Start free
The service hatch of a campground check-in cabin in the morning, navy boards and a lit lantern beside it, a clipboard of blank forms with a pen tied on with twine on the ledge next to a jar of bluebells, pines and a gravel road out of focus to the left.

WordPress

Waivers and agreements, sent from your WordPress site.

A booking comes in, a guest needs to sign, and somebody copies an address into another tab. The plugin removes that step, and WordPress tells you who has signed.

Version 1.6.0 is built and tested; it is not in the WordPress directory yet. Review there takes days to weeks. The zip above is the same code, and it updates itself once the listing is live.

What SignSealer is

SignSealer is where waivers, rental agreements and consent forms are written, signed and kept. The plugin lets your WordPress site start them.

1

Write it once in SignSealer

The document is a template in your SignSealer account: one from the library of waivers and agreements, or your own PDF. A form in SignSealer says who signs it and how they are asked.

2

Your site starts it

A WooCommerce order, a form submission or a Sign now button sends the customer to sign, with their name, email and booking details already filled in.

3

You see who signed

They sign on SignSealer's page. The signed PDF, its certificate and its evidence stay in SignSealer; WordPress shows the status on the order or the entry.

Getting started: install, connect, make the document →

What it does

Connect the site once. After that it is a block on a page and a status you can read.

A form on any page

A SignSealer agreement block in the editor, or [signsealer_sign workflow="your-form"] if you prefer a shortcode. Your forms and their shortcodes are listed under SignSealer → Templates so you are not guessing at a name.

Status, without polling

When somebody signs, SignSealer posts to your site and the plugin checks the signature, the freshness and whether it has seen that delivery before. WordPress keeps the id and the status, so a page can say whether a booking's waiver is done.

An action your own code can use

Every verified delivery fires signsealer_event. Hook it to close a task, unlock a download, mark an order, or message a host — the signature has already been checked before your handler runs.

Works with the plugins you already use

Each one is found when WordPress loads. A site without it gets none of its hooks and no screen for it.

PluginWhat happensWhere you see who signed
The block editor, and any page builder that runs shortcodes
Step-by-step guide →
Put the SignSealer agreement block on a page, or [signsealer_sign workflow="your-form"] in a shortcode widget. The visitor fills in the form and signs on SignSealer.Your SignSealer dashboard, and the signsealer_event action for your own code.
WooCommerce
Step-by-step guide →
Mark a product as needing an agreement. It is signed after payment, as soon as the order is placed, or before payment: on a page of your site, with the classic checkout and the checkout block both refusing to place the order until it is signed. The link is on the thank-you page, in the order email and under My Account.The order screen and the order notes. Works with orders stored as posts or in WooCommerce's own order tables.
WooCommerce Bookings
Step-by-step guide →
A booking you confirm starts its agreement straight away, paid or not, because it is wanted before the day. The date, time, number of people and resource fill the template's blanks.The booking's own screen.
Gravity Forms
Step-by-step guide →
Under SignSealer → Forms, choose a form's workflow and say which field is the email and which is the name. Any template blank, or any box on your own PDF that you fill in when it is sent, can come from a field: a rental form's pickup date and time land on the agreement, written out as “October 5, 2026” and “9:00 am”. After they submit, the person goes straight to the signing page, or the form's own confirmation gains the link. Your choice, per form.The entry, with a note saying what was sent and what happened.
WPForms
Step-by-step guide →
The same as Gravity Forms: map the form once, and a submission ends on the signing page or with the link in its confirmation.The entry, with a note, in WPForms Pro. WPForms Lite keeps no entries, so your SignSealer dashboard.
Fluent Forms
Step-by-step guide →
The same as Gravity Forms: map the form once, and a submission ends on the signing page or with the link in its confirmation.The entry, with a note.
Contact Form 7
Step-by-step guide →
The same mapping. Contact Form 7 keeps no entries of its own, so the link is shown under the form's message after it is sent.Your SignSealer dashboard.

After signing, the person is offered the way back to your site: the order they came from, or the page the form was on.

When your plan includes texting, the link can go by text as well as email: the checkout, or a form, shows a tick box with the consent wording beside the phone number, and a ticked box is recorded as the person's consent before anything is texted. On a plan without texting, no box is shown.

Not yet: Ninja Forms, Formidable, Forminator, SureForms and MetForm. Until they are, set that form's confirmation to redirect to your SignSealer form's public address, or to a page with the signing button. The plugin's Start here page names any of them it finds on your site.

Step-by-step guides

Every screen by the words on it, what the customer sees, and the questions people ask.

Getting started

Install the plugin, connect it to your SignSealer account with one button, and make the document your customers sign. About ten minutes.

WooCommerce

Mark the products that need an agreement. The customer signs after paying, on ordering, or before payment at checkout, and the order shows it.

WooCommerce Bookings

A booking you confirm starts its agreement straight away, paid or not, with the date, time, party size and resource filled in.

Gravity Forms

Connect a Gravity form to a SignSealer workflow once. Each submission ends on the signing page, with the person's details already on the agreement.

WPForms

Connect a WPForms form to a SignSealer workflow once, and every submission ends on the signing page with its details already on the agreement.

Fluent Forms

Connect a Fluent form to a SignSealer workflow once, and every submission ends on the signing page with its details already on the agreement.

Contact Form 7

Connect a Contact Form 7 form to a SignSealer workflow once, and every message sent ends on the signing page.

Signing button

The SignSealer agreement block or a shortcode puts a Sign now button on any page: for walk-ups, a class page, or a form plugin not supported yet.

What it will not do

Three limits on purpose. Each one is the reason a signature sent from WordPress is worth something later.

It never draws a signature pad

Signing happens on SignSealer's own pages. A canvas in WordPress posting an image to an API would make every line on the certificate untrue: the certificate says what the signing engine observed, and it cannot observe a drawing that arrived as a form field.

It never stores the evidence

Ids, a status and a link. Restore a six-month-old backup of your site and nothing about any signature changes, because nothing about any signature was there. A record that a shared host can lose is a record that loses a dispute.

It never holds a master key

The connection is OAuth 2.0 with PKCE, scoped to one business, and you end it from your SignSealer account without touching WordPress. There is no credential on the site that reaches a second account.

Connecting a site

Four steps, and the third is the one most plugins make you do by hand.

1

Install

Add the plugin and activate it. It needs WordPress 6.4 and PHP 7.4, and is tested to WordPress 7.1.

2

Connect

Open SignSealer → Start here in the WordPress menu, press Connect to SignSealer, sign in, and approve what the site may do. The site gets its own credential, not your password.

3

Nothing

Connecting registers the webhook endpoint and stores its signing secret for you. There is no address to copy between two screens and no secret to paste.

4

Choose where

Start here has a card for each integration on your site — an order, a form, a button on a page — with its steps. The document is the one you authored in SignSealer, so its text is the text the certificate commits to.

The SignSealer plugin's Start here page in WordPress, before connecting: how to connect, and the Connect to SignSealer button.
SignSealer → Start here in WordPress, on a site not yet connected. The site is an example; the screen is the plugin’s.

What a reviewer or an IT lead will ask

Written for the person who has to answer for it, not for the person who installs it.

QuestionAnswer
What does it send you?The template you chose, the values filled in, and the signer's name and email. It is listed field by field in the plugin's readme under External services, which the WordPress directory requires.
What does it keep on our site?A document id, a status and a timestamp. Deleting the plugin removes them; it does not touch anything at SignSealer, because that is not the plugin's to delete.
Can a fake delivery mark something signed?No. Every delivery is checked for an HMAC signature over the exact bytes sent, a five-minute freshness window, and whether it has been seen before. A rotation is handled: both signatures are offered and either passing is a pass.
Does it slow the site down?Nothing runs on a page a visitor loads unless that page has the block on it. The admin lists are cached for five minutes. The plugin is about forty kilobytes and has no dependencies.
Will it work with WooCommerce?Yes: after payment, when the order is placed, or before payment, with the checkout refusing to place the order until it is signed. So do WooCommerce Bookings, Gravity Forms, WPForms, Fluent Forms and Contact Form 7; the table under Works with says what each one does.
From above: a thin slab of oak beside a closed dark laptop on an otherwise empty navy desk.

Why it is deliberately thin

Because the alternative is a signature that lives on a shared host.

A signing evidence chain must not depend on a server running thirty other plugins. Everything that makes a signature worth having — consent recorded as its own event before the signature, the document's exact text fingerprinted into every entry, a hash chain that breaks if anything is altered — happens on SignSealer and can be checked afterwards by anybody holding the certificate's code, without an account and without us.

What WordPress keeps is what WordPress is good at: a page, a booking, an order, and a status beside it.

What is on the evidence trail →

One form, four ways to sign

The same agreement can start anywhere.

A form published through the plugin is the same form a member of staff can send by email or text, the same one a visitor can open from a QR code, and the same one that runs on a tablet at a counter. They are not four integrations — they are four doors into one workflow, and everything they produce lands on the same trail with the same certificate.

All integrations →

What it costs

Free to install. You need a SignSealer account, and the free plan is enough to try it.

The plugin is free and open source, licensed GPL-2.0-or-later like WordPress itself. It is a client for a SignSealer account: the free plan covers a small number of documents a month, and the paid plans start where that runs out. Nothing about the plugin is a paid add-on.

SignSealer is a product of Mashdun LLC. The plugin is not affiliated with or endorsed by the WordPress Foundation or Automattic.

A hand holding a phone showing a document and a signature, outside a timber lakeside cabin, with two guests walking to the door with luggage.

Ready when the next guest is.

Free for the first 25 agreements a month. No card to start.