Signature Field For Contact Form 7 – CF7Sign Security & Risk Analysis

wordpress.org/plugins/cf7-signature

Easily add drawing smooth signature field to Contact Form 7 form

700 active installs v1.0.0 PHP + WP 4.8+ Updated Jul 3, 2023
contact-form-7sigsignsignature-fieldsignature-pad
85
A · Safe
CVEs total0
Unpatched0
Last CVENever
Safety Verdict

Is Signature Field For Contact Form 7 – CF7Sign Safe to Use in 2026?

Generally Safe

Score 85/100

Signature Field For Contact Form 7 – CF7Sign has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.

No known CVEs Updated 2yr ago
Risk Assessment

The "cf7-signature" plugin v1.0.0 exhibits a generally strong security posture based on the provided static analysis. The absence of any known CVEs, unpatched vulnerabilities, or common vulnerability types in its history is a significant positive indicator. Furthermore, the code analysis reveals a complete lack of SQL injection risks due to the exclusive use of prepared statements, and a very high percentage of properly escaped output. The minimal attack surface with zero unprotected entry points also suggests a well-designed plugin from an external threat perspective.

However, there are some areas that warrant attention. The taint analysis identified two flows with unsanitized paths. While no critical or high severity issues were reported from these flows, the presence of unsanitized paths, even if currently benign, represents a potential future risk if the plugin is updated or extended without careful sanitization. Additionally, the complete absence of nonce checks and capability checks, while not explicitly flagged as a vulnerability in this version, could be a concern in future development, especially if new entry points are introduced. The static analysis also noted file operations without further context, which, depending on their nature, could introduce risks if not handled securely.

In conclusion, "cf7-signature" v1.0.0 appears to be a relatively secure plugin with good practices regarding SQL and output escaping. The vulnerability history is clean, and the attack surface is well-managed. The primary concerns lie with the identified unsanitized paths in the taint analysis, which should be monitored and addressed in future development to prevent potential vulnerabilities.

Key Concerns

  • Flows with unsanitized paths found in taint analysis
  • No nonce checks implemented
  • No capability checks implemented
Vulnerabilities
None known

Signature Field For Contact Form 7 – CF7Sign Security Vulnerabilities

No known vulnerabilities — this is a good sign.
Version History

Signature Field For Contact Form 7 – CF7Sign Release Timeline

No version history available.
Code Analysis
Analyzed Mar 16, 2026

Signature Field For Contact Form 7 – CF7Sign Code Analysis

Dangerous Functions
0
Raw SQL Queries
0
0 prepared
Unescaped Output
2
32 escaped
Nonce Checks
0
Capability Checks
0
File Operations
4
External Requests
0
Bundled Libraries
0

Output Escaping

94% escaped34 total outputs
Data Flows · Security
2 unsanitized

Data Flow Analysis

2 flows2 with unsanitized paths
validation_filter (actions.php:107)
Source (user input) Sink (dangerous op) Sanitizer Transform Unsanitized Sanitized
Attack Surface

Signature Field For Contact Form 7 – CF7Sign Attack Surface

Entry Points0
Unprotected0
WordPress Hooks 11
filterwpcf7_validate_signactions.php:23
filterwpcf7_validate_sign*actions.php:24
filterwpcf7_mail_componentsactions.php:25
actionwpcf7_mail_sentactions.php:26
actionwpcf7_mail_failedactions.php:27
filtercfdb7_before_save_dataactions.php:29
filtercf7adb_before_save_dataactions.php:30
actioninitcf7-signature.php:14
actionwpcf7_initcf7-signature.php:20
actionwpcf7_enqueue_scriptscf7-signature.php:26
actionwpcf7_admin_initcf7-signature.php:101
Maintenance & Trust

Signature Field For Contact Form 7 – CF7Sign Maintenance & Trust

Maintenance Signals

WordPress version tested6.2.9
Last updatedJul 3, 2023
PHP min version
Downloads5K

Community Trust

Rating66/100
Number of ratings3
Active installs700
Developer Profile

Signature Field For Contact Form 7 – CF7Sign Developer Profile

wpdebuglog

9 plugins · 23K total installs

91
trust score
Avg Security Score
96/100
Avg Patch Time
9 days
View full developer profile
Detection Fingerprints

How We Detect Signature Field For Contact Form 7 – CF7Sign

Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.

Asset Fingerprints

Asset Paths
/wp-content/plugins/cf7-signature/signature-pad.min.js/wp-content/plugins/cf7-signature/script.js
Script Paths
/wp-content/plugins/cf7-signature/signature-pad.min.js/wp-content/plugins/cf7-signature/script.js
Version Parameters
cf7-sign-js?ver=

HTML / DOM Fingerprints

CSS Classes
signature-padcf7sg-signwpcf7-sign-wrap
Data Attributes
data-hidden
Shortcode Output
<canvas style="display:block" data-hidden=""><button class="btn btn-primary cf7sg-sign">Clear</button>
FAQ

Frequently Asked Questions about Signature Field For Contact Form 7 – CF7Sign