WEN Maintenance Mode Security & Risk Analysis

wordpress.org/plugins/wen-maintenance-mode

The fastest & simplest maintenance page for WordPress site. Super-easy to use!

90 active installs v1.5 PHP 7.4+ WP 6.0+ Updated May 13, 2025
coming-soon-pagelanding-pagemaintenancemaintenance-modemaintenance-page
92
A · Safe
CVEs total0
Unpatched0
Last CVENever
Download
Safety Verdict

Is WEN Maintenance Mode Safe to Use in 2026?

Generally Safe

Score 92/100

WEN Maintenance Mode has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.

No known CVEs Updated 1yr ago
Risk Assessment

The "wen-maintenance-mode" v1.5 plugin exhibits a generally positive security posture based on the static analysis provided. The absence of any recorded vulnerabilities (CVEs) and a clean vulnerability history suggest a well-maintained and likely secure codebase.

However, the static analysis reveals some areas for improvement. A significant concern is the high percentage of unsanitized output (79%) and the presence of unsanitized paths in taint analysis flows. Although no critical or high severity issues were flagged, these represent potential avenues for cross-site scripting (XSS) or other injection attacks if an attacker can control user input that eventually reaches these unescaped outputs or unsanitized paths.

The plugin's limited attack surface, with no AJAX handlers, REST API routes, or shortcodes, is a strength. The presence of nonce checks, albeit not on all potential entry points, is also a positive sign. Nevertheless, the 0% usage of prepared statements for the single SQL query is a notable weakness. If this query is ever exposed to user-controlled input, it could be vulnerable to SQL injection, despite the lack of reported vulnerabilities to date.

Key Concerns

  • Raw SQL queries without prepared statements
  • High percentage of unsafely escaped output
  • Unsanitized paths in taint analysis flows
Vulnerabilities
None known

WEN Maintenance Mode Security Vulnerabilities

No known vulnerabilities — this is a good sign.
Version History

WEN Maintenance Mode Release Timeline

v1.5Current
v1.4
v1.3
v1.2
v1.1
v1.0
Code Analysis
Analyzed Mar 16, 2026

WEN Maintenance Mode Code Analysis

Dangerous Functions
0
Raw SQL Queries
1
0 prepared
Unescaped Output
68
18 escaped
Nonce Checks
4
Capability Checks
0
File Operations
0
External Requests
0
Bundled Libraries
0

SQL Query Safety

0% prepared1 total queries

Output Escaping

21% escaped86 total outputs
Data Flows · Security
4 unsanitized

Data Flow Analysis

6 flows4 with unsanitized paths
wmm_settings_page (inc\classes\admin.php:44)
Source (user input) Sink (dangerous op) Sanitizer Transform Unsanitized Sanitized
Attack Surface

WEN Maintenance Mode Attack Surface

Entry Points0
Unprotected0
WordPress Hooks 9
actionadmin_menuinc\classes\admin.php:5
actionadmin_enqueue_scriptsinc\classes\admin.php:7
filterplugin_action_links_wen-maintenance-mode/wen-maintenance-mode.phpinc\classes\admin.php:10
filtercron_scheduleswen-maintenance-mode.php:30
actionplugins_loadedwen-maintenance-mode.php:65
actiontemplate_redirectwen-maintenance-mode.php:86
actionadmin_bar_menuwen-maintenance-mode.php:104
actionwmm_check_disable_maintenancewen-maintenance-mode.php:128
actioninitwen-maintenance-mode.php:129

Scheduled Events 1

wmm_check_disable_maintenance
Maintenance & Trust

WEN Maintenance Mode Maintenance & Trust

Maintenance Signals

WordPress version tested6.8.5
Last updatedMay 13, 2025
PHP min version7.4
Downloads3K

Community Trust

Rating0/100
Number of ratings0
Active installs90
Developer Profile

WEN Maintenance Mode Developer Profile

Web Experts Nepal

3 plugins · 90 total installs

88
trust score
Avg Security Score
92/100
Avg Patch Time
30 days
View full developer profile
Detection Fingerprints

How We Detect WEN Maintenance Mode

Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.

Asset Fingerprints

Asset Paths
/wp-content/plugins/wen-maintenance-mode/assets/css/admin-style.css/wp-content/plugins/wen-maintenance-mode/assets/js/admin.js
Script Paths
/wp-content/plugins/wen-maintenance-mode/assets/js/admin.js
Version Parameters
wen-maintenance-mode/assets/css/admin-style.css?ver=wen-maintenance-mode/assets/js/admin.js?ver=

HTML / DOM Fingerprints

CSS Classes
maintenance-status
Data Attributes
data-ondata-off
FAQ

Frequently Asked Questions about WEN Maintenance Mode