
Head, Footer and Post Injections Security & Risk Analysis
wordpress.org/plugins/header-footerHead and Footer plugin lets you to add HTML code to the head and footer sections of your site pages, inside posts... and more!
Is Head, Footer and Post Injections Safe to Use in 2026?
Generally Safe
Score 99/100Head, Footer and Post Injections has a strong security track record. Known vulnerabilities have been patched promptly.
The "header-footer" plugin v3.3.3 exhibits a generally strong security posture based on the static analysis. The absence of direct entry points like AJAX handlers, REST API routes, shortcodes, and cron events significantly limits the attack surface. Code signals also indicate good practices, with all SQL queries utilizing prepared statements, a high percentage of output properly escaped, and the presence of nonce and capability checks. The taint analysis shows no unsanitized paths, further reinforcing the impression of secure coding. The plugin's history of a single medium-severity CVE, which is now patched, suggests a responsible approach to security over time. However, the existence of any past vulnerability, even if resolved, warrants ongoing vigilance. The plugin has demonstrated good security practices in its current version but historical issues suggest it is not entirely immune to vulnerabilities.
Key Concerns
- Medium severity vulnerability found historically
- Past vulnerability of Code Injection type
Head, Footer and Post Injections Security Vulnerabilities
CVEs by Year
Severity Breakdown
1 total CVE
Head, Footer and Post Injections <= 3.3.0 - Authenticated (Administrator+) PHP Code Injection in Multisite Environments
Head, Footer and Post Injections Code Analysis
Output Escaping
Data Flow Analysis
Head, Footer and Post Injections Attack Surface
WordPress Hooks 16
Maintenance & Trust
Head, Footer and Post Injections Maintenance & Trust
Maintenance Signals
Community Trust
Head, Footer and Post Injections Alternatives
Insert Headers And Footers
wp-headers-and-footers
Include inline javascript, stylesheets, CSS code or anything you want in Header and Footer areas of your WordPress with ease.
NinjaTeam Header Footer Custom Code
header-footer-code
Help you easy to insert CSS and JavaScript codes to or before .
In Page Script
in-page-script
This plugin helps to add scripts into the header (before close tag </HEAD>) or the footer (before close tag </BODY>).
KP Tracking Code
its-tracking-code
This plugin used to add tracking code to header & footer section.
Site Kit by Google – Analytics, Search Console, AdSense, Speed
google-site-kit
Site Kit is a one-stop solution for WordPress users to use everything Google has to offer to make them successful on the web.
Head, Footer and Post Injections Developer Profile
14 plugins · 515K total installs
How We Detect Head, Footer and Post Injections
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/header-footer/admin/css/admin.css/wp-content/plugins/header-footer/admin/js/admin.jsheader-footer/admin/css/admin.css?ver=header-footer/admin/js/admin.js?ver=HTML / DOM Fingerprints
<!-- Made with love by Stefano Lissa https://www.satollo.net --><!-- START: Head, Footer and Post Injections --><!-- END: Head, Footer and Post Injections --><!-- START: AMP Head, Footer and Post Injections -->+7 moredata-hefo-typedata-hefo-idwindow.hefo_optionswindow.hefo_is_mobile