WP Simple Maintenance & Under Construction Mode Security & Risk Analysis

wordpress.org/plugins/wp-simple-maintenance-mode

Create a simple Coming Soon Page, Under Construction or Maintenance Mode Page with WP Simple Maintenance Mode Plugin. Work on your site in private whi …

30 active installs v1.5.1 PHP 5.4+ WP 3.5.1+ Updated Feb 13, 2020
coming-sooncoming-soon-pagelanding-pagemaintenance-modeunder-construction
85
A · Safe
CVEs total0
Unpatched0
Last CVENever
Safety Verdict

Is WP Simple Maintenance & Under Construction Mode Safe to Use in 2026?

Generally Safe

Score 85/100

WP Simple Maintenance & Under Construction Mode has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.

No known CVEs Updated 6yr ago
Risk Assessment

The wp-simple-maintenance-mode plugin, version 1.5.1, exhibits a mixed security posture. While it largely avoids dangerous functions, uses prepared statements for nearly all SQL queries, and has no recorded vulnerabilities, there are significant concerns in its handling of entry points. The presence of two AJAX handlers without authentication checks creates a substantial attack surface that is directly exposed. Furthermore, the taint analysis reveals two flows with unsanitized paths, both classified as high severity, indicating potential for malicious data to be processed without proper validation. The lack of any nonce checks on AJAX handlers is a critical oversight that compounds the risk associated with these unprotected entry points.

Despite the absence of historical vulnerabilities and a generally good approach to SQL queries and file operations, the unprotected AJAX endpoints and high-severity taint flows present a tangible risk. The plugin's limited attack surface is its saving grace, but the quality of protection for those exposed points is poor. Users should be aware that the plugin's design, particularly concerning its AJAX handlers, leaves it susceptible to potential exploitation if malicious data can be supplied through these channels.

Key Concerns

  • AJAX handlers without auth checks
  • High severity taint flows
  • Outputs not properly escaped
  • Missing nonce checks on AJAX
Vulnerabilities
None known

WP Simple Maintenance & Under Construction Mode Security Vulnerabilities

No known vulnerabilities — this is a good sign.
Version History

WP Simple Maintenance & Under Construction Mode Release Timeline

v1.5.1Current
v1.5
v1.0
Code Analysis
Analyzed Mar 16, 2026

WP Simple Maintenance & Under Construction Mode Code Analysis

Dangerous Functions
0
Raw SQL Queries
1
145 prepared
Unescaped Output
45
21 escaped
Nonce Checks
0
Capability Checks
2
File Operations
0
External Requests
0
Bundled Libraries
0

SQL Query Safety

99% prepared146 total queries

Output Escaping

32% escaped66 total outputs
Data Flows · Security
2 unsanitized

Data Flow Analysis

2 flows2 with unsanitized paths
h3uc9sa_FormSubmitter (index.php:14)
Source (user input) Sink (dangerous op) Sanitizer Transform Unsanitized Sanitized
Attack Surface
2 unprotected

WP Simple Maintenance & Under Construction Mode Attack Surface

Entry Points2
Unprotected2

AJAX Handlers 2

authwp_ajax_h3uc9sa_FormSubmitterindex.php:148
authwp_ajax_h3uc9sa_AjaxerHandlerindex.php:149
WordPress Hooks 3
actionadmin_bar_menuindex.php:168
actionadmin_menuindex.php:170
filtertemplate_includeindex.php:181
Maintenance & Trust

WP Simple Maintenance & Under Construction Mode Maintenance & Trust

Maintenance Signals

WordPress version tested5.3.21
Last updatedFeb 13, 2020
PHP min version5.4
Downloads2K

Community Trust

Rating0/100
Number of ratings0
Active installs30
Developer Profile

WP Simple Maintenance & Under Construction Mode Developer Profile

H3 Technologies

3 plugins · 80 total installs

91
trust score
Avg Security Score
95/100
Avg Patch Time
30 days
View full developer profile
Detection Fingerprints

How We Detect WP Simple Maintenance & Under Construction Mode

Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.

Asset Fingerprints

Asset Paths
/wp-content/plugins/wp-simple-maintenance-mode/assets/css/wpsmm-admin-style.css/wp-content/plugins/wp-simple-maintenance-mode/assets/css/wpsmm-maintenance-style.css/wp-content/plugins/wp-simple-maintenance-mode/assets/js/wpsmm-admin-script.js/wp-content/plugins/wp-simple-maintenance-mode/assets/js/wpsmm-maintenance-script.js/wp-content/plugins/wp-simple-maintenance-mode/assets/js/wp-smm-admin-script.js
Script Paths
/wp-content/plugins/wp-simple-maintenance-mode/assets/js/wpsmm-admin-script.js/wp-content/plugins/wp-simple-maintenance-mode/assets/js/wpsmm-maintenance-script.js/wp-content/plugins/wp-simple-maintenance-mode/assets/js/wp-smm-admin-script.js
Version Parameters
/wp-content/plugins/wp-simple-maintenance-mode/assets/css/wpsmm-admin-style.css?ver=/wp-content/plugins/wp-simple-maintenance-mode/assets/css/wpsmm-maintenance-style.css?ver=/wp-content/plugins/wp-simple-maintenance-mode/assets/js/wpsmm-admin-script.js?ver=/wp-content/plugins/wp-simple-maintenance-mode/assets/js/wpsmm-maintenance-script.js?ver=/wp-content/plugins/wp-simple-maintenance-mode/assets/js/wp-smm-admin-script.js?ver=

HTML / DOM Fingerprints

CSS Classes
h3uc9sa-main-bodyh3uc9sa-site-titleh3uc9sa-headingh3uc9sa-descriptionh3uc9sa-bottom-contenth3uc9sa-social-facebookh3uc9sa-social-twitterh3uc9sa-social-instagram+14 more
HTML Comments
<!-- Your site is currently in maintenance mode. --><!-- Main Content --><!-- Site Title --><!-- Heading -->+22 more
Data Attributes
data-site-titledata-headingdata-descriptiondata-bottom-contentdata-social-facebookdata-social-twitter+15 more
JS Globals
wp_smm_ajax_obj
FAQ

Frequently Asked Questions about WP Simple Maintenance & Under Construction Mode