
Custom Header Extended Security & Risk Analysis
wordpress.org/plugins/custom-header-extendedAllows users to create a custom header on a per-post basis.
Is Custom Header Extended Safe to Use in 2026?
Generally Safe
Score 85/100Custom Header Extended has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.
The 'custom-header-extended' plugin v1.0.0 presents a generally positive security posture based on the provided static analysis. The absence of any identified vulnerabilities in its history, coupled with the code signals showing a complete lack of dangerous functions, raw SQL queries, file operations, and external HTTP requests, indicates diligent development practices. The presence of nonce and capability checks further strengthens its security by implementing common WordPress security measures.
While the attack surface appears minimal with no AJAX handlers, REST API routes, shortcodes, or cron events, the static analysis did not find any taint flows, which could be due to a lack of complex data processing or a limitation in the analysis tools used. The output escaping, while high at 79%, still leaves a small percentage of outputs potentially unescaped, which could be a minor concern if user-controlled data is involved in those specific instances.
Overall, the plugin demonstrates strong foundational security. The lack of historical vulnerabilities is a significant positive indicator. The minor concern regarding output escaping is the primary area to monitor, but without explicit taint flows or critical vulnerabilities, the risk is assessed as low. The plugin's strengths lie in its avoidance of common risky practices. The primary weakness is the potential for minor output escaping issues, though the overall risk is mitigated by the plugin's limited functionality and robust history.
Key Concerns
- 79% of outputs properly escaped (21% potentially unescaped)
Custom Header Extended Security Vulnerabilities
Custom Header Extended Code Analysis
Output Escaping
Custom Header Extended Attack Surface
WordPress Hooks 19
Maintenance & Trust
Custom Header Extended Maintenance & Trust
Maintenance Signals
Community Trust
Custom Header Extended Alternatives
Custom Background Extended
custom-background-extended
Allows users to create a custom background on a per-post basis.
Insights
insights
Insights allows you to quickly access and insert information (links, images, videos, maps..) into your blog posts.
Default Image Link
default-image-link
Select default settings for image link when you upload or insert images. Select default image link to None, Attachment Page, Media File or Custom URL.
Article Photos
article-photo
This plugin adds a form to your post screen that allows you to upload an image to go with your blog post. You can then use the_article_image() functio …
Recent Posts Widget With Thumbnails
recent-posts-widget-with-thumbnails
List the most recent posts with post titles, thumbnails, excerpts, authors, categories, dates and more!
Custom Header Extended Developer Profile
33 plugins · 34K total installs
How We Detect Custom Header Extended
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/custom-header-extended/js/custom-headers.min.js/wp-content/plugins/custom-header-extended/js/custom-headers.min.jscustom-header-extended/js/custom-headers.min.js?ver=