
Footer header JS & CSS Security & Risk Analysis
wordpress.org/plugins/footer-header-js-cssAdd scripts to the footer and header with versions and handles. Add styles to header.
Is Footer header JS & CSS Safe to Use in 2026?
Generally Safe
Score 85/100Footer header JS & CSS has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.
The 'footer-header-js-css' plugin, version 1.2.2, exhibits a mixed security posture. On the positive side, it has a zero attack surface, no known CVEs, and all SQL queries utilize prepared statements. This suggests a deliberate effort to avoid common vulnerabilities like SQL injection and to keep the plugin free of known exploits.
However, significant concerns arise from the code analysis, particularly the complete lack of output escaping for all 12 identified outputs. This is a critical flaw that can lead to Cross-Site Scripting (XSS) vulnerabilities if any user-supplied data is reflected without proper sanitization. The taint analysis revealing two flows with unsanitized paths, even without critical or high severity, corroborates the XSS risk, indicating potential pathways for malicious input to reach unescaped output points.
In conclusion, while the plugin avoids certain common pitfalls, the pervasive lack of output escaping is a major security weakness that exposes users to XSS attacks. The absence of any historical vulnerabilities might be due to its small attack surface and limited functionality, but it does not negate the immediate risks posed by the unescaped outputs.
Key Concerns
- All outputs unescaped
- Flows with unsanitized paths
Footer header JS & CSS Security Vulnerabilities
Footer header JS & CSS Code Analysis
Output Escaping
Data Flow Analysis
Footer header JS & CSS Attack Surface
WordPress Hooks 6
Maintenance & Trust
Footer header JS & CSS Maintenance & Trust
Maintenance Signals
Community Trust
Footer header JS & CSS Alternatives
Simple Header Footer HTML
simple-header-footer-html
A simple plugin for injecting HTML into various places in your WordPress theme output.
Assets to footer
assets-to-footer
Moves scripts and styles to the footer.
CS Remove Version Number From CSS & JS
cs-remove-version-number-from-css-js
This plugin will remove the version number from CSS and JS files.
Filename based asset cache busting
filename-based-asset-cache-busting
Filename based cache busting for WordPress scripts/styles using last modified date.
Manage/Remove version number from CSS & JS
manageremove-version-number-from-css-js
This plugin provide an option to manage or remove the version number from CSS and JS files.
Footer header JS & CSS Developer Profile
2 plugins · 100 total installs
How We Detect Footer header JS & CSS
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/footer-header-js-css/footer-header-js-and-css.phpheader_scripts_versionfooter_scripts_versionHTML / DOM Fingerprints
aria-label