
Signature Add-On for WooCommerce Security & Risk Analysis
wordpress.org/plugins/woocommerce-digital-signatureAutomatically require your WooCommerce customers to sign a legally binding contract before downloading your product. Easy to Use.
Is Signature Add-On for WooCommerce Safe to Use in 2026?
Generally Safe
Score 100/100Signature Add-On for WooCommerce has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.
The WooCommerce Digital Signature plugin version 1.8.4 exhibits a generally strong security posture based on the provided static analysis and vulnerability history. The absence of known CVEs and a clean vulnerability history are significant positive indicators. The code demonstrates good practices by utilizing prepared statements for all SQL queries and implementing nonce and capability checks on its entry points, contributing to a secure foundation.
However, there are minor areas of concern that warrant attention. While the overall output escaping rate is high at 86%, the remaining 14% of unescaped outputs represent a potential risk for cross-site scripting (XSS) vulnerabilities, especially given the presence of file operations and shortcodes which can be entry points for user-supplied data. The total number of entry points, while not inherently insecure, combined with the potential for unescaped output, suggests a need for vigilance in ensuring all user-facing output is thoroughly sanitized.
In conclusion, the plugin is well-developed from a security perspective, with no critical or high-risk issues identified in the analysis. The vulnerability history is exceptionally clean, and the use of secure coding practices like prepared statements and proper authentication checks is commendable. The primary area for improvement lies in ensuring 100% output sanitization to mitigate any potential XSS vectors, thereby solidifying its security.
Key Concerns
- 14% of outputs are not properly escaped
Signature Add-On for WooCommerce Security Vulnerabilities
Signature Add-On for WooCommerce Code Analysis
SQL Query Safety
Output Escaping
Data Flow Analysis
Signature Add-On for WooCommerce Attack Surface
AJAX Handlers 2
Shortcodes 2
WordPress Hooks 52
Maintenance & Trust
Signature Add-On for WooCommerce Maintenance & Trust
Maintenance Signals
Community Trust
Signature Add-On for WooCommerce Alternatives
Signature Add-On for Gravity Forms
gravity-signature-forms-add-on
Automatically generate a legally binding & court recognized contract from a Gravity Forms submission. Proposals. Time sheets. Contracts.
Electronic Signature
electronic-signatures
This plugin helps integrate Electronic Signature on SwiftCloud.ai with Wordpress.
Essential Addons for Elementor – Popular Elementor Templates & Widgets
essential-addons-for-elementor-lite
Elementor addon offering 110+ widgets and templates — Elementor Gallery, Slider, Form, Post Grid, Menu, Accordion, WooCommerce & more.
Google for WooCommerce
google-listings-and-ads
Native integration with Google that allows merchants to easily display their products across Google’s network.
WooPayments: Integrated WooCommerce Payments
woocommerce-payments
Securely accept credit and debit cards on your WooCommerce store. Manage payments without leaving your WordPress dashboard. Only with WooPayments.
Signature Add-On for WooCommerce Developer Profile
10 plugins · 4K total installs
How We Detect Signature Add-On for WooCommerce
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/woocommerce-digital-signature/assets/js/esig_woo.js/wp-content/plugins/woocommerce-digital-signature/assets/css/esig_woo.css/wp-content/plugins/woocommerce-digital-signature/assets/css/esig_woo_admin.css/wp-content/plugins/woocommerce-digital-signature/assets/js/esig_woo.jswoocommerce-digital-signature/assets/js/esig_woo.js?ver=woocommerce-digital-signature/assets/css/esig_woo.css?ver=woocommerce-digital-signature/assets/css/esig_woo_admin.css?ver=HTML / DOM Fingerprints
esig-woo-product-agreementdata-esig-woo-product-id