
Signature Add-On for Gravity Forms Security & Risk Analysis
wordpress.org/plugins/gravity-signature-forms-add-onAutomatically generate a legally binding & court recognized contract from a Gravity Forms submission. Proposals. Time sheets. Contracts.
Is Signature Add-On for Gravity Forms Safe to Use in 2026?
Generally Safe
Score 99/100Signature Add-On for Gravity Forms has a strong security track record. Known vulnerabilities have been patched promptly. It's a solid choice for most WordPress installations.
The "gravity-signature-forms-add-on" plugin, version 1.8.8, exhibits a generally strong security posture, with notable strengths in its handling of SQL queries and output escaping. The absence of dangerous functions, external HTTP requests, and any critical or high-severity taint flows are positive indicators. Furthermore, the plugin demonstrates a commitment to security by implementing nonce and capability checks on a majority of its entry points, and all identified SQL queries utilize prepared statements, mitigating common injection risks. However, a past medium-severity vulnerability of the "Missing Authorization" type, albeit no longer unpatched, suggests a historical weakness that warrants attention and continued vigilance. While the current analysis shows no immediate critical flaws, the presence of a past authorization vulnerability, even if resolved, means users should remain aware of the potential for such issues. The plugin's small attack surface and good security practices overall present a low immediate risk, but the historical vulnerability should be considered in a comprehensive security strategy.
Key Concerns
- Past medium vulnerability (Missing Authorization)
Signature Add-On for Gravity Forms Security Vulnerabilities
CVEs by Year
Severity Breakdown
1 total CVE
Signature Add-On for Gravity Forms <= 1.8.6 - Missing Authorization
Signature Add-On for Gravity Forms Release Timeline
Signature Add-On for Gravity Forms Code Analysis
SQL Query Safety
Output Escaping
Signature Add-On for Gravity Forms Attack Surface
AJAX Handlers 2
Shortcodes 1
WordPress Hooks 32
Maintenance & Trust
Signature Add-On for Gravity Forms Maintenance & Trust
Maintenance Signals
Community Trust
Signature Add-On for Gravity Forms Alternatives
Signature Add-On for WooCommerce
woocommerce-digital-signature
Automatically require your WooCommerce customers to sign a legally binding contract before downloading your product. Easy to Use.
NEX-Forms ADD ON – Digital Signatures
nex-forms-digital-signatures-add-on
Easily add Digital / E-Signature fields to your forms. Capture signatures with submissions and automatically include them in emails and PDF exports.
Ninja Forms Signature Contract Add-On
ninja-signature-contract-forms-add-on
Instantly produce a legally enforceable & court recognized contract from a Ninja Form submission. Signature Pad Contracts. Proposals.
Electronic Signature
electronic-signatures
This plugin helps integrate Electronic Signature on SwiftCloud.ai with Wordpress.
GM Digital Signature for Wpforms
digital-signature-for-wpforms
Add a secure digital signature field to WPForms. Collect legally binding e-signatures on contracts, consent forms, and agreements — directly on your W …
Signature Add-On for Gravity Forms Developer Profile
10 plugins · 4K total installs
How We Detect Signature Add-On for Gravity Forms
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/gravity-signature-forms-add-on/assets/css/esig-about-alert.css/wp-content/plugins/gravity-signature-forms-add-on/assets/css/esig-gravity-form-admin.css/wp-content/plugins/gravity-signature-forms-add-on/assets/js/esig-gravity-form-admin.js/wp-content/plugins/gravity-signature-forms-add-on/assets/js/esig-gravity-form-scripts.js/wp-content/plugins/gravity-signature-forms-add-on/assets/js/esig-gravity-form-settings.js/wp-content/plugins/gravity-signature-forms-add-on/assets/js/esig-gravity-form-validate.js/wp-content/plugins/gravity-signature-forms-add-on/admin/esig-gravity-form-admin.php/wp-content/plugins/gravity-signature-forms-add-on/includes/esig-gf-functions.php/wp-content/plugins/gravity-signature-forms-add-on/includes/esig-gravity-form.php/wp-content/plugins/gravity-signature-forms-add-on/admin/about/autoload.php/wp-content/plugins/gravity-signature-forms-add-on/includes/esig-gf-generate-value.php/wp-content/plugins/gravity-signature-forms-add-on/includes/esig-gravity-settings.php+4 moregravity-signature-forms-add-on/gravity-signature-forms-add-on.php?ver=HTML / DOM Fingerprints
esig-about-alertbangBar<!-- @package WP E-Signature - Gravity Form --><!-- @contributors Kevin Michael Gray (Approve Me), Abu Shoaib (Approve Me) --><!-- @wordpress-plugin --><!-- If this file is called directly, abort. -->+13 moreesig-icon-cssesig-gravity-form-admin.jsesig-gravity-form-scripts.jsesig-gravity-form-settings.jsesig-gravity-form-validate.jsesig-gf-functions.php+6 moreesig_gf_getesig_get_activation_state