
Signed Posts Security & Risk Analysis
wordpress.org/plugins/signed-postsSigned Posts allows authors to sign posts, assuring content integrity. Signature verification proves post-signing alteration hasn't occurred.
Is Signed Posts Safe to Use in 2026?
Generally Safe
Score 100/100Signed Posts has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.
The "signed-posts" v0.5 plugin exhibits a strong security posture based on the provided static analysis. There are no identified entry points such as AJAX handlers, REST API routes, shortcodes, or cron events that are directly exposed. Furthermore, the code shows diligent use of security best practices, including the absence of dangerous functions, 100% of SQL queries utilizing prepared statements, a high percentage of properly escaped output (87%), and a significant number of nonce and capability checks (3 and 5 respectively). The absence of file operations and external HTTP requests also reduces potential attack vectors. The taint analysis revealing zero flows with unsanitized paths is particularly reassuring, indicating no immediate concerns for critical or high severity vulnerabilities originating from data flow.
The plugin's vulnerability history is also clean, with zero known CVEs recorded. This lack of past vulnerabilities, combined with the robust static analysis, suggests a well-developed and secure plugin. However, it's worth noting that a 100% output escaping rate would be ideal, and the 13% of unescaped output, while not critical in this context, could potentially become a vector if a new attack surface were introduced or an existing one overlooked in future versions. Overall, "signed-posts" v0.5 appears to be a very secure plugin with a minimal risk profile.
Key Concerns
- Minor unescaped output detected
Signed Posts Security Vulnerabilities
Signed Posts Release Timeline
Signed Posts Code Analysis
Output Escaping
Signed Posts Attack Surface
WordPress Hooks 18
Maintenance & Trust
Signed Posts Maintenance & Trust
Maintenance Signals
Community Trust
Signed Posts Alternatives
24TT Document Verifier
24tt-document-verifier
The 24TT Document Verifier is a powerful, enterprise-grade solution designed for institutions, universities, businesses, and government bodies globall …
Email OTP Login with default login form
email-otp-login-with-default-login-form
Adds email OTP (One-Time Password) verification after valid login credentials on the default wp-login.php form for added security.
Email OTP Login
email-otp-login
Adds OTP (One-Time Password) verification after login for enhanced security in WordPress. OTP is sent to the user's email.
advertSAFE Site Seal
advertsafe
Add trust to your website and users with the advertSAFE site seal plugin. Plus earn 25% commission from any new member sign ups through your seal.
Authyo OTP for Contact Form 7
authyo-otp-for-contact-form-7
Adds OTP verification (Email, SMS, WhatsApp, Voice Call) and Google Sheets Integration (with Multi-Sheet support) to Contact Form 7.
Signed Posts Developer Profile
5 plugins · 280 total installs
How We Detect Signed Posts
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/signed-posts/css/signed-posts-frontend.css/wp-content/plugins/signed-posts/js/signed-posts-frontend.js/wp-content/plugins/signed-posts/js/signed-posts-frontend.jssigned-posts/css/signed-posts-frontend.css?ver=signed-posts/js/signed-posts-frontend.js?ver=HTML / DOM Fingerprints
signed-posts-signature-blockdata-signed-posts-signaturedata-signed-posts-methoddata-signed-posts-author-iddata-signed-posts-pgp-key-urldata-signed-posts-did-identifier<div class="signed-posts-signature-block">