Findings
The plugin works well to enable a signature canvas with Gravity Forms.
The code indentation could be neater in places.
Reason for the 'Use with caution' result
The plugin has been given this recommendation at the tester's discretion:
The implementing user should be aware that signature image files are stored in the default WordPress media location, which means they are potentially discoverable and downloadable, although some effort is needed to exploit this. This is a general issue with how WordPress stores media, rather than the plugin itself, but worth being aware of.