
WP Post Signature Security & Risk Analysis
wordpress.org/plugins/wp-post-signatureThis plugin allows you to append a signature after every post. Some variables can be used.
Is WP Post Signature Safe to Use in 2026?
Use With Caution
Score 63/100WP Post Signature has 1 unpatched vulnerability. Evaluate alternatives or apply available mitigations.
The "wp-post-signature" plugin v0.4.1 presents a mixed security posture. While it demonstrates some good practices, such as exclusively using prepared statements for SQL queries and including nonce and capability checks, significant concerns remain. The static analysis reveals a notable weakness in output escaping, with only 25% of outputs being properly handled. This indicates a potential for Cross-Site Scripting (XSS) vulnerabilities, where malicious scripts could be injected into the website's content. The absence of any taint analysis flows might be misleading, as it doesn't necessarily confirm the absence of vulnerabilities, especially in conjunction with the low output escaping rate. The plugin's vulnerability history is a major red flag. The presence of one unpatched medium-severity CVE, identified as Cross-Site Scripting, is a critical concern. The fact that this vulnerability is marked as "currently unpatched" and the "last vulnerability" date is in the future suggests potential issues with maintenance or a reporting anomaly, but the core issue of an unpatched XSS vulnerability remains. This history indicates a pattern of security weaknesses that require immediate attention and patching.
Key Concerns
- Unpatched CVE (Medium Severity)
- Low percentage of properly escaped output
- Zero taint flows analyzed is not definitive
WP Post Signature Security Vulnerabilities
CVEs by Year
Severity Breakdown
1 total CVE
Post Signature <= 0.4.1 - Authenticated (Author+) Stored Cross-Site Scripting
WP Post Signature Code Analysis
Output Escaping
WP Post Signature Attack Surface
WordPress Hooks 4
Maintenance & Trust
WP Post Signature Maintenance & Trust
Maintenance Signals
Community Trust
WP Post Signature Alternatives
AB Post Signature
ab-post-signature
Plugin allows you to add a signature after every post.
Author Signature
author-signature
This plugin appends the author's signature to blog posts or/and pages.
Digital Signature For Contact Form 7
digital-signature-for-contact-form-7
Contact Form 7 Signature Addon making autographs of people who want to get an E-signature in the system. We build too easy to access and use for users …
GD bbPress Tools
gd-bbpress-tools
Adds different expansions and tools to the bbPress plugin powered forums: BBCode support, signatures, various tweaks, custom views, quote...
PRyC WP: Add custom content to post and page (top/bottom)
pryc-wp-add-custom-content-to-bottom-of-post
Add custom content to post and/or page (top/bottom). You may use text, HTML, Shortcodes and JavaScript. Simple, but work...
WP Post Signature Developer Profile
2 plugins · 1K total installs
How We Detect WP Post Signature
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
HTML / DOM Fingerprints
<!-- SIGNATURE_MARK -->