WP ESIGNATURE RTL (Right to Left) Security & Risk Analysis

wordpress.org/plugins/e-signature-rtl-right-to-left

Adds full Right-to-left (RTL) support to WP Signature generated contract & Admin Area of WP eSignature.

100 active installs v1.8.0 PHP + WP 4.5+ Updated Jan 8, 2026
right-to-leftrtlrtl-pluginrtl-support-wordpresswordpress-right-to-left
100
A · Safe
CVEs total0
Unpatched0
Last CVENever
Safety Verdict

Is WP ESIGNATURE RTL (Right to Left) Safe to Use in 2026?

Generally Safe

Score 100/100

WP ESIGNATURE RTL (Right to Left) has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.

No known CVEs Updated 2mo ago
Risk Assessment

The "e-signature-rtl-right-to-left" plugin v1.8.0 exhibits a generally positive security posture based on the provided static analysis. The plugin has a zero attack surface in terms of AJAX handlers, REST API routes, shortcodes, and cron events, indicating a minimal entry point for attackers. Furthermore, it demonstrates good practices by exclusively using prepared statements for SQL queries and avoiding external HTTP requests. The absence of any recorded vulnerability history, including critical or high severity CVEs, further reinforces this positive assessment. This suggests the plugin has been developed with security in mind or has a history of responsible patching.

However, there are areas for concern that temper the overall positive outlook. A significant weakness is the low percentage of properly escaped output (14%), which could lead to Cross-Site Scripting (XSS) vulnerabilities if user-supplied data is not adequately sanitized before being displayed. The plugin also lacks nonce checks and capability checks, which are crucial for securing actions performed by the plugin and preventing unauthorized access or privilege escalation, especially in the context of its file operation. While no taint flows or dangerous functions were identified, the identified weaknesses in output escaping and the absence of critical security checks represent tangible risks.

In conclusion, while the plugin scores well on fundamental security aspects like SQL injection prevention and attack surface minimization, the insufficient output escaping and lack of robust authentication/authorization mechanisms for its operations are significant vulnerabilities. The absence of past vulnerabilities is encouraging but does not negate the current risks identified in the code. Developers should prioritize addressing the output escaping issue and implementing appropriate nonce and capability checks to mitigate potential XSS and unauthorized access vulnerabilities.

Key Concerns

  • Low output escaping percentage
  • Missing nonce checks
  • Missing capability checks
Vulnerabilities
None known

WP ESIGNATURE RTL (Right to Left) Security Vulnerabilities

No known vulnerabilities — this is a good sign.
Code Analysis
Analyzed Mar 16, 2026

WP ESIGNATURE RTL (Right to Left) Code Analysis

Dangerous Functions
0
Raw SQL Queries
0
0 prepared
Unescaped Output
6
1 escaped
Nonce Checks
0
Capability Checks
0
File Operations
1
External Requests
0
Bundled Libraries
0

Output Escaping

14% escaped7 total outputs
Attack Surface

WP ESIGNATURE RTL (Right to Left) Attack Surface

Entry Points0
Unprotected0
WordPress Hooks 8
actioninitesig-rtl.php:25
actionadmin_noticesesig-rtl.php:27
filteresig-pdf-export-stylesheetesig-rtl.php:28
filteresign-rtl-signature-marginesig-rtl.php:29
filtermce_external_pluginsesig-rtl.php:65
filtermce_buttonsesig-rtl.php:66
actionesig_headesig-rtl.php:79
actionadmin_enqueue_scriptsesig-rtl.php:90
Maintenance & Trust

WP ESIGNATURE RTL (Right to Left) Maintenance & Trust

Maintenance Signals

WordPress version tested6.9.4
Last updatedJan 8, 2026
PHP min version
Downloads7K

Community Trust

Rating0/100
Number of ratings0
Active installs100
Developer Profile

WP ESIGNATURE RTL (Right to Left) Developer Profile

approveme

10 plugins · 4K total installs

94
trust score
Avg Security Score
100/100
Avg Patch Time
15 days
View full developer profile
Detection Fingerprints

How We Detect WP ESIGNATURE RTL (Right to Left)

Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.

Asset Fingerprints

Asset Paths
assets/css/rtl-admin.cssassets/css/rtl-basic-mobile.cssassets/css/rtl-basic.cssassets/css/rtl-pdf.cssassets/css/rtl-print.cssassets/css/rtl.css

HTML / DOM Fingerprints

JS Globals
WP_E_ApiWP_E_DocumentWP_E_Esigrole
FAQ

Frequently Asked Questions about WP ESIGNATURE RTL (Right to Left)