
Add Code To Head Security & Risk Analysis
wordpress.org/plugins/add-code-to-headAdd custom Javascript/HTML/CSS codes to the page head without editing the template.
Is Add Code To Head Safe to Use in 2026?
Mostly Safe
Score 70/100Add Code To Head is generally safe to use though it hasn't been updated recently. 1 past CVE were resolved. Keep it updated.
The "add-code-to-head" plugin v1.17 exhibits a mixed security posture. While the static analysis reveals no immediate critical vulnerabilities in terms of attack surface, dangerous functions, or taint flows, the vulnerability history is a significant concern. The presence of one unpatched medium severity CVE, specifically a Cross-Site Scripting (XSS) vulnerability, indicates a past failure in code sanitization or input validation that has not yet been addressed. This historical pattern, coupled with the lack of demonstrated nonce and capability checks in the static analysis, raises questions about the plugin's overall robustness and its ability to prevent future similar issues. Although the plugin claims 100% output escaping, the unpatched XSS vulnerability suggests this might not be consistently applied or that the vulnerability exploited a different vector.
Despite the lack of an immediately apparent exploitable attack surface in the provided static analysis, the unpatched vulnerability is a critical red flag. The absence of explicit capability checks and nonce verifications in the analyzed code, while not directly leading to detected vulnerabilities in this specific scan, could be contributing factors to past or potential future security weaknesses. Users should be aware that the plugin has a known security flaw that remains unpatched. While other aspects of the static analysis appear clean, this single, unaddressed CVE significantly elevates the risk profile of using this version of the plugin.
Key Concerns
- Unpatched medium severity CVE (XSS)
- Lack of demonstrated capability checks
- Lack of demonstrated nonce checks
- SQL query not using prepared statements
Add Code To Head Security Vulnerabilities
CVEs by Year
Severity Breakdown
1 total CVE
Add Code To Head <= 1.17 - Authenticated (Administrator+) Stored Cross-Site Scripting
Add Code To Head Code Analysis
SQL Query Safety
Add Code To Head Attack Surface
WordPress Hooks 3
Maintenance & Trust
Add Code To Head Maintenance & Trust
Maintenance Signals
Community Trust
Add Code To Head Alternatives
Scripts n Styles
scripts-n-styles
This plugin allows Admin users to individually add HTML, custom CSS, Classes and JavaScript directly to Post, Pages or any other custom post types.
Code Embed
simple-embed-code
Code Embed provides a very easy and efficient way to embed code (JavaScript, CSS and HTML) in your posts and pages.
WebberZone Snippetz – Header, Body and Footer manager
add-to-all
The ultimate snippet manager for WordPress. Create and manage custom HTML, CSS, or JS code snippets and control where and when they are displayed.
Code Manager
code-manager
Write, test and deploy PHP, JavaScript, CSS and HTML code blocks from the WordPress dashboard.
Same Height
same-height
Force different parts of your content to the same height. Very useful if you want to present to boxes side by side. Responsive and bootstrap-friendly.
Add Code To Head Developer Profile
2 plugins · 3K total installs
How We Detect Add Code To Head
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
HTML / DOM Fingerprints
plugin-options