
Header Footer Script Adder – Insert Code in Header, Body & Footer Security & Risk Analysis
wordpress.org/plugins/header-and-footer-script-adderEasily add custom scripts and code to your WordPress site’s header, body, or footer. Perfect for Google Analytics, Tag Manager, pixels, meta tags, cus …
Is Header Footer Script Adder – Insert Code in Header, Body & Footer Safe to Use in 2026?
Generally Safe
Score 99/100Header Footer Script Adder – Insert Code in Header, Body & Footer has a strong security track record. Known vulnerabilities have been patched promptly.
The "header-and-footer-script-adder" plugin v2.0.6 exhibits a mixed security posture. On the positive side, the static analysis reveals a very small attack surface with no identified AJAX handlers, REST API routes, shortcodes, or cron events that are unprotected. This indicates a good practice in limiting direct entry points into the plugin's functionality.
However, there are notable areas of concern. The plugin performs SQL queries without using prepared statements, which is a significant risk for SQL injection vulnerabilities. Furthermore, a substantial portion of output escaping is missing, suggesting a potential for Cross-Site Scripting (XSS) vulnerabilities if user-supplied data is not handled securely before being displayed.
The plugin's vulnerability history shows one past medium-severity CVE related to XSS. While this vulnerability is currently patched, the pattern of a past XSS issue, combined with the unescaped output found in the static analysis, warrants caution. The absence of critical or high severity vulnerabilities in its history is a positive sign, but the presence of any vulnerability, especially one related to XSS, coupled with insecure coding practices in the current version, points to a need for vigilance.
Key Concerns
- Raw SQL queries without prepared statements
- Significant percentage of unescaped output
- Past medium severity CVE (XSS)
Header Footer Script Adder – Insert Code in Header, Body & Footer Security Vulnerabilities
CVEs by Year
Severity Breakdown
1 total CVE
Header Footer Script Adder – Insert Code in Header, Body & Footer <= 2.0.5 - Authenticated (Contributor+) Stored Cross-Site Scripting
Header Footer Script Adder – Insert Code in Header, Body & Footer Code Analysis
SQL Query Safety
Output Escaping
Header Footer Script Adder – Insert Code in Header, Body & Footer Attack Surface
WordPress Hooks 11
Maintenance & Trust
Header Footer Script Adder – Insert Code in Header, Body & Footer Maintenance & Trust
Maintenance Signals
Community Trust
Header Footer Script Adder – Insert Code in Header, Body & Footer Alternatives
Gerenciador de Códigos de Rastreamento Convr
codigos-de-rastreamento-convr
Instale e gerencie códigos de rastreamento e pixels de um jeito fácil e simples. Compatível com Facebook, Google Ads, Convr e mais.
ElementsKit Elementor Addons – Advanced Widgets & Templates Addons for Elementor
elementskit-lite
Join millions who empower their websites with ElementsKit Elementor Addons. Get templates, & 100+ widgets like header-footer, mega menu, custom widget
Ultimate Addons for Elementor
header-footer-elementor
Powerful Elementor addon with advanced Elementor widgets, templates, WooCommerce widgets & Header-Footer builder to build professional websites fa …
Header Footer Code Manager
header-footer-code-manager
Easily add tracking code snippets, conversion pixels, or other scripts required by third party services for analytics, marketing, or chat features.
Royal Addons for Elementor – Addons and Templates Kit for Elementor
royal-elementor-addons
Elementor templates, Header footer builder, Elementor Post Grid, Woocommerce Grid builder, Slider, Forms, Gallery, Nav menu addons, Elementor widgets.
Header Footer Script Adder – Insert Code in Header, Body & Footer Developer Profile
3 plugins · 1K total installs
How We Detect Header Footer Script Adder – Insert Code in Header, Body & Footer
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/header-and-footer-script-adder/admin/css/admin-styles.css/wp-content/plugins/header-and-footer-script-adder/admin/js/admin-scripts.js/wp-content/plugins/header-and-footer-script-adder/public/css/public-styles.css/wp-content/plugins/header-and-footer-script-adder/public/js/public-scripts.jsheader-and-footer-script-adder/admin/css/admin-styles.css?ver=header-and-footer-script-adder/admin/js/admin-scripts.js?ver=header-and-footer-script-adder/public/css/public-styles.css?ver=header-and-footer-script-adder/public/js/public-scripts.js?ver=HTML / DOM Fingerprints
asm_page_scriptsdata-asm-idASM_GLOBAL_SETTINGS