
Yeekit – Signature Field for WPForms Security & Risk Analysis
wordpress.org/plugins/yeekit-signature-field-for-wpformsSignature Field for WPForms adds a smooth, responsive signature field to your WPForms forms.
Is Yeekit – Signature Field for WPForms Safe to Use in 2026?
Generally Safe
Score 100/100Yeekit – Signature Field for WPForms has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.
The yeekit-signature-field-for-wpforms plugin v2.0.0 exhibits a generally strong security posture, particularly in its handling of SQL queries and output escaping. The absence of recorded CVEs and taint vulnerabilities further contributes to this positive assessment. The plugin demonstrates good practices by utilizing prepared statements for all SQL queries and has a high percentage of properly escaped output, minimizing risks of SQL injection and cross-site scripting (XSS) through output manipulation. The presence of a nonce check and a file operation, while not inherently risky, indicate areas where thorough review is always beneficial. However, the lack of capability checks on its single AJAX handler is a notable concern. This could allow unauthenticated or lower-privileged users to trigger potentially sensitive actions within the plugin.
The static analysis reveals a very small attack surface with only one AJAX handler, and importantly, no unprotected entry points discovered in the initial scan. The absence of dangerous functions, shortcodes, cron events, and REST API routes with weak permission callbacks is commendable. The plugin's vulnerability history is clean, suggesting a commitment to security or a lack of exploitation, which is a positive sign. Despite the excellent record, the missing capability checks on the AJAX endpoint represent the primary actionable risk identified. A balanced conclusion is that while the plugin is well-engineered with respect to common web vulnerabilities, the single AJAX endpoint warrants immediate attention to ensure proper authorization is enforced.
Key Concerns
- Missing capability checks on AJAX handler
Yeekit – Signature Field for WPForms Security Vulnerabilities
Yeekit – Signature Field for WPForms Release Timeline
Yeekit – Signature Field for WPForms Code Analysis
Output Escaping
Yeekit – Signature Field for WPForms Attack Surface
AJAX Handlers 1
WordPress Hooks 12
Maintenance & Trust
Yeekit – Signature Field for WPForms Maintenance & Trust
Maintenance Signals
Community Trust
Yeekit – Signature Field for WPForms Alternatives
GM Digital Signature for Wpforms
digital-signature-for-wpforms
Add a secure digital signature field to WPForms. Collect legally binding e-signatures on contracts, consent forms, and agreements — directly on your W …
Signature field for Elementor Forms
signature-field-for-elementor-forms
Elementor Form Signature field add-on makes it easy for users to sign your forms.
Digital Signature For Gravity Forms
digital-signature-for-gravity-forms
Gravity Forms Digital Signature is free plugin. Downloading the Gravity Form with the Digital Signature Field is free here.
Ultimate Addons for Elementor Forms
ultimate-addons-for-elementor-forms
Ultimate Addons for Elementor Forms is the must-have plugin to complement Elementor Forms.
Image CAPTCHA for Contact Form 7 and WPForms by HookAndHook (DSGVO/GDPR)
contact-form-7-image-captcha
Adds an Image CAPTCHA to Contact Form 7 and WPForms, GDPR ready, perfect WPForms or Contact Form 7 Spam Protection Image CAPTCHA, adds a honeypot
Yeekit – Signature Field for WPForms Developer Profile
59 plugins · 26K total installs
How We Detect Yeekit – Signature Field for WPForms
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/yeekit-signature-field-for-wpforms/libs/css/jquery.signature.css/wp-content/plugins/yeekit-signature-field-for-wpforms/libs/js/jquery.signature.js/wp-content/plugins/yeekit-signature-field-for-wpforms/libs/js/signature.js/wp-content/plugins/yeekit-signature-field-for-wpforms/libs/js/jquery.signature.js/wp-content/plugins/yeekit-signature-field-for-wpforms/libs/js/signature.jsyeekit-signature-field-for-wpforms/libs/css/jquery.signature.css?ver=yeekit-signature-field-for-wpforms/libs/js/jquery.signature.js?ver=yeekit-signature-field-for-wpforms/libs/js/signature.js?ver=HTML / DOM Fingerprints
wpforms-signature-fieldcolor-picker-rowdata-signature_backgrounddata-signature_colordata-signature_widthdata-signature_heightdata-signature_fullnamewpforms_signature_field<img class="wpforms-signature-field" src="