Header and Footer Scripts Security & Risk Analysis

wordpress.org/plugins/header-and-footer-scripts

Header and Footer Scripts plugin allows you to add scripts to WordPress site's and just before closing tag.

200K active installs v2.4.2 PHP 5.6+ WP 4.6+ Updated Feb 1, 2026
footerheadheaderpostscripts
99
A · Safe
CVEs total1
Unpatched0
Last CVEJan 8, 2026
Safety Verdict

Is Header and Footer Scripts Safe to Use in 2026?

Generally Safe

Score 99/100

Header and Footer Scripts has a strong security track record. Known vulnerabilities have been patched promptly.

1 known CVELast CVE: Jan 8, 2026Updated 2mo ago
Risk Assessment

The plugin "header-and-footer-scripts" v2.4.2 exhibits a generally positive security posture based on the static analysis. The absence of direct entry points like AJAX handlers, REST API routes, or shortcodes, coupled with 100% use of prepared statements for SQL queries, indicates a strong foundation in secure coding practices. The plugin also demonstrates awareness of security mechanisms with nonce checks and capability checks in place, and a good rate of output escaping (77%). There are no critical or high-severity issues identified in the taint analysis, and no unpatched vulnerabilities in its history.

However, a few areas warrant attention. The 77% output escaping rate, while good, implies that 23% of outputs are not properly escaped, potentially leaving the door open for certain types of injection vulnerabilities if user-supplied data is involved in those unescaped outputs. Furthermore, the plugin has a history of at least one medium-severity vulnerability in the past, which was identified as Cross-site Scripting. Although this is currently unpatched, it signals a recurring type of risk that needs to be actively monitored and mitigated.

In conclusion, "header-and-footer-scripts" v2.4.2 has several strong security features, particularly in its handling of SQL and its limited attack surface. The main concern lies in the potential for XSS due to imperfect output escaping and the historical presence of such vulnerabilities. Continued vigilance in ensuring all output is properly escaped and prompt patching of any new vulnerabilities will be crucial for maintaining its security.

Key Concerns

  • Improper output escaping (23% not escaped)
  • Historical medium vulnerability (XSS)
Vulnerabilities
1

Header and Footer Scripts Security Vulnerabilities

CVEs by Year

1 CVE in 2026
2026
Patched Has unpatched

Severity Breakdown

Medium
1

1 total CVE

CVE-2025-11453medium · 6.4Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')

Header and Footer Scripts <= 2.3.0 - Authenticated (Contributor+) Stored Cross-Site Scripting

Jan 8, 2026 Patched in 2.4.0 (15d)
Code Analysis
Analyzed Mar 16, 2026

Header and Footer Scripts Code Analysis

Dangerous Functions
0
Raw SQL Queries
0
0 prepared
Unescaped Output
7
24 escaped
Nonce Checks
1
Capability Checks
4
File Operations
0
External Requests
0
Bundled Libraries
0

Output Escaping

77% escaped31 total outputs
Attack Surface

Header and Footer Scripts Attack Surface

Entry Points0
Unprotected0
WordPress Hooks 11
actioninitshfs.php:47
actionadmin_initshfs.php:48
actionadmin_menushfs.php:49
actionadmin_noticesshfs.php:50
actionupdate_option_jamify_hfs_allow_authorshfs.php:51
actionupdate_option_jamify_hfs_allow_contributorshfs.php:52
actionadmin_enqueue_scriptsshfs.php:53
actionwp_headshfs.php:54
actionwp_body_openshfs.php:55
actionwp_footershfs.php:56
actionsave_postshfs.php:110
Maintenance & Trust

Header and Footer Scripts Maintenance & Trust

Maintenance Signals

WordPress version tested6.9.4
Last updatedFeb 1, 2026
PHP min version5.6
Downloads1.6M

Community Trust

Rating92/100
Number of ratings58
Active installs200K
Developer Profile

Header and Footer Scripts Developer Profile

Anand Kumar

2 plugins · 210K total installs

94
trust score
Avg Security Score
100/100
Avg Patch Time
15 days
View full developer profile
Detection Fingerprints

How We Detect Header and Footer Scripts

Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.

Asset Fingerprints

Asset Paths
/wp-content/plugins/header-and-footer-scripts/css/jamify-hfs-admin.css
Version Parameters
header-and-footer-scripts/css/jamify-hfs-admin.css?ver=

HTML / DOM Fingerprints

Data Attributes
data-id="jamify_hfs_inpost_head_script"
JS Globals
jamify_hfs_insert_headerjamify_hfs_insert_bodyjamify_hfs_insert_footerjamify_hfs_inpost_head_script
FAQ

Frequently Asked Questions about Header and Footer Scripts