Yeekit – Signature Field for WPForms Security & Risk Analysis

wordpress.org/plugins/yeekit-signature-field-for-wpforms

Signature Field for WPForms adds a smooth, responsive signature field to your WPForms forms.

20 active installs v2.0.0 PHP + WP 2.0+ Updated Nov 28, 2025
formssignaturesignature-fieldwp-signaturewpforms
100
A · Safe
CVEs total0
Unpatched0
Last CVENever
Download
Safety Verdict

Is Yeekit – Signature Field for WPForms Safe to Use in 2026?

Generally Safe

Score 100/100

Yeekit – Signature Field for WPForms has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.

No known CVEs Updated 5mo ago
Risk Assessment

The yeekit-signature-field-for-wpforms plugin v2.0.0 exhibits a generally strong security posture, particularly in its handling of SQL queries and output escaping. The absence of recorded CVEs and taint vulnerabilities further contributes to this positive assessment. The plugin demonstrates good practices by utilizing prepared statements for all SQL queries and has a high percentage of properly escaped output, minimizing risks of SQL injection and cross-site scripting (XSS) through output manipulation. The presence of a nonce check and a file operation, while not inherently risky, indicate areas where thorough review is always beneficial. However, the lack of capability checks on its single AJAX handler is a notable concern. This could allow unauthenticated or lower-privileged users to trigger potentially sensitive actions within the plugin.

The static analysis reveals a very small attack surface with only one AJAX handler, and importantly, no unprotected entry points discovered in the initial scan. The absence of dangerous functions, shortcodes, cron events, and REST API routes with weak permission callbacks is commendable. The plugin's vulnerability history is clean, suggesting a commitment to security or a lack of exploitation, which is a positive sign. Despite the excellent record, the missing capability checks on the AJAX endpoint represent the primary actionable risk identified. A balanced conclusion is that while the plugin is well-engineered with respect to common web vulnerabilities, the single AJAX endpoint warrants immediate attention to ensure proper authorization is enforced.

Key Concerns

  • Missing capability checks on AJAX handler
Vulnerabilities
None known

Yeekit – Signature Field for WPForms Security Vulnerabilities

No known vulnerabilities — this is a good sign.
Version History

Yeekit – Signature Field for WPForms Release Timeline

v2.0.0Current
v1.1.0
Code Analysis
Analyzed Mar 16, 2026

Yeekit – Signature Field for WPForms Code Analysis

Dangerous Functions
0
Raw SQL Queries
0
0 prepared
Unescaped Output
3
48 escaped
Nonce Checks
1
Capability Checks
0
File Operations
1
External Requests
2
Bundled Libraries
0

Output Escaping

94% escaped51 total outputs
Attack Surface

Yeekit – Signature Field for WPForms Attack Surface

Entry Points1
Unprotected0

AJAX Handlers 1

authwp_ajax_yeekit_dismiss_notyyeekit\document.php:13
WordPress Hooks 12
actionwpforms_frontend_jssignature.php:18
actionwpforms_frontend_csssignature.php:19
filterwpforms_html_field_valuesignature.php:20
actionadmin_menuyeekit\document.php:10
actionadmin_enqueue_scriptsyeekit\document.php:11
filterfluentform_global_addonsyeekit\document.php:12
actionadmin_noticesyeekit\document.php:14
actionelementor/element/form/section_form_options/after_section_endyeekit\document.php:15
actionadmin_inityeekit\document.php:17
actionelementor/editor/after_enqueue_stylesyeekit\document.php:19
filterhttp_responseyeekit\document.php:208
actioninityeekit-signature-field-for-wpforms.php:18
Maintenance & Trust

Yeekit – Signature Field for WPForms Maintenance & Trust

Maintenance Signals

WordPress version tested6.9.4
Last updatedNov 28, 2025
PHP min version
Downloads401

Community Trust

Rating0/100
Number of ratings0
Active installs20
Developer Profile

Yeekit – Signature Field for WPForms Developer Profile

add-ons.org

59 plugins · 26K total installs

87
trust score
Avg Security Score
99/100
Avg Patch Time
48 days
View full developer profile
Detection Fingerprints

How We Detect Yeekit – Signature Field for WPForms

Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.

Asset Fingerprints

Asset Paths
/wp-content/plugins/yeekit-signature-field-for-wpforms/libs/css/jquery.signature.css/wp-content/plugins/yeekit-signature-field-for-wpforms/libs/js/jquery.signature.js/wp-content/plugins/yeekit-signature-field-for-wpforms/libs/js/signature.js
Script Paths
/wp-content/plugins/yeekit-signature-field-for-wpforms/libs/js/jquery.signature.js/wp-content/plugins/yeekit-signature-field-for-wpforms/libs/js/signature.js
Version Parameters
yeekit-signature-field-for-wpforms/libs/css/jquery.signature.css?ver=yeekit-signature-field-for-wpforms/libs/js/jquery.signature.js?ver=yeekit-signature-field-for-wpforms/libs/js/signature.js?ver=

HTML / DOM Fingerprints

CSS Classes
wpforms-signature-fieldcolor-picker-row
Data Attributes
data-signature_backgrounddata-signature_colordata-signature_widthdata-signature_heightdata-signature_fullname
JS Globals
wpforms_signature_field
Shortcode Output
<img class="wpforms-signature-field" src="
FAQ

Frequently Asked Questions about Yeekit – Signature Field for WPForms