Header Enhancement Security & Risk Analysis

wordpress.org/plugins/header-enhancement

Header Enhancement allows you to add an expressive custom header video on your website with features like mobile compatibility and sound effects.

600 active installs v2.0 PHP + WP 5.9+ Updated Mar 9, 2026
custom-headerheaderheader-mediaheader-videomobile-friendly-header
100
A · Safe
CVEs total0
Unpatched0
Last CVENever
Safety Verdict

Is Header Enhancement Safe to Use in 2026?

Generally Safe

Score 100/100

Header Enhancement has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.

No known CVEs Updated 2mo ago
Risk Assessment

The 'header-enhancement' v2.0 plugin exhibits a strong security posture based on the provided static analysis. The absence of dangerous functions, raw SQL queries, file operations, and external HTTP requests is commendable. A high percentage of output escaping and the presence of nonce and capability checks indicate good development practices for user input handling and access control. The plugin also has a clean vulnerability history with no recorded CVEs, suggesting a well-maintained and secure codebase.

However, the static analysis does reveal a potential area for scrutiny. While all identified AJAX handlers have authentication checks, the presence of 3 AJAX handlers represents the entire attack surface. If any of these checks were to be bypassed or found to be insufficient, it could lead to unauthorized actions. The taint analysis showing zero flows is excellent, but it's crucial to remember that this analysis is limited. A comprehensive review of the internal logic of these AJAX handlers would be advisable to ensure no subtle vulnerabilities exist that static analysis might miss.

Overall, 'header-enhancement' v2.0 appears to be a secure plugin. Its strengths lie in its adherence to secure coding practices and its lack of historical vulnerabilities. The primary, albeit minor, concern stems from the potential attack surface presented by the AJAX endpoints, emphasizing the importance of rigorous validation and authorization within these handlers.

Key Concerns

  • 3 AJAX handlers present potential attack surface
Vulnerabilities
None known

Header Enhancement Security Vulnerabilities

No known vulnerabilities — this is a good sign.
Version History

Header Enhancement Release Timeline

v2.0Current
v1.5.7
v1.5.6
v1.5.5
v1.5.4
v1.5.3
v1.5.2
v1.5.1
v1.5
v1.4.3
v1.4.2
v1.4.1
v1.4
v1.3
v1.2
v1.1
v1.0
Code Analysis
Analyzed Mar 16, 2026

Header Enhancement Code Analysis

Dangerous Functions
0
Raw SQL Queries
0
0 prepared
Unescaped Output
2
52 escaped
Nonce Checks
2
Capability Checks
9
File Operations
0
External Requests
0
Bundled Libraries
0

Output Escaping

96% escaped54 total outputs
Attack Surface

Header Enhancement Attack Surface

Entry Points3
Unprotected0

AJAX Handlers 3

authwp_ajax_query-themespartials\CatchThemesThemePlugin.php:12
authwp_ajax_customize_load_themespartials\CatchThemesThemePlugin.php:22
authwp_ajax_ctp_switchpartials\ctp-tabs-removal.php:90
WordPress Hooks 12
actionadmin_menuheader-enhancement.php:72
actionadmin_enqueue_scriptsheader-enhancement.php:73
actionadmin_enqueue_scriptsheader-enhancement.php:74
actionwp_print_scriptsheader-enhancement.php:75
filterplugin_row_metaheader-enhancement.php:77
actionwp_enqueue_scriptsheader-enhancement.php:78
actionadmin_enqueue_scriptspartials\CatchThemesThemePlugin.php:14
actioncustomize_registerpartials\CatchThemesThemePlugin.php:17
filterinstall_plugins_tabspartials\CatchThemesThemePlugin.php:24
filterinstall_plugins_table_api_args_catchpluginspartials\CatchThemesThemePlugin.php:25
actioninstall_plugins_catchpluginspartials\CatchThemesThemePlugin.php:26
actionadmin_initpartials\ctp-tabs-removal.php:22
Maintenance & Trust

Header Enhancement Maintenance & Trust

Maintenance Signals

WordPress version tested7.0
Last updatedMar 9, 2026
PHP min version
Downloads17K

Community Trust

Rating70/100
Number of ratings2
Active installs600
Developer Profile

Header Enhancement Developer Profile

Catch Plugins

9 plugins · 29K total installs

78
trust score
Avg Security Score
99/100
Avg Patch Time
798 days
View full developer profile
Detection Fingerprints

How We Detect Header Enhancement

Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.

Asset Fingerprints

Asset Paths
/wp-content/plugins/header-enhancement/js/jquery.matchHeight.min.js/wp-content/plugins/header-enhancement/js/dashboard-main.js/wp-content/plugins/header-enhancement/css/header-enhancement.css/wp-content/plugins/header-enhancement/css/admin-dashboard.css/wp-content/plugins/header-enhancement/css/frontend.css/wp-content/plugins/header-enhancement/js/header-enhancement.js
Script Paths
/wp-content/plugins/header-enhancement/js/jquery.matchHeight.min.js/wp-content/plugins/header-enhancement/js/dashboard-main.js/wp-content/plugins/header-enhancement/js/header-enhancement.js
Version Parameters
header-enhancement/css/header-enhancement.css?ver=header-enhancement/css/admin-dashboard.css?ver=header-enhancement/css/frontend.css?ver=header-enhancement/js/jquery.matchHeight.min.js?ver=header-enhancement/js/dashboard-main.js?ver=header-enhancement/js/header-enhancement.js?ver=

HTML / DOM Fingerprints

CSS Classes
ct-rate-stars
FAQ

Frequently Asked Questions about Header Enhancement