Header Footer Script Adder – Insert Code in Header, Body & Footer Security & Risk Analysis

wordpress.org/plugins/header-and-footer-script-adder

Easily add custom scripts and code to your WordPress site’s header, body, or footer. Perfect for Google Analytics, Tag Manager, pixels, meta tags, cus …

1K active installs v2.0.6 PHP 7.4+ WP 6.0+ Updated Nov 3, 2025
add-scriptsbodyfooterheaderinsert-code
99
A · Safe
CVEs total1
Unpatched0
Last CVEDec 12, 2025
Safety Verdict

Is Header Footer Script Adder – Insert Code in Header, Body & Footer Safe to Use in 2026?

Generally Safe

Score 99/100

Header Footer Script Adder – Insert Code in Header, Body & Footer has a strong security track record. Known vulnerabilities have been patched promptly. It's a solid choice for most WordPress installations.

1 known CVELast CVE: Dec 12, 2025Updated 6mo ago
Risk Assessment

The "header-and-footer-script-adder" plugin v2.0.6 exhibits a mixed security posture. On the positive side, the static analysis reveals a very small attack surface with no identified AJAX handlers, REST API routes, shortcodes, or cron events that are unprotected. This indicates a good practice in limiting direct entry points into the plugin's functionality.

However, there are notable areas of concern. The plugin performs SQL queries without using prepared statements, which is a significant risk for SQL injection vulnerabilities. Furthermore, a substantial portion of output escaping is missing, suggesting a potential for Cross-Site Scripting (XSS) vulnerabilities if user-supplied data is not handled securely before being displayed.

The plugin's vulnerability history shows one past medium-severity CVE related to XSS. While this vulnerability is currently patched, the pattern of a past XSS issue, combined with the unescaped output found in the static analysis, warrants caution. The absence of critical or high severity vulnerabilities in its history is a positive sign, but the presence of any vulnerability, especially one related to XSS, coupled with insecure coding practices in the current version, points to a need for vigilance.

Key Concerns

  • Raw SQL queries without prepared statements
  • Significant percentage of unescaped output
  • Past medium severity CVE (XSS)
Vulnerabilities
1 published

Header Footer Script Adder – Insert Code in Header, Body & Footer Security Vulnerabilities

CVEs by Year

1 CVE in 2025
2025
Patched Has unpatched

Severity Breakdown

Medium
1

1 total CVE

CVE-2025-12109medium · 6.4Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')

Header Footer Script Adder – Insert Code in Header, Body & Footer <= 2.0.5 - Authenticated (Contributor+) Stored Cross-Site Scripting

Dec 12, 2025 Patched in 2.0.6 (1d)
Version History

Header Footer Script Adder – Insert Code in Header, Body & Footer Release Timeline

v2.0.6Current
v2.0.51 CVE
v2.0.41 CVE
v2.0.31 CVE
v2.0.21 CVE
v2.0.11 CVE
v2.0.01 CVE
v1.0.31 CVE
v1.0.21 CVE
v1.0.11 CVE
Code Analysis
Analyzed Mar 16, 2026

Header Footer Script Adder – Insert Code in Header, Body & Footer Code Analysis

Dangerous Functions
0
Raw SQL Queries
2
0 prepared
Unescaped Output
34
22 escaped
Nonce Checks
1
Capability Checks
3
File Operations
0
External Requests
1
Bundled Libraries
0

SQL Query Safety

0% prepared2 total queries

Output Escaping

39% escaped56 total outputs
Attack Surface

Header Footer Script Adder – Insert Code in Header, Body & Footer Attack Surface

Entry Points0
Unprotected0
WordPress Hooks 11
actionupgrader_process_completeheader_footer_script_adder.php:91
actionadmin_headheader_footer_script_adder.php:109
actionadmin_enqueue_scriptsincludes\class-core.php:127
actionadmin_enqueue_scriptsincludes\class-core.php:128
actionadmin_menuincludes\class-core.php:129
actionadmin_initincludes\class-core.php:130
actionadd_meta_boxesincludes\class-core.php:131
actionsave_postincludes\class-core.php:132
actionwp_headincludes\class-core.php:145
actionwp_body_openincludes\class-core.php:146
actionwp_footerincludes\class-core.php:147
Maintenance & Trust

Header Footer Script Adder – Insert Code in Header, Body & Footer Maintenance & Trust

Maintenance Signals

WordPress version tested6.8.5
Last updatedNov 3, 2025
PHP min version7.4
Downloads15K

Community Trust

Rating80/100
Number of ratings5
Active installs1K
Developer Profile

Header Footer Script Adder – Insert Code in Header, Body & Footer Developer Profile

mahethekiller

3 plugins · 1K total installs

100
trust score
Avg Security Score
100/100
Avg Patch Time
1 days
View full developer profile
Detection Fingerprints

How We Detect Header Footer Script Adder – Insert Code in Header, Body & Footer

Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.

Asset Fingerprints

Asset Paths
/wp-content/plugins/header-and-footer-script-adder/admin/css/admin-styles.css/wp-content/plugins/header-and-footer-script-adder/admin/js/admin-scripts.js/wp-content/plugins/header-and-footer-script-adder/public/css/public-styles.css/wp-content/plugins/header-and-footer-script-adder/public/js/public-scripts.js
Version Parameters
header-and-footer-script-adder/admin/css/admin-styles.css?ver=header-and-footer-script-adder/admin/js/admin-scripts.js?ver=header-and-footer-script-adder/public/css/public-styles.css?ver=header-and-footer-script-adder/public/js/public-scripts.js?ver=

HTML / DOM Fingerprints

CSS Classes
asm_page_scripts
Data Attributes
data-asm-id
JS Globals
ASM_GLOBAL_SETTINGS
FAQ

Frequently Asked Questions about Header Footer Script Adder – Insert Code in Header, Body & Footer