
Head & Footer Code Security & Risk Analysis
wordpress.org/plugins/head-footer-codeEasy add site-wide, category and article specific custom code before the closing </head> and </body>, or after opening <body> tag.
Is Head & Footer Code Safe to Use in 2026?
Generally Safe
Score 100/100Head & Footer Code has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.
The "head-footer-code" plugin version 1.5.5 exhibits a strong security posture based on the provided static analysis. The absence of any identified AJAX handlers, REST API routes, shortcodes, or cron events with unprotected entry points is a significant strength, drastically reducing the plugin's attack surface. Furthermore, the code demonstrates good practices with a high percentage of properly escaped output, all SQL queries utilizing prepared statements, and the presence of nonce and capability checks. The complete lack of critical or high-severity taint flows, dangerous functions, file operations, or external HTTP requests further bolsters this positive assessment.
The vulnerability history is also clean, with no known CVEs recorded. This suggests a well-maintained and secure codebase over its history. While the plugin has a limited number of entry points to analyze for taint flows, the overall findings indicate a low risk of common web vulnerabilities such as SQL injection, cross-site scripting (XSS), or arbitrary file operations. The plugin appears to be developed with security in mind, prioritizing safe coding practices.
In conclusion, "head-footer-code" v1.5.5 presents a very low-risk profile. Its strengths lie in its minimal attack surface and the robust implementation of security best practices throughout its code. The lack of any historical vulnerabilities further reinforces its security. There are no apparent weaknesses or areas of concern identified in this analysis that would warrant significant deductions.
Head & Footer Code Security Vulnerabilities
Head & Footer Code Code Analysis
SQL Query Safety
Output Escaping
Head & Footer Code Attack Surface
WordPress Hooks 18
Maintenance & Trust
Head & Footer Code Maintenance & Trust
Maintenance Signals
Community Trust
Head & Footer Code Alternatives
Header Footer Script Adder – Insert Code in Header, Body & Footer
header-and-footer-script-adder
Easily add custom scripts and code to your WordPress site’s header, body, or footer. Perfect for Google Analytics, Tag Manager, pixels, meta tags, cus …
Woody Code Snippets – Insert PHP, CSS, JS, and Header/Footer Scripts
insert-php
Insert PHP, JavaScript, CSS, HTML, ads, and tracking code into WordPress headers, footers, pages, and content using conditional logic, without editing …
SOGO Add Script to Individual Pages Header Footer
oh-add-script-header-footer
Simple plugin to add script to header and footer for individual pages & posts
Embed Code – Headers & Footers by DesignBombs
embed-code
The easiest way to embed code in the head or footer of your site, globally or on a per-page/post basis.
Custom Header Footer Scripts for Customizer
custom-script-for-customizer
Add custom script to header and footer through WordPress Customizer. Edit your scripts with CodeMirror editor within Customizer.
Head & Footer Code Developer Profile
8 plugins · 108K total installs
How We Detect Head & Footer Code
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/head-footer-code/assets/css/admin.min.css/wp-content/plugins/head-footer-code/assets/css/edit.min.csshead-footer-code/assets/css/admin.min.css?ver=head-footer-code/assets/css/edit.min.css?ver=