Header Footer Script Adder – Insert Code in Header, Body & Footer Security & Risk Analysis

wordpress.org/plugins/header-and-footer-script-adder

Easily add custom scripts and code to your WordPress site’s header, body, or footer. Perfect for Google Analytics, Tag Manager, pixels, meta tags, cus …

1K active installs v2.0.6 PHP 7.4+ WP 6.0+ Updated Nov 3, 2025
add-scriptsbodyfooterheaderinsert-code
99
A · Safe
CVEs total1
Unpatched0
Last CVEDec 12, 2025
Safety Verdict

Is Header Footer Script Adder – Insert Code in Header, Body & Footer Safe to Use in 2026?

Generally Safe

Score 99/100

Header Footer Script Adder – Insert Code in Header, Body & Footer has a strong security track record. Known vulnerabilities have been patched promptly.

1 known CVELast CVE: Dec 12, 2025Updated 5mo ago
Risk Assessment

The "header-and-footer-script-adder" plugin v2.0.6 exhibits a mixed security posture. On the positive side, the static analysis reveals a very small attack surface with no identified AJAX handlers, REST API routes, shortcodes, or cron events that are unprotected. This indicates a good practice in limiting direct entry points into the plugin's functionality.

However, there are notable areas of concern. The plugin performs SQL queries without using prepared statements, which is a significant risk for SQL injection vulnerabilities. Furthermore, a substantial portion of output escaping is missing, suggesting a potential for Cross-Site Scripting (XSS) vulnerabilities if user-supplied data is not handled securely before being displayed.

The plugin's vulnerability history shows one past medium-severity CVE related to XSS. While this vulnerability is currently patched, the pattern of a past XSS issue, combined with the unescaped output found in the static analysis, warrants caution. The absence of critical or high severity vulnerabilities in its history is a positive sign, but the presence of any vulnerability, especially one related to XSS, coupled with insecure coding practices in the current version, points to a need for vigilance.

Key Concerns

  • Raw SQL queries without prepared statements
  • Significant percentage of unescaped output
  • Past medium severity CVE (XSS)
Vulnerabilities
1

Header Footer Script Adder – Insert Code in Header, Body & Footer Security Vulnerabilities

CVEs by Year

1 CVE in 2025
2025
Patched Has unpatched

Severity Breakdown

Medium
1

1 total CVE

CVE-2025-12109medium · 6.4Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')

Header Footer Script Adder – Insert Code in Header, Body & Footer <= 2.0.5 - Authenticated (Contributor+) Stored Cross-Site Scripting

Dec 12, 2025 Patched in 2.0.6 (1d)
Code Analysis
Analyzed Mar 16, 2026

Header Footer Script Adder – Insert Code in Header, Body & Footer Code Analysis

Dangerous Functions
0
Raw SQL Queries
2
0 prepared
Unescaped Output
34
22 escaped
Nonce Checks
1
Capability Checks
3
File Operations
0
External Requests
1
Bundled Libraries
0

SQL Query Safety

0% prepared2 total queries

Output Escaping

39% escaped56 total outputs
Attack Surface

Header Footer Script Adder – Insert Code in Header, Body & Footer Attack Surface

Entry Points0
Unprotected0
WordPress Hooks 11
actionupgrader_process_completeheader_footer_script_adder.php:91
actionadmin_headheader_footer_script_adder.php:109
actionadmin_enqueue_scriptsincludes\class-core.php:127
actionadmin_enqueue_scriptsincludes\class-core.php:128
actionadmin_menuincludes\class-core.php:129
actionadmin_initincludes\class-core.php:130
actionadd_meta_boxesincludes\class-core.php:131
actionsave_postincludes\class-core.php:132
actionwp_headincludes\class-core.php:145
actionwp_body_openincludes\class-core.php:146
actionwp_footerincludes\class-core.php:147
Maintenance & Trust

Header Footer Script Adder – Insert Code in Header, Body & Footer Maintenance & Trust

Maintenance Signals

WordPress version tested6.8.5
Last updatedNov 3, 2025
PHP min version7.4
Downloads15K

Community Trust

Rating80/100
Number of ratings5
Active installs1K
Developer Profile

Header Footer Script Adder – Insert Code in Header, Body & Footer Developer Profile

mahethekiller

3 plugins · 1K total installs

100
trust score
Avg Security Score
100/100
Avg Patch Time
1 days
View full developer profile
Detection Fingerprints

How We Detect Header Footer Script Adder – Insert Code in Header, Body & Footer

Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.

Asset Fingerprints

Asset Paths
/wp-content/plugins/header-and-footer-script-adder/admin/css/admin-styles.css/wp-content/plugins/header-and-footer-script-adder/admin/js/admin-scripts.js/wp-content/plugins/header-and-footer-script-adder/public/css/public-styles.css/wp-content/plugins/header-and-footer-script-adder/public/js/public-scripts.js
Version Parameters
header-and-footer-script-adder/admin/css/admin-styles.css?ver=header-and-footer-script-adder/admin/js/admin-scripts.js?ver=header-and-footer-script-adder/public/css/public-styles.css?ver=header-and-footer-script-adder/public/js/public-scripts.js?ver=

HTML / DOM Fingerprints

CSS Classes
asm_page_scripts
Data Attributes
data-asm-id
JS Globals
ASM_GLOBAL_SETTINGS
FAQ

Frequently Asked Questions about Header Footer Script Adder – Insert Code in Header, Body & Footer