
Sign-up Sheets Security & Risk Analysis
wordpress.org/plugins/sign-up-sheetsCreate online sign-up sheets for volunteers, events, and group scheduling.
Is Sign-up Sheets Safe to Use in 2026?
Generally Safe
Score 91/100Sign-up Sheets has a strong security track record. Known vulnerabilities have been patched promptly.
The "sign-up-sheets" plugin v2.3.4 exhibits a mixed security posture. On the positive side, static analysis reveals a well-structured codebase with a strong emphasis on security best practices, demonstrated by a high percentage of prepared SQL statements and properly escaped output. The absence of unprotected entry points and critical/high severity taint flows is encouraging. However, the presence of the `unserialize` function is a significant concern, as it can lead to deserialization vulnerabilities if not handled with extreme care and input validation.
The plugin's vulnerability history, with 9 known CVEs including 2 high and 7 medium severity issues, paints a concerning picture. The prevalence of deserialization, CSRF, code injection, XSS, and authorization bypass vulnerabilities suggests a recurring pattern of exploitable weaknesses. The fact that the last vulnerability was recorded relatively recently (September 2025) indicates that the development team has not consistently maintained a secure codebase over time, despite the apparent improvements in static analysis metrics for this specific version.
In conclusion, while v2.3.4 shows improvements in code hygiene for prepared statements and output escaping, the historical vulnerability record and the presence of a dangerous function like `unserialize` warrant caution. The potential for past vulnerabilities to reappear or for new ones to emerge due to insecure handling of deserialization remains a notable risk. Users should be aware of this history and ensure the plugin is always updated to the latest patched version.
Key Concerns
- Dangerous function: unserialize detected
- Total known CVEs: 9
- High severity CVEs: 2
- Medium severity CVEs: 7
Sign-up Sheets Security Vulnerabilities
CVEs by Year
Severity Breakdown
9 total CVEs
Sign-up Sheets <= 2.3.2 - Unauthenticated PHP Object Injection
Sign-up Sheets <= 2.3.3 - Cross-Site Request Forgery
Sign-up Sheets <= 2.3.0.1 - Unauthenticated Arbitrary Shortcode Execution
Sign-up Sheets <= 2.2.12 - Reflected Cross-Site Scripting
Sign-up Sheets <= 2.2.12 - Missing Authorization
Sign-up Sheets <= 2.2.11.1 - Cross-Site Request Forgery
Sign-up Sheets <= 2.2.8 - Cross-Site Request Forgery
Sign-up Sheets <= 1.0.13 - Authenticated CSV Injection
Sign-up Sheets <= 1.0.13 - Stored Cross-Site Scripting
Sign-up Sheets Code Analysis
Dangerous Functions Found
Bundled Libraries
SQL Query Safety
Output Escaping
Data Flow Analysis
Sign-up Sheets Attack Surface
Shortcodes 4
WordPress Hooks 87
Scheduled Events 1
Maintenance & Trust
Sign-up Sheets Maintenance & Trust
Maintenance Signals
Community Trust
Sign-up Sheets Alternatives
Volunteer Sign Up Sheets
pta-volunteer-sign-up-sheets
Easily create and manage sign-up sheets for activities and events, while protecting the privacy of the volunteers' personal information.
Sign-up List
sign-up-list
Publish a sign-up list to rally up volunteers, event guests, participants and the likes. Show people who's on the list and let them sign up.
Wired Impact Volunteer Management
wired-impact-volunteer-management
A free, easy way to manage your nonprofit's volunteers.
PTA Shortcodes
pta-shortcodes
Easily generate shortcodes for the PTA plugins from Stephen Sherrard Plugins. Adds a PTA Shortcode generator button to the TinyMCE "classic edito …
Newsletter – Send awesome emails from WordPress
newsletter
An email marketing tool for your blog: subscription forms to create your lists with unlimited subscribers and newsletters.
Sign-up Sheets Developer Profile
1 plugin · 1K total installs
How We Detect Sign-up Sheets
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/sign-up-sheets/css/admin.css/wp-content/plugins/sign-up-sheets/css/frontend.css/wp-content/plugins/sign-up-sheets/js/admin.js/wp-content/plugins/sign-up-sheets/js/frontend.js/wp-content/plugins/sign-up-sheets/js/admin.js/wp-content/plugins/sign-up-sheets/js/frontend.jssign-up-sheets/css/admin.css?ver=sign-up-sheets/css/frontend.css?ver=sign-up-sheets/js/admin.js?ver=sign-up-sheets/js/frontend.js?ver=HTML / DOM Fingerprints
fdsus-signup-sheet-wrapperfdsus-signup-sheet-titlefdsus-signup-sheet-fieldfdsus-signup-sheet-submit-buttonfdsus-signup-sheet-error-messagefdsus-signup-sheet-success-messagefdsus-signup-sheet-admin-wrap<!-- Start Sign-up Sheet --><!-- End Sign-up Sheet --><!-- Sign-up Sheets Plugin - Fetch Designs -->data-plugin-name="sign-up-sheets"data-sheet-idFDSUS_Frontend<div class="fdsus-signup-sheet-wrapper"><h2 class="fdsus-signup-sheet-title">