
signwpdf PDF Sign & Fill Security & Risk Analysis
wordpress.org/plugins/signwpdf-pdf-sign-fillProfessional PDF signature collection plugin. Upload fillable PDFs, collect signatures, and store signed documents securely.
Is signwpdf PDF Sign & Fill Safe to Use in 2026?
Generally Safe
Score 100/100signwpdf PDF Sign & Fill has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.
The "signwpdf-pdf-sign-fill" plugin v1.1.2 exhibits a generally good security posture based on the provided static analysis. A significant strength is the absence of any identified critical or high-severity issues in taint analysis and the complete lack of historical CVEs, indicating a history of relatively secure development or prompt patching. The high percentage of prepared statements for SQL queries and properly escaped outputs are excellent practices that mitigate common web application vulnerabilities. The plugin also demonstrates a strong awareness of WordPress security mechanisms, with nonce and capability checks present on all identified AJAX handlers, which is a crucial defense against cross-site request forgery and unauthorized actions. The total absence of unprotected entry points further reinforces this positive assessment.
While the overall security is strong, there are minor areas for consideration. The presence of 40 file operations, while not inherently insecure, could represent an expanded attack surface if not carefully managed. Similarly, 4 external HTTP requests, although not flagged as issues, always introduce a potential risk if the external services are compromised or if data sent to them is not properly sanitized. The bundled Freemius v1.0 and TCPDF v1.0.004 libraries, if they are indeed outdated or have known vulnerabilities not reflected in the plugin's history, could pose a latent risk. However, given the absence of historical CVEs and taint issues, these bundled libraries appear to be well-managed or not exploitable in this context. In conclusion, the plugin is commendably secure, with the identified points being minor considerations rather than significant threats.
Key Concerns
- Bundled Freemius v1.0 library
- Bundled TCPDF v1.0.004 library
signwpdf PDF Sign & Fill Security Vulnerabilities
signwpdf PDF Sign & Fill Code Analysis
Bundled Libraries
SQL Query Safety
Output Escaping
Data Flow Analysis
signwpdf PDF Sign & Fill Attack Surface
AJAX Handlers 14
Shortcodes 6
WordPress Hooks 8
Maintenance & Trust
signwpdf PDF Sign & Fill Maintenance & Trust
Maintenance Signals
Community Trust
signwpdf PDF Sign & Fill Alternatives
E2Pdf – Export Pdf Tool for WordPress
e2pdf
PDF Builder for CF7, Divi, Elementor Forms, Everest, Fluent, Formidable, Forminator, Gravity, JFB, Ninja, WPForms, WooCommerce, Post Meta, ACF, etc.
Qualified Electronic Signatures by eID Easy
eid-easy-qualified-electonic-signature
This plugin will help you add qualified signatures to the PDF files created from the Contact From 7 responses.
Magic Import Document Extractor
magic-import-document-extractor
AI-powered document extraction for WordPress forms. Supports PDF, Word, images in 10+ languages. 10 free uploads/month.
PDF Embedder
pdf-embedder
Seamlessly embed PDFs into your content, with customizations and intelligent responsive resizing, and no third-party services or iframes.
Embed Any Document – Embed PDF, Word, PowerPoint and Excel Files
embed-any-document
Embed PDF, DOC, PPT and XLS documents easily on your WordPress website with the help of Google Docs Viewer or Microsoft Office Online.
signwpdf PDF Sign & Fill Developer Profile
1 plugin · 0 total installs
How We Detect signwpdf PDF Sign & Fill
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/signwpdf-pdf-sign-fill/freemius/freemius-sdk/start.php/wp-content/plugins/signwpdf-pdf-sign-fill/assets/css/admin.css/wp-content/plugins/signwpdf-pdf-sign-fill/assets/js/admin.js/wp-content/plugins/signwpdf-pdf-sign-fill/assets/css/pdf-interactive.css/wp-content/plugins/signwpdf-pdf-sign-fill/assets/js/pdf-interactive.js/wp-content/plugins/signwpdf-pdf-sign-fill/freemius/freemius-sdk/start.php/wp-content/plugins/signwpdf-pdf-sign-fill/assets/js/admin.js/wp-content/plugins/signwpdf-pdf-sign-fill/assets/js/pdf-interactive.jssignwpdf-pdf-sign-fill/assets/css/admin.css?ver=signwpdf-pdf-sign-fill/assets/js/admin.js?ver=signwpdf-pdf-sign-fill/assets/css/pdf-interactive.css?ver=signwpdf-pdf-sign-fill/assets/js/pdf-interactive.js?ver=HTML / DOM Fingerprints
swpdf-admin-contentswpdf-edit-fields-modalswpdf-signature-canvasswpdf-form-field<!-- DEVELOPER NOTES - READ BEFORE MAKING CHANGES --><!-- VERSION UPDATE: When updating the plugin version: --><!-- The constant is used for cache-busting JS/CSS files --><!-- If you only update the header, users will get cached old JS files! -->+34 moredata-nonce-admindata-nonce-publicSWPDF_VERSIONSWPDF_PLUGIN_URLswpdf_fs$swpdf_fs/wp-json/signwpdf/v1/save-signature/wp-json/signwpdf/v1/get-pdf-template