full developer profile
Detection Fingerprints

How We Detect WCS Web Maintenance

Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.

Asset Fingerprints

Asset Paths
/wp-content/plugins/wcs-web-maintenance/css/style.css/wp-content/plugins/wcs-web-maintenance/css/maintenance.css
Script Paths
/wp-content/plugins/wcs-web-maintenance/scripts.js
Version Parameters
wcs-web-maintenance/css/style.css?ver=wcs-web-maintenance/css/maintenance.css?ver=wcs-web-maintenance/scripts.js?ver=

HTML / DOM Fingerprints

Data Attributes
data-action
JS Globals
wcs_web_maintenance
FAQ

Frequently Asked Questions about WCS Web Maintenance