
Signature Field For Contact Form 7 – CF7Sign Security & Risk Analysis
wordpress.org/plugins/cf7-signatureEasily add drawing smooth signature field to Contact Form 7 form
Is Signature Field For Contact Form 7 – CF7Sign Safe to Use in 2026?
Generally Safe
Score 85/100Signature Field For Contact Form 7 – CF7Sign has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.
The "cf7-signature" plugin v1.0.0 exhibits a generally strong security posture based on the provided static analysis. The absence of any known CVEs, unpatched vulnerabilities, or common vulnerability types in its history is a significant positive indicator. Furthermore, the code analysis reveals a complete lack of SQL injection risks due to the exclusive use of prepared statements, and a very high percentage of properly escaped output. The minimal attack surface with zero unprotected entry points also suggests a well-designed plugin from an external threat perspective.
However, there are some areas that warrant attention. The taint analysis identified two flows with unsanitized paths. While no critical or high severity issues were reported from these flows, the presence of unsanitized paths, even if currently benign, represents a potential future risk if the plugin is updated or extended without careful sanitization. Additionally, the complete absence of nonce checks and capability checks, while not explicitly flagged as a vulnerability in this version, could be a concern in future development, especially if new entry points are introduced. The static analysis also noted file operations without further context, which, depending on their nature, could introduce risks if not handled securely.
In conclusion, "cf7-signature" v1.0.0 appears to be a relatively secure plugin with good practices regarding SQL and output escaping. The vulnerability history is clean, and the attack surface is well-managed. The primary concerns lie with the identified unsanitized paths in the taint analysis, which should be monitored and addressed in future development to prevent potential vulnerabilities.
Key Concerns
- Flows with unsanitized paths found in taint analysis
- No nonce checks implemented
- No capability checks implemented
Signature Field For Contact Form 7 – CF7Sign Security Vulnerabilities
Signature Field For Contact Form 7 – CF7Sign Release Timeline
Signature Field For Contact Form 7 – CF7Sign Code Analysis
Output Escaping
Data Flow Analysis
Signature Field For Contact Form 7 – CF7Sign Attack Surface
WordPress Hooks 11
Maintenance & Trust
Signature Field For Contact Form 7 – CF7Sign Maintenance & Trust
Maintenance Signals
Community Trust
Signature Field For Contact Form 7 – CF7Sign Alternatives
Digital Signature For Contact Form 7
digital-signature-for-contact-form-7
Contact Form 7 Signature Addon making autographs of people who want to get an E-signature in the system. We build too easy to access and use for users …
Digital Signature Addon for Contact Form 7
digital-signature-addon-for-contact-form-7
Converts Contact Form 7 into a signable form with a digital signature field for mouse and touchscreen devices.
Signature field for Elementor Forms
signature-field-for-elementor-forms
Elementor Form Signature field add-on makes it easy for users to sign your forms.
Mailster Contact Form 7
mailster-contact-form-7
Create your Signup Forms with Contact Form 7 and allow users to signup to your newsletter.
Digital Signature For Gravity Forms
digital-signature-for-gravity-forms
Gravity Forms Digital Signature is free plugin. Downloading the Gravity Form with the Digital Signature Field is free here.
Signature Field For Contact Form 7 – CF7Sign Developer Profile
9 plugins · 23K total installs
How We Detect Signature Field For Contact Form 7 – CF7Sign
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/cf7-signature/signature-pad.min.js/wp-content/plugins/cf7-signature/script.js/wp-content/plugins/cf7-signature/signature-pad.min.js/wp-content/plugins/cf7-signature/script.jscf7-sign-js?ver=HTML / DOM Fingerprints
signature-padcf7sg-signwpcf7-sign-wrapdata-hidden<canvas style="display:block" data-hidden=""><button class="btn btn-primary cf7sg-sign">Clear</button>