
GM Digital Signature for Wpforms Security & Risk Analysis
wordpress.org/plugins/digital-signature-for-wpformsAdd a secure digital signature field to WPForms. Collect legally binding e-signatures on contracts, consent forms, and agreements — directly on your W …
Is GM Digital Signature for Wpforms Safe to Use in 2026?
Generally Safe
Score 100/100GM Digital Signature for Wpforms has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.
The "digital-signature-for-wpforms" v1.0 plugin exhibits a generally strong security posture based on the provided static analysis. The absence of any detected AJAX handlers, REST API routes, shortcodes, or cron events with unauthenticated entry points is a significant positive indicator, suggesting a limited attack surface. Furthermore, the code adheres to good practices by utilizing prepared statements for all SQL queries and properly escaping a high percentage of its output. The lack of reported vulnerabilities in its history also contributes to this positive assessment.
However, the analysis does reveal a few areas that warrant attention. The presence of file operations without explicit mention of sanitization or permission checks could represent a potential risk, especially if sensitive files are being accessed or modified. The complete absence of nonce checks and capability checks across all potential entry points (though currently none are explicitly identified as exposed) is a notable concern. While the attack surface is reported as zero, this could change with future updates, and the lack of these fundamental WordPress security mechanisms means that any future exposure would be immediately vulnerable.
In conclusion, the plugin demonstrates a good foundation in security by avoiding common pitfalls like raw SQL and unescaped output. Its clean vulnerability history is reassuring. Nevertheless, the potential for risks with file operations and the complete absence of nonce and capability checks are weaknesses that should be addressed to further harden the plugin against potential threats.
Key Concerns
- File operations without clear sanitization/auth checks
- No nonce checks found
- No capability checks found
GM Digital Signature for Wpforms Security Vulnerabilities
GM Digital Signature for Wpforms Code Analysis
Output Escaping
GM Digital Signature for Wpforms Attack Surface
WordPress Hooks 4
Maintenance & Trust
GM Digital Signature for Wpforms Maintenance & Trust
Maintenance Signals
Community Trust
GM Digital Signature for Wpforms Alternatives
Digital Signature Addon for Contact Form 7
digital-signature-addon-for-contact-form-7
Converts Contact Form 7 into a signable form with a digital signature field for mouse and touchscreen devices.
Digital Signature for eCommerce Checkout
digital-signature-for-ecommerce-checkout
Add a secure and responsive digital signature field to the WooCommerce checkout page. Perfect for waivers, terms, and customer authorization.
Digital Signature For Contact Form 7
digital-signature-for-contact-form-7
Contact Form 7 Signature Addon making autographs of people who want to get an E-signature in the system. We build too easy to access and use for users …
Signature Add-On for Gravity Forms
gravity-signature-forms-add-on
Automatically generate a legally binding & court recognized contract from a Gravity Forms submission. Proposals. Time sheets. Contracts.
Signature Add-On for WooCommerce
woocommerce-digital-signature
Automatically require your WooCommerce customers to sign a legally binding contract before downloading your product. Easy to Use.
GM Digital Signature for Wpforms Developer Profile
26 plugins · 12K total installs
How We Detect GM Digital Signature for Wpforms
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/digital-signature-for-wpforms/assets/css/admin-style.css/wp-content/plugins/digital-signature-for-wpforms/js/front.js/wp-content/plugins/digital-signature-for-wpforms/js/digital-pad.js/wp-content/plugins/digital-signature-for-wpforms/js/front.js/wp-content/plugins/digital-signature-for-wpforms/js/digital-pad.jsdigital-signature-for-wpforms/assets/css/admin-style.css?ver=1.0digital-signature-for-wpforms/js/front.js?ver=1.0.0digital-signature-for-wpforms/js/digital-pad.js?ver=1.0.0HTML / DOM Fingerprints
dsf-signature-paddata-dsf-signatureDSFWFORMS_PREFIX