
Electronic Signature Security & Risk Analysis
wordpress.org/plugins/electronic-signaturesThis plugin helps integrate Electronic Signature on SwiftCloud.ai with Wordpress.
Is Electronic Signature Safe to Use in 2026?
Generally Safe
Score 85/100Electronic Signature has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.
The plugin "electronic-signatures" v2.0.2 presents a mixed security posture. While it boasts no known historical vulnerabilities and a relatively small attack surface with no immediately obvious unprotected entry points, several concerning code signals warrant attention. The use of the `create_function` function is a significant red flag, as it can be a vector for code injection if not handled with extreme care. Furthermore, the complete absence of prepared statements for all seven SQL queries is a critical vulnerability, opening the door to SQL injection attacks. The low percentage of properly escaped output (27%) also suggests a risk of cross-site scripting (XSS) vulnerabilities.
Taint analysis reveals two flows of high severity, indicating potential issues with how data is handled and whether it's properly sanitized before being used in sensitive operations. Although there are no critical taint flows or known CVEs, these high-severity flows, combined with the unsanitized paths, suggest that user-supplied data might not be adequately protected within the plugin. The vulnerability history being clean is a positive sign of past development practices, but it does not negate the risks identified in the current static analysis.
In conclusion, while the plugin has a clean history and a limited attack surface, the identified code signals and taint analysis results point to significant potential security weaknesses. The reliance on raw SQL, the presence of `create_function`, and the poor output escaping are substantial concerns that should be addressed to improve the overall security of the plugin.
Key Concerns
- All SQL queries use raw SQL, no prepared statements
- Dangerous function detected: create_function
- Only 27% of outputs are properly escaped
- High severity taint flow detected (x2)
- Taint flows with unsanitized paths detected (x3)
Electronic Signature Security Vulnerabilities
Electronic Signature Code Analysis
Dangerous Functions Found
SQL Query Safety
Output Escaping
Data Flow Analysis
Electronic Signature Attack Surface
Shortcodes 4
WordPress Hooks 18
Maintenance & Trust
Electronic Signature Maintenance & Trust
Maintenance Signals
Community Trust
Electronic Signature Alternatives
Signature Add-On for Gravity Forms
gravity-signature-forms-add-on
Automatically generate a legally binding & court recognized contract from a Gravity Forms submission. Proposals. Time sheets. Contracts.
Signature Add-On for WooCommerce
woocommerce-digital-signature
Automatically require your WooCommerce customers to sign a legally binding contract before downloading your product. Easy to Use.
NEX-Forms ADD ON – Digital Signatures
nex-forms-digital-signatures-add-on
Easily add Digital / E-Signature fields to your forms. Capture signatures with submissions and automatically include them in emails and PDF exports.
Ninja Forms Signature Contract Add-On
ninja-signature-contract-forms-add-on
Instantly produce a legally enforceable & court recognized contract from a Ninja Form submission. Signature Pad Contracts. Proposals.
GM Digital Signature for Wpforms
digital-signature-for-wpforms
Add a secure digital signature field to WPForms. Collect legally binding e-signatures on contracts, consent forms, and agreements — directly on your W …
Electronic Signature Developer Profile
1 plugin · 200 total installs
How We Detect Electronic Signature
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/electronic-signatures/css/swiftsignature-style.css/wp-content/plugins/electronic-signatures/js/swiftsignature-script.js/wp-content/plugins/electronic-signatures/css/ssing_bs_modal.min.css/wp-content/plugins/electronic-signatures/admin/css/swift-dashboard.css/wp-content/plugins/electronic-signatures/admin/js/swift-dashboard.js/wp-content/plugins/electronic-signatures/js/swiftsignature-script.js/wp-content/plugins/electronic-signatures/admin/js/jstz.min.js/wp-content/plugins/electronic-signatures/admin/js/swift-dashboard.jselectronic-signatures/css/swiftsignature-style.css?ver=electronic-signatures/js/swiftsignature-script.js?ver=electronic-signatures/css/ssing_bs_modal.min.css?ver=electronic-signatures/admin/css/swift-dashboard.css?ver=electronic-signatures/admin/js/swift-dashboard.js?ver=HTML / DOM Fingerprints
swiftsignature-form-shortcode<!-- SHORTCODE_FORM_START --><!-- SHORTCODE_FORM_END --><!-- SHORTCODE_START --><!-- SHORTCODE_END -->data-swift-signature-actionssign_ajax_objectssign_ajax_object.ajax_urlssign_ajax_object.ssing_plugin_home_url[electronic-signature][swift-signature]