Qualified Electronic Signatures by eID Easy Security & Risk Analysis

wordpress.org/plugins/eid-easy-qualified-electonic-signature

This plugin will help you add qualified signatures to the PDF files created from the Contact From 7 responses.

20 active installs v3.3.1 PHP + WP 4.5+ Updated Jul 5, 2024
digitalsignatureelectonicsignatureesignaturefluent-formsqualified-signature
91
A · Safe
CVEs total1
Unpatched0
Last CVEJun 25, 2024
Safety Verdict

Is Qualified Electronic Signatures by eID Easy Safe to Use in 2026?

Generally Safe

Score 91/100

Qualified Electronic Signatures by eID Easy has a strong security track record. Known vulnerabilities have been patched promptly.

1 known CVELast CVE: Jun 25, 2024Updated 1yr ago
Risk Assessment

The plugin "eid-easy-qualified-electronic-signature" version 3.3.1 exhibits a mixed security posture. On the positive side, the plugin demonstrates good practices in SQL query handling, with 100% using prepared statements, and output escaping, with all outputs being properly escaped. The absence of critical or high-severity taint flows is also a strong indicator of secure coding in those areas. File operations and external HTTP requests are present but do not appear to introduce immediate risks based on the static analysis. However, significant concerns arise from the attack surface. The plugin exposes two AJAX handlers, both of which lack authentication checks, presenting a clear risk of unauthorized actions. The absence of nonce checks on these AJAX endpoints further exacerbates this issue, making them vulnerable to CSRF attacks.

The plugin's vulnerability history shows one known CVE, which has since been patched. The nature of the past vulnerability, "Use of Less Trusted Source," suggests a previous weakness that has been addressed. The fact that there are no currently unpatched vulnerabilities is a positive sign. Despite the secure handling of SQL and output, the unprotected AJAX endpoints represent a substantial security weakness. While the plugin has addressed past vulnerabilities and shows good internal code hygiene, the direct exposure of functionality without proper authorization checks is a significant oversight that could be exploited.

Key Concerns

  • AJAX handlers without authentication checks
  • Missing nonce checks on AJAX handlers
  • Total entry points unprotected
Vulnerabilities
1

Qualified Electronic Signatures by eID Easy Security Vulnerabilities

CVEs by Year

1 CVE in 2024
2024
Patched Has unpatched

Severity Breakdown

Medium
1

1 total CVE

Various Plugins <= Various Version - Use of Polyfill.io

Jun 25, 2024 Patched in 3.3.1 (14d)
Code Analysis
Analyzed Mar 16, 2026

Qualified Electronic Signatures by eID Easy Code Analysis

Dangerous Functions
0
Raw SQL Queries
0
0 prepared
Unescaped Output
0
32 escaped
Nonce Checks
0
Capability Checks
1
File Operations
5
External Requests
2
Bundled Libraries
0

Output Escaping

100% escaped32 total outputs
Data Flows
All sanitized

Data Flow Analysis

2 flows
addSignaturesPage (EidEasySignerAdmin.php:81)
Source (user input) Sink (dangerous op) Sanitizer Transform Unsanitized Sanitized
Attack Surface
2 unprotected

Qualified Electronic Signatures by eID Easy Attack Surface

Entry Points2
Unprotected2

AJAX Handlers 2

authwp_ajax_eideasy_signing_urlcf7-eideasy-attachment-signer.php:63
noprivwp_ajax_eideasy_signing_urlcf7-eideasy-attachment-signer.php:64
WordPress Hooks 11
actionadmin_initcf7-eideasy-attachment-signer.php:34
actionadmin_menucf7-eideasy-attachment-signer.php:35
actionwpcf7_before_send_mailcf7-eideasy-attachment-signer.php:43
filterwpcf7_mail_componentscf7-eideasy-attachment-signer.php:44
filterfluentform_email_attachmentscf7-eideasy-attachment-signer.php:59
filterfluentform_submission_confirmationcf7-eideasy-attachment-signer.php:60
actionparse_requestcf7-eideasy-attachment-signer.php:68
actionparse_requestcf7-eideasy-attachment-signer.php:69
actionplugins_loadedcf7-eideasy-attachment-signer.php:72
actionwp_enqueue_scriptscf7-eideasy-attachment-signer.php:73
filterwpcf7_skip_mailEidEasySigner.php:189
Maintenance & Trust

Qualified Electronic Signatures by eID Easy Maintenance & Trust

Maintenance Signals

WordPress version tested6.5.8
Last updatedJul 5, 2024
PHP min version
Downloads2K

Community Trust

Rating0/100
Number of ratings0
Active installs20
Developer Profile

Qualified Electronic Signatures by eID Easy Developer Profile

eID Easy

2 plugins · 120 total installs

76
trust score
Avg Security Score
95/100
Avg Patch Time
300 days
View full developer profile
Detection Fingerprints

How We Detect Qualified Electronic Signatures by eID Easy

Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.

Asset Fingerprints

Asset Paths
/wp-content/plugins/eid-easy-qualified-electonic-signature/redirector.js
Script Paths
redirector.js
Version Parameters
eid-easy-qualified-electonic-signature/redirector.js?ver=

HTML / DOM Fingerprints

JS Globals
eideasy_settings
REST Endpoints
/wp-json/eideasy_signing_url
FAQ

Frequently Asked Questions about Qualified Electronic Signatures by eID Easy