
Header and Footer Scripts Security & Risk Analysis
wordpress.org/plugins/header-and-footer-scriptsHeader and Footer Scripts plugin allows you to add scripts to WordPress site's and just before closing tag.
Is Header and Footer Scripts Safe to Use in 2026?
Generally Safe
Score 99/100Header and Footer Scripts has a strong security track record. Known vulnerabilities have been patched promptly.
The plugin "header-and-footer-scripts" v2.4.2 exhibits a generally positive security posture based on the static analysis. The absence of direct entry points like AJAX handlers, REST API routes, or shortcodes, coupled with 100% use of prepared statements for SQL queries, indicates a strong foundation in secure coding practices. The plugin also demonstrates awareness of security mechanisms with nonce checks and capability checks in place, and a good rate of output escaping (77%). There are no critical or high-severity issues identified in the taint analysis, and no unpatched vulnerabilities in its history.
However, a few areas warrant attention. The 77% output escaping rate, while good, implies that 23% of outputs are not properly escaped, potentially leaving the door open for certain types of injection vulnerabilities if user-supplied data is involved in those unescaped outputs. Furthermore, the plugin has a history of at least one medium-severity vulnerability in the past, which was identified as Cross-site Scripting. Although this is currently unpatched, it signals a recurring type of risk that needs to be actively monitored and mitigated.
In conclusion, "header-and-footer-scripts" v2.4.2 has several strong security features, particularly in its handling of SQL and its limited attack surface. The main concern lies in the potential for XSS due to imperfect output escaping and the historical presence of such vulnerabilities. Continued vigilance in ensuring all output is properly escaped and prompt patching of any new vulnerabilities will be crucial for maintaining its security.
Key Concerns
- Improper output escaping (23% not escaped)
- Historical medium vulnerability (XSS)
Header and Footer Scripts Security Vulnerabilities
CVEs by Year
Severity Breakdown
1 total CVE
Header and Footer Scripts <= 2.3.0 - Authenticated (Contributor+) Stored Cross-Site Scripting
Header and Footer Scripts Code Analysis
Output Escaping
Header and Footer Scripts Attack Surface
WordPress Hooks 11
Maintenance & Trust
Header and Footer Scripts Maintenance & Trust
Maintenance Signals
Community Trust
Header and Footer Scripts Alternatives
Woody Code Snippets – Insert PHP, CSS, JS, and Header/Footer Scripts
insert-php
Insert PHP, JavaScript, CSS, HTML, ads, and tracking code into WordPress headers, footers, pages, and content using conditional logic, without editing …
Header Footer Script Adder – Insert Code in Header, Body & Footer
header-and-footer-script-adder
Easily add custom scripts and code to your WordPress site’s header, body, or footer. Perfect for Google Analytics, Tag Manager, pixels, meta tags, cus …
Blog News Addons For Elementor (News, Magazine and Blog Addons)
blognews-for-elementor
Build news, magazine & blog sites with BlogNews for Elementor. 50+ widgets, 20+ templates, header/footer builder. No coding required!
Softtemplates For Elementor
softtemplates-for-elementor
SoftTemplates for Elementor is a plugin that allows you to create a header, footer, blog archive, blog page, search page, single page template and sin …
Inject Header And Footer
inject-header-and-footer
This plugin allows you to easily add scripts, codes, or texts to the header (head section) and footer (footer section) of your WordPress Website and B …
Header and Footer Scripts Developer Profile
2 plugins · 210K total installs
How We Detect Header and Footer Scripts
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/header-and-footer-scripts/css/jamify-hfs-admin.cssheader-and-footer-scripts/css/jamify-hfs-admin.css?ver=HTML / DOM Fingerprints
data-id="jamify_hfs_inpost_head_script"jamify_hfs_insert_headerjamify_hfs_insert_bodyjamify_hfs_insert_footerjamify_hfs_inpost_head_script