
Qualified Electronic Signatures by eID Easy Security & Risk Analysis
wordpress.org/plugins/eid-easy-qualified-electonic-signatureThis plugin will help you add qualified signatures to the PDF files created from the Contact From 7 responses.
Is Qualified Electronic Signatures by eID Easy Safe to Use in 2026?
Generally Safe
Score 91/100Qualified Electronic Signatures by eID Easy has a strong security track record. Known vulnerabilities have been patched promptly.
The plugin "eid-easy-qualified-electronic-signature" version 3.3.1 exhibits a mixed security posture. On the positive side, the plugin demonstrates good practices in SQL query handling, with 100% using prepared statements, and output escaping, with all outputs being properly escaped. The absence of critical or high-severity taint flows is also a strong indicator of secure coding in those areas. File operations and external HTTP requests are present but do not appear to introduce immediate risks based on the static analysis. However, significant concerns arise from the attack surface. The plugin exposes two AJAX handlers, both of which lack authentication checks, presenting a clear risk of unauthorized actions. The absence of nonce checks on these AJAX endpoints further exacerbates this issue, making them vulnerable to CSRF attacks.
The plugin's vulnerability history shows one known CVE, which has since been patched. The nature of the past vulnerability, "Use of Less Trusted Source," suggests a previous weakness that has been addressed. The fact that there are no currently unpatched vulnerabilities is a positive sign. Despite the secure handling of SQL and output, the unprotected AJAX endpoints represent a substantial security weakness. While the plugin has addressed past vulnerabilities and shows good internal code hygiene, the direct exposure of functionality without proper authorization checks is a significant oversight that could be exploited.
Key Concerns
- AJAX handlers without authentication checks
- Missing nonce checks on AJAX handlers
- Total entry points unprotected
Qualified Electronic Signatures by eID Easy Security Vulnerabilities
CVEs by Year
Severity Breakdown
1 total CVE
Various Plugins <= Various Version - Use of Polyfill.io
Qualified Electronic Signatures by eID Easy Code Analysis
Output Escaping
Data Flow Analysis
Qualified Electronic Signatures by eID Easy Attack Surface
AJAX Handlers 2
WordPress Hooks 11
Maintenance & Trust
Qualified Electronic Signatures by eID Easy Maintenance & Trust
Maintenance Signals
Community Trust
Qualified Electronic Signatures by eID Easy Alternatives
Fluent Forms PDF Generator
fluentforms-pdf
Generate PDF from Your Form Submissions and Download/Email Them
Fluent Forms Connector for MailPoet
fluent-forms-connector-for-mailpoet
Connect Fluent Forms with MailPoet.
Multilingual Forms for Fluent Forms with WPML
multilingual-forms-fluent-forms-wpml
Seamlessly integrate Fluent Forms with WPML to create multilingual forms for your WordPress website.
Electronic Signature Add-on for Fluent Forms
signature-fluent-contract-forms-add-on
Instantly produce a legally binding PDF WordPress contract from a Fluent Forms contact form submission. Digital Signature Pad. Proposal.
Cloud Storage Manager for Fluent Forms – Google Drive, Dropbox, OneDrive, S3 Uploads
cloud-storage-manager
Upload Fluent Forms files to Google Drive, Dropbox, OneDrive, S3, and Cloudflare R2. Save server space with cloud storage.
Qualified Electronic Signatures by eID Easy Developer Profile
2 plugins · 120 total installs
How We Detect Qualified Electronic Signatures by eID Easy
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/eid-easy-qualified-electonic-signature/redirector.jsredirector.jseid-easy-qualified-electonic-signature/redirector.js?ver=HTML / DOM Fingerprints
eideasy_settings/wp-json/eideasy_signing_url