
Add Custom Codes – Insert Header, Footer, Custom PHP Snippets, CSS, Javascript Security & Risk Analysis
wordpress.org/plugins/add-custom-codesAdd custom codes to your wordpress site. A completely free plugin to add Custom PHP functions, HTML, CSS, Javascript, any other codes to your website.
Is Add Custom Codes – Insert Header, Footer, Custom PHP Snippets, CSS, Javascript Safe to Use in 2026?
High Risk
Score 39/100Add Custom Codes – Insert Header, Footer, Custom PHP Snippets, CSS, Javascript carries significant security risk with 4 known CVEs, 4 still unpatched. Consider switching to a maintained alternative.
The 'add-custom-codes' plugin v4.80 presents a mixed security profile. While it demonstrates good practices like using prepared statements for all SQL queries and a significant percentage of proper output escaping, several concerning elements stand out. The presence of an unprotected AJAX handler is a critical oversight, creating a direct entry point for potential attackers. Furthermore, the plugin has a history of 4 known CVEs, with all of them remaining unpatched, including one high-severity vulnerability. This history, coupled with common vulnerability types like Missing Authorization, Cross-Site Scripting (XSS), Cross-Site Request Forgery (CSRF), and Code Injection, suggests recurring security weaknesses that have not been adequately addressed.
The static analysis also reveals a flow with unsanitized paths, which, while not classified as critical or high severity in this analysis, is a red flag, especially given the plugin's past issues. The total number of entry points is relatively low, but the existence of an unprotected one significantly elevates the risk. In conclusion, despite some positive security implementations, the plugin's unpatched vulnerabilities, historical pattern of common exploit types, and an unprotected AJAX handler make it a considerable security risk. Immediate patching of all known vulnerabilities and remediation of the unprotected AJAX endpoint are crucial.
Key Concerns
- Unpatched CVEs (4 total, 1 high, 3 medium)
- Unprotected AJAX handler
- Flow with unsanitized paths
- Only 71% of outputs properly escaped
Add Custom Codes – Insert Header, Footer, Custom PHP Snippets, CSS, Javascript Security Vulnerabilities
CVEs by Year
Severity Breakdown
4 total CVEs
Add Custom Codes <= 4.80 - Missing Authorization
Add Custom Codes <= 4.80 - Authenticated (Author+) Stored Cross-Site Scripting
Add Custom Codes <= 4.80 - Cross-Site Request Forgery
Add Custom Codes <= 4.80 - Authenticated (Contributor+) Remote Code Execution
Add Custom Codes – Insert Header, Footer, Custom PHP Snippets, CSS, Javascript Code Analysis
Output Escaping
Data Flow Analysis
Add Custom Codes – Insert Header, Footer, Custom PHP Snippets, CSS, Javascript Attack Surface
AJAX Handlers 1
Shortcodes 1
WordPress Hooks 32
Maintenance & Trust
Add Custom Codes – Insert Header, Footer, Custom PHP Snippets, CSS, Javascript Maintenance & Trust
Maintenance Signals
Community Trust
Add Custom Codes – Insert Header, Footer, Custom PHP Snippets, CSS, Javascript Alternatives
Simple Custom CSS and JS
custom-css-js
Easily add Custom CSS or JS to your website with an awesome editor.
Insert Headers And Footers
wp-headers-and-footers
Include inline javascript, stylesheets, CSS code or anything you want in Header and Footer areas of your WordPress with ease.
Simple Custom CSS Plugin
simple-custom-css
Add Custom CSS to your WordPress site without any hassles.
Simple CSS
simple-css
Add CSS to your website through an admin editor, the Customizer or a metabox for page/post specific CSS.
WP Add Custom CSS
wp-add-custom-css
Add custom css to the whole website and to specific posts and pages.
Add Custom Codes – Insert Header, Footer, Custom PHP Snippets, CSS, Javascript Developer Profile
1 plugin · 1K total installs
How We Detect Add Custom Codes – Insert Header, Footer, Custom PHP Snippets, CSS, Javascript
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/add-custom-codes/assets/css/codemirror-material.css/wp-content/plugins/add-custom-codes/assets/css/style43.css/wp-content/plugins/add-custom-codes/assets/js/scripts.js/wp-content/plugins/add-custom-codes/assets/css/about.css/wp-content/plugins/add-custom-codes/assets/js/scripts.jsadd-custom-codes/assets/css/style43.css?ver=add-custom-codes/assets/js/scripts.js?ver=HTML / DOM Fingerprints
<!-- Global CSS by Add Custom Codes --><!-- End - Global CSS by Add Custom Codes --><!-- Global Header Codes by Add Custom Codes --><!-- End - Global Header Codes by Add Custom Codes -->+2 moredata-accodes-toggleaccodes_dataaccodes_toggle_snippet_nonce