Sign Customiser Security & Risk Analysis

wordpress.org/plugins/sign-customiser

Transform your WooCommerce store into a powerful custom sign business with real-time pricing, instant previews, and automated manufacturing specs.

30 active installs v1.6.2 PHP 7.4+ WP 6.5+ Updated Mar 10, 2026
acrylic-signschannel-signsmetal-signsneonsign-customizer
100
A · Safe
CVEs total0
Unpatched0
Last CVENever
Safety Verdict

Is Sign Customiser Safe to Use in 2026?

Generally Safe

Score 100/100

Sign Customiser has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.

No known CVEs Updated 26d ago
Risk Assessment

The "sign-customiser" plugin v1.6.2 exhibits a mixed security posture. While it demonstrates good practices by avoiding dangerous functions and using prepared statements for all SQL queries, and importantly, has no recorded vulnerability history, several critical concerns are present.

The static analysis reveals a significant attack surface with one unprotected REST API route. Furthermore, only 30% of output is properly escaped, and there are no nonce or capability checks implemented for any entry points. The presence of file operations and external HTTP requests without apparent sanitization or validation in the analyzed code signals potential avenues for exploitation.

Despite the absence of past CVEs, the current lack of robust authentication and authorization checks on its entry points, combined with insufficient output escaping, creates a substantial risk. The plugin's strengths in SQL handling and lack of historical vulnerabilities are overshadowed by the immediate threats posed by its unprotected REST API route and general lack of input validation and output sanitization.

Key Concerns

  • Unprotected REST API route
  • Insufficient output escaping (30% proper)
  • Missing nonce checks
  • Missing capability checks
  • File operations without apparent validation
  • External HTTP requests without apparent validation
Vulnerabilities
None known

Sign Customiser Security Vulnerabilities

No known vulnerabilities — this is a good sign.
Code Analysis
Analyzed Mar 16, 2026

Sign Customiser Code Analysis

Dangerous Functions
0
Raw SQL Queries
0
0 prepared
Unescaped Output
7
3 escaped
Nonce Checks
0
Capability Checks
0
File Operations
1
External Requests
1
Bundled Libraries
0

Output Escaping

30% escaped10 total outputs
Attack Surface
1 unprotected

Sign Customiser Attack Surface

Entry Points1
Unprotected1

REST API Routes 1

GET/wp-json/spc/productscart.php:157
WordPress Hooks 10
actionadmin_initbootstrap.php:3
actionadmin_noticesbootstrap.php:13
actionwp_headbootstrap.php:79
actionrest_api_initcart.php:156
actionwoocommerce_new_orderorders.php:149
actionwoocommerce_thankyouorders.php:150
actionwoocommerce_order_status_processingorders.php:151
actionwoocommerce_order_status_completedorders.php:152
actionadmin_menusettings.php:13
actionadmin_initsettings.php:60
Maintenance & Trust

Sign Customiser Maintenance & Trust

Maintenance Signals

WordPress version tested6.6.5
Last updatedMar 10, 2026
PHP min version7.4
Downloads2K

Community Trust

Rating100/100
Number of ratings3
Active installs30
Developer Profile

Sign Customiser Developer Profile

Sign Customiser

1 plugin · 30 total installs

94
trust score
Avg Security Score
100/100
Avg Patch Time
30 days
View full developer profile
Detection Fingerprints

How We Detect Sign Customiser

Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.

Asset Fingerprints

Asset Paths
/wp-content/plugins/sign-customiser/assets/js/sign-customiser-frontend.js/wp-content/plugins/sign-customiser/assets/css/sign-customiser-frontend.css/wp-content/plugins/sign-customiser/assets/css/sign-customiser-admin.css/wp-content/plugins/sign-customiser/assets/js/sign-customiser-admin.js
Script Paths
/wp-content/plugins/sign-customiser/assets/js/sign-customiser-frontend.js/wp-content/plugins/sign-customiser/assets/js/sign-customiser-admin.js
Version Parameters
sign-customiser/assets/js/sign-customiser-frontend.js?ver=sign-customiser/assets/css/sign-customiser-frontend.css?ver=sign-customiser/assets/css/sign-customiser-admin.css?ver=sign-customiser/assets/js/sign-customiser-admin.js?ver=

HTML / DOM Fingerprints

CSS Classes
spcwp_ajax_cart_dismissspcwp_migration_banner_dismiss
Data Attributes
id="spcwp_ajax_cart_dismiss"id="spcwp_migration_banner_dismiss"
JS Globals
window.SpcWcConfig
REST Endpoints
/wp-json/sign-customiser/v1/product
FAQ

Frequently Asked Questions about Sign Customiser