
AddFunc Head & Footer Code Security & Risk Analysis
wordpress.org/plugins/addfunc-head-footer-codeEasily add code to your head, footer and/or immediately after the opening body tag, site-wide and/or on any individual page/post.
Is AddFunc Head & Footer Code Safe to Use in 2026?
Generally Safe
Score 85/100AddFunc Head & Footer Code has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.
The "addfunc-head-footer-code" plugin v2.3 exhibits a generally good security posture based on the provided static analysis. The absence of dangerous functions, file operations, external HTTP requests, and SQL injection vulnerabilities (all queries use prepared statements) is a strong positive. Furthermore, the presence of nonce and capability checks, along with the lack of significant untrusted input flows identified by taint analysis, suggests developers have implemented some important security safeguards. The clean vulnerability history, with zero known CVEs, further bolsters confidence in its current security state.
However, a notable concern arises from the output escaping analysis. With only 29% of outputs properly escaped, a significant portion of user-generated or dynamic content displayed by the plugin could be vulnerable to Cross-Site Scripting (XSS) attacks. This is the primary weakness identified and represents a potential avenue for attackers to inject malicious scripts into pages where this plugin is active.
In conclusion, while the plugin demonstrates strengths in its backend operations and lack of known historical vulnerabilities, the insufficient output escaping is a critical oversight. Addressing the XSS risks associated with unescaped output should be a priority to improve its overall security. The very small attack surface is also a positive, as it limits the potential entry points for attackers.
Key Concerns
- Insufficient output escaping
AddFunc Head & Footer Code Security Vulnerabilities
AddFunc Head & Footer Code Code Analysis
Output Escaping
AddFunc Head & Footer Code Attack Surface
WordPress Hooks 10
Maintenance & Trust
AddFunc Head & Footer Code Maintenance & Trust
Maintenance Signals
Community Trust
AddFunc Head & Footer Code Alternatives
Embed Code – Headers & Footers by DesignBombs
embed-code
The easiest way to embed code in the head or footer of your site, globally or on a per-page/post basis.
Average Head & Footer Code
average-head-footer-code
Easily add code to your head and/or footer, site-wide and/or on any individual page/post.
GTM Code Visibility
gtm-code-visibility
Easily add Google Tag Manager code to your site and use it only when site is switched to "Search Engine Visibility".
Vanilla Bean – Meta Maid
vanilla-bean-meta-maid
Meta Maid is the simplest of plugins, allowing you to add meta tags, script tags and tracking code to
GA Code Visibility
ga-code-visibility
Easily add Google Analytics code to your head and use it only when site is switched to "Search Engine Visibility".
AddFunc Head & Footer Code Developer Profile
3 plugins · 20K total installs
How We Detect AddFunc Head & Footer Code
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
HTML / DOM Fingerprints
dashiconsdashicons-infoname="aFhfc_head_code"id="aFhfc_head_code"name="aFhfc_head_replace"id="aFhfc_head_replace"name="aFhfc_body_code"id="aFhfc_body_code"+8 moreAFHDFTRCD_IDAFHDFTRCD_NICK