AddFunc Head & Footer Code Security & Risk Analysis

wordpress.org/plugins/addfunc-head-footer-code

Easily add code to your head, footer and/or immediately after the opening body tag, site-wide and/or on any individual page/post.

20K active installs v2.4 PHP + WP 3.0.1+ Updated Mar 28, 2026
add-to-headfooter-codehead-codeper-pagetracking-code
99
A · Safe
CVEs total1
Unpatched0
Last CVEApr 9, 2026
Download
Safety Verdict

Is AddFunc Head & Footer Code Safe to Use in 2026?

Generally Safe

Score 99/100

AddFunc Head & Footer Code has a strong security track record. Known vulnerabilities have been patched promptly. It's a solid choice for most WordPress installations.

1 known CVELast CVE: Apr 9, 2026Updated 1mo ago
Risk Assessment

The "addfunc-head-footer-code" plugin v2.3 exhibits a generally good security posture based on the provided static analysis. The absence of dangerous functions, file operations, external HTTP requests, and SQL injection vulnerabilities (all queries use prepared statements) is a strong positive. Furthermore, the presence of nonce and capability checks, along with the lack of significant untrusted input flows identified by taint analysis, suggests developers have implemented some important security safeguards. The clean vulnerability history, with zero known CVEs, further bolsters confidence in its current security state.

However, a notable concern arises from the output escaping analysis. With only 29% of outputs properly escaped, a significant portion of user-generated or dynamic content displayed by the plugin could be vulnerable to Cross-Site Scripting (XSS) attacks. This is the primary weakness identified and represents a potential avenue for attackers to inject malicious scripts into pages where this plugin is active.

In conclusion, while the plugin demonstrates strengths in its backend operations and lack of known historical vulnerabilities, the insufficient output escaping is a critical oversight. Addressing the XSS risks associated with unescaped output should be a priority to improve its overall security. The very small attack surface is also a positive, as it limits the potential entry points for attackers.

Key Concerns

  • Insufficient output escaping
Vulnerabilities
1 published

AddFunc Head & Footer Code Security Vulnerabilities

CVEs by Year

1 CVE in 2026
2026
Patched Has unpatched

Severity Breakdown

Medium
1

1 total CVE

CVE-2026-2305medium · 6.4Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')

AddFunc Head & Footer Code <= 2.3 - Authenticated (Contributor+) Stored Cross-Site Scripting via Custom Fields

Apr 9, 2026 Patched in 2.4 (1d)
Version History

AddFunc Head & Footer Code Release Timeline

v2.4Current
v2.31 CVE
v2.21 CVE
v2.11 CVE
v1.51 CVE
v1.41 CVE
v1.31 CVE
v1.21 CVE
v1.11 CVE
Code Analysis
Analyzed Mar 16, 2026

AddFunc Head & Footer Code Code Analysis

Dangerous Functions
0
Raw SQL Queries
0
0 prepared
Unescaped Output
15
6 escaped
Nonce Checks
1
Capability Checks
3
File Operations
0
External Requests
0
Bundled Libraries
0

Output Escaping

29% escaped21 total outputs
Attack Surface

AddFunc Head & Footer Code Attack Surface

Entry Points0
Unprotected0
WordPress Hooks 10
actionadmin_initaddfunc-head-footer-code.php:93
actionadmin_menuaddfunc-head-footer-code.php:94
actionwp_headaddfunc-head-footer-code.php:98
actionwp_headaddfunc-head-footer-code.php:101
actionwp_headaddfunc-head-footer-code.php:106
actionwp_print_footer_scriptsaddfunc-head-footer-code.php:116
actionwp_footeraddfunc-head-footer-code.php:119
actionwp_footeraddfunc-head-footer-code.php:122
actionadd_meta_boxesaddfunc-head-footer-code.php:134
actionsave_postaddfunc-head-footer-code.php:174
Maintenance & Trust

AddFunc Head & Footer Code Maintenance & Trust

Maintenance Signals

WordPress version tested6.9.4
Last updatedMar 28, 2026
PHP min version
Downloads244K

Community Trust

Rating100/100
Number of ratings25
Active installs20K
Developer Profile

AddFunc Head & Footer Code Developer Profile

AddFunc

3 plugins · 20K total installs

93
trust score
Avg Security Score
90/100
Avg Patch Time
1 days
View full developer profile
Detection Fingerprints

How We Detect AddFunc Head & Footer Code

Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.

Asset Fingerprints

HTML / DOM Fingerprints

CSS Classes
dashiconsdashicons-info
Data Attributes
name="aFhfc_head_code"id="aFhfc_head_code"name="aFhfc_head_replace"id="aFhfc_head_replace"name="aFhfc_body_code"id="aFhfc_body_code"+8 more
JS Globals
AFHDFTRCD_IDAFHDFTRCD_NICK
FAQ

Frequently Asked Questions about AddFunc Head & Footer Code