
WIP Incoming Lite Security & Risk Analysis
wordpress.org/plugins/wip-incoming-liteWIP Incoming Lite is a free Coming Soon, Under Construction & Maintenance Mode WordPress plugin and allows you to manage a launch / under construc …
Is WIP Incoming Lite Safe to Use in 2026?
Generally Safe
Score 91/100WIP Incoming Lite has a strong security track record. Known vulnerabilities have been patched promptly. It's a solid choice for most WordPress installations.
The "wip-incoming-lite" plugin v1.1.2 presents a mixed security posture. On one hand, the static analysis indicates a very small attack surface with no exposed AJAX handlers, REST API routes, shortcodes, or cron events. This is a positive sign as it limits potential entry points for attackers. However, the presence of dangerous functions like `unserialize` is a significant concern, as is the fact that 100% of its single SQL query does not use prepared statements, making it vulnerable to SQL injection. The low percentage of properly escaped output (16%) also suggests a risk of Cross-Site Scripting (XSS) vulnerabilities.
The vulnerability history reveals one past medium-severity CVE, specifically a Cross-Site Request Forgery (CSRF) vulnerability. While there are no currently unpatched vulnerabilities, the presence of a past CSRF issue, combined with the lack of robust input sanitization and output escaping in the code analysis, suggests a pattern of potential weaknesses. The taint analysis shows a flow with an unsanitized path, further reinforcing concerns about input handling.
In conclusion, while the plugin has a limited attack surface, the identified code quality issues, particularly the unescaped output, raw SQL queries, and the use of `unserialize`, coupled with a history of a medium-severity vulnerability, warrant caution. Developers should prioritize addressing these areas to improve the plugin's overall security.
Key Concerns
- SQL queries not using prepared statements
- Dangerous function usage (unserialize)
- Low percentage of properly escaped output
- Flow with unsanitized paths in taint analysis
- Medium severity CVE in vulnerability history
WIP Incoming Lite Security Vulnerabilities
CVEs by Year
Severity Breakdown
1 total CVE
WIP Incoming Lite <= 1.1.1 - Cross-Site Request Forgery to Stored Cross-Site Scripting
WIP Incoming Lite Release Timeline
WIP Incoming Lite Code Analysis
Dangerous Functions Found
SQL Query Safety
Output Escaping
Data Flow Analysis
WIP Incoming Lite Attack Surface
WordPress Hooks 8
Maintenance & Trust
WIP Incoming Lite Maintenance & Trust
Maintenance Signals
Community Trust
WIP Incoming Lite Alternatives
Under Construction
under-construction-page
Easy to use Under Construction Page & Coming Soon Page. Enable Under Construction Mode in seconds & show you're Under Construction!
CMP – Coming Soon & Maintenance Plugin by NiteoThemes
cmp-coming-soon-maintenance
Beautiful Coming soon, Maintenance or Landing page on your website, packed with premium features for free.
Maintenance Page
maintenance-page
Allows you to quickly create a maintenance/coming-soon page. Use this plugin whenever your site is down for maintenance or undergoing development.
Coming Soon Page & Maintenance Mode
responsive-coming-soon
Coming Soon Plugin and Maintenance Mode plugin with Launch page & site offline plugin for your Website while it's under construction.
WP Maintenance Mode & Site Under Construction
wp-maintenance-mode-site-under-construction
WP plugin for Under Construction, Maintenance Mode & Coming Soon Pages. Enable with one click & show a landing page to visitors easily.
WIP Incoming Lite Developer Profile
76 plugins · 10K total installs
How We Detect WIP Incoming Lite
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/wip-incoming-lite/assets/css/notice.css/wp-content/plugins/wip-incoming-lite/assets/css/panel.css/wp-content/plugins/wip-incoming-lite/assets/css/on_off.css/wp-content/plugins/wip-incoming-lite/assets/css/jquery-ui.css/wp-content/plugins/wip-incoming-lite/assets/js/on_off.js/wp-content/plugins/wip-incoming-lite/assets/js/panel.js/wp-content/plugins/wip-incoming-lite/core/functions.wip-incoming-lite.phpwip-incoming-lite/style.css?ver=wip-incoming-lite/assets/css/notice.css?ver=wip-incoming-lite/assets/css/panel.css?ver=wip-incoming-lite/assets/css/on_off.css?ver=wip-incoming-lite/assets/css/jquery-ui.css?ver=wip-incoming-lite/assets/js/on_off.js?ver=wip-incoming-lite/assets/js/panel.js?ver=HTML / DOM Fingerprints
WIP_plugin_panel_messagewip-incoming-lite-countdown-timerdata-wip-incoming-tabwip_incoming_settingwip_incoming_countdown