
Post Signature Security & Risk Analysis
wordpress.org/plugins/post-signatureAppends the post author's display name to posts. Useful for multi-author blogs that are crossposted elsewhere, such as LiveJournal or Facebook.
Is Post Signature Safe to Use in 2026?
Generally Safe
Score 85/100Post Signature has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.
The 'post-signature' v1.01 plugin exhibits an exceptionally strong security posture based on the provided static analysis and vulnerability history. The absence of any identified dangerous functions, SQL queries without prepared statements, unescaped output, file operations, or external HTTP requests is a significant strength. Furthermore, the plugin demonstrates robust security practices by incorporating capability checks, indicating that actions requiring specific user permissions are likely being enforced correctly. The lack of any recorded vulnerabilities or CVEs in its history further bolsters this positive assessment.
While the static analysis reveals a commendably small attack surface with no unprotected entry points, there is a complete absence of nonce checks. This, coupled with zero AJAX handlers, REST API routes, shortcodes, or cron events that would typically require such checks, suggests that the plugin's functionality might not inherently necessitate these measures. However, the absence of any taint analysis results or flows with unsanitized paths indicates that the analysis either did not detect any such flows or the plugin is designed in a way that prevents them. Overall, the plugin appears very secure, with the only potential, albeit minor, area of consideration being the lack of explicit nonce checks, though this may be a reflection of its limited functionality rather than an oversight.
Key Concerns
- No nonce checks identified
Post Signature Security Vulnerabilities
Post Signature Release Timeline
Post Signature Code Analysis
Post Signature Attack Surface
WordPress Hooks 5
Maintenance & Trust
Post Signature Maintenance & Trust
Maintenance Signals
Community Trust
Post Signature Alternatives
Digital Signature For Contact Form 7
digital-signature-for-contact-form-7
Contact Form 7 Signature Addon making autographs of people who want to get an E-signature in the system. We build too easy to access and use for users …
GD bbPress Tools
gd-bbpress-tools
Adds different expansions and tools to the bbPress plugin powered forums: BBCode support, signatures, various tweaks, custom views, quote...
PRyC WP: Add custom content to post and page (top/bottom)
pryc-wp-add-custom-content-to-bottom-of-post
Add custom content to post and/or page (top/bottom). You may use text, HTML, Shortcodes and JavaScript. Simple, but work...
Signature field for Elementor Forms
signature-field-for-elementor-forms
Elementor Form Signature field add-on makes it easy for users to sign your forms.
Signature Add-On for Gravity Forms
gravity-signature-forms-add-on
Automatically generate a legally binding & court recognized contract from a Gravity Forms submission. Proposals. Time sheets. Contracts.
Post Signature Developer Profile
16 plugins · 17K total installs
How We Detect Post Signature
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/post-signature/languagesHTML / DOM Fingerprints
post-signaturename="post_signature_options[posts]"name="post_signature_options[pages]"name="post_signature_options[hide_here]"id="post-signature"