Header Footer Builder for Elementor Security & Risk Analysis

wordpress.org/plugins/header-footer-builder-for-elementor

Header Footer Builder for Eelementor for WordPress & WooCommerce. Beginner-friendly, eCommerce-ready, optimized and fully compatible Plugin.

10K active installs v1.1.2 PHP 7.4+ WP 3.0+ Updated Mar 5, 2026
create-custom-header-and-footer-in-elementorelementor-footerelementor-headerelementor-templatesheader-footer-builder
100
A · Safe
CVEs total0
Unpatched0
Last CVENever
Safety Verdict

Is Header Footer Builder for Elementor Safe to Use in 2026?

Generally Safe

Score 100/100

Header Footer Builder for Elementor has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.

No known CVEs Updated 29d ago
Risk Assessment

The security posture of the "header-footer-builder-for-elementor" plugin version 1.1.3 appears to be relatively strong, with no known historical vulnerabilities and a significant focus on secure coding practices within the analyzed code. The plugin demonstrates a commendable approach to SQL queries, exclusively utilizing prepared statements, and a high percentage of properly escaped output, which greatly mitigates common injection and Cross-Site Scripting (XSS) risks. The absence of critical or high-severity taint flows further reinforces this positive assessment.

However, there are notable concerns regarding the attack surface. A substantial portion of the plugin's AJAX handlers (6 out of 8) lack authentication checks. This creates a significant entry point for potential unauthorized actions if these handlers are not inherently protected by other WordPress security mechanisms or if they perform sensitive operations. The presence of bundled libraries like Select2 and Freemius v1.0, while not flagged as outdated in the provided data, warrants attention as bundled components can sometimes introduce vulnerabilities if not kept up-to-date.

Overall, while the core code quality and vulnerability history are promising, the significant number of unprotected AJAX endpoints represent the most pressing security risk. This imbalance between generally secure coding and exposed entry points suggests that while the plugin is built with care, careful configuration and monitoring are essential to prevent exploitation of its unauthenticated AJAX handlers. The lack of past vulnerabilities is a positive indicator, but the current attack surface requires diligent attention.

Key Concerns

  • Unprotected AJAX handlers
  • Bundled library (Select2)
  • Bundled library (Freemius v1.0)
Vulnerabilities
None known

Header Footer Builder for Elementor Security Vulnerabilities

No known vulnerabilities — this is a good sign.
Code Analysis
Analyzed Mar 16, 2026

Header Footer Builder for Elementor Code Analysis

Dangerous Functions
0
Raw SQL Queries
0
0 prepared
Unescaped Output
5
139 escaped
Nonce Checks
13
Capability Checks
15
File Operations
0
External Requests
1
Bundled Libraries
2

Bundled Libraries

Select2Freemius1.0

Output Escaping

97% escaped144 total outputs
Data Flows
All sanitized

Data Flow Analysis

1 flows
<turbo-footer-template> (header-footer-template\footer-builder\turbo-footer-template.php:0)
Source (user input) Sink (dangerous op) Sanitizer Transform Unsanitized Sanitized
Attack Surface
6 unprotected

Header Footer Builder for Elementor Attack Surface

Entry Points8
Unprotected6

AJAX Handlers 8

authwp_ajax_tahefobu_create_footer_templateheader-footer-template\footer-builder\turbo-footer-template.php:164
authwp_ajax_tahefobu_save_footer_conditionsheader-footer-template\footer-builder\turbo-footer-template.php:207
authwp_ajax_tahefobu_get_footer_conditions_popupheader-footer-template\footer-builder\turbo-footer-template.php:233
authwp_ajax_tahefobu_create_header_templateheader-footer-template\header-builder\turbo-header-template.php:113
authwp_ajax_tahefobu_get_header_conditionsheader-footer-template\header-builder\turbo-header-template.php:621
authwp_ajax_tahefobu_save_header_conditionsheader-footer-template\header-builder\turbo-header-template.php:644
authwp_ajax_wppulse_reason_submitwppulse\wppulse-plugin-analytics-engine-sdk.php:43
authwp_ajax_wppulse_reason_skipwppulse\wppulse-plugin-analytics-engine-sdk.php:44
WordPress Hooks 53
actionwp_enqueue_scriptsheader-footer-builder-for-elementor.php:144
actioninitheader-footer-builder-for-elementor.php:145
actionplugins_loadedheader-footer-builder-for-elementor.php:146
actionelementor/editor/after_enqueue_stylesheader-footer-builder-for-elementor.php:147
actionelementor/elements/categories_registeredheader-footer-builder-for-elementor.php:150
actionelementor/widgets/registerheader-footer-builder-for-elementor.php:153
actionwp_enqueue_scriptsheader-footer-builder-for-elementor.php:154
actionelementor/frontend/before_enqueue_scriptsheader-footer-builder-for-elementor.php:155
actionadmin_noticesheader-footer-builder-for-elementor.php:208
actionadmin_noticesheader-footer-builder-for-elementor.php:213
actionadmin_noticesheader-footer-builder-for-elementor.php:218
filterelementor/document/urls/previewheader-footer-builder-for-elementor.php:222
actionwp_enqueue_scriptsheader-footer-builder-for-elementor.php:271
filtertemplate_includeheader-footer-builder-for-elementor.php:289
actiontemplate_redirectheader-footer-template\footer-builder\turbo-footer-render.php:7
actionwp_footerheader-footer-template\footer-builder\turbo-footer-render.php:109
actionwp_enqueue_scriptsheader-footer-template\footer-builder\turbo-footer-render.php:125
filterbody_classheader-footer-template\footer-builder\turbo-footer-render.php:167
actioninitheader-footer-template\footer-builder\turbo-footer-template.php:7
actionelementor/initheader-footer-template\footer-builder\turbo-footer-template.php:34
actionadmin_footer-edit.phpheader-footer-template\footer-builder\turbo-footer-template.php:41
filtermanage_tahefobu_footer_posts_columnsheader-footer-template\footer-builder\turbo-footer-template.php:259
actionmanage_tahefobu_footer_posts_custom_columnheader-footer-template\footer-builder\turbo-footer-template.php:264
filterbody_classheader-footer-template\footer-builder\turbo-footer-template.php:371
actionadmin_enqueue_scriptsheader-footer-template\footer-builder\turbo-footer-template.php:385
actionastra_mastheadheader-footer-template\header-builder\turbo-header-render.php:102
actionelementskit/headerheader-footer-template\header-builder\turbo-header-render.php:103
actioninitheader-footer-template\header-builder\turbo-header-template.php:7
actionelementor/initheader-footer-template\header-builder\turbo-header-template.php:34
actionadmin_footer-edit.phpheader-footer-template\header-builder\turbo-header-template.php:41
actionadmin_enqueue_scriptsheader-footer-template\header-builder\turbo-header-template.php:160
actionadmin_menuheader-footer-template\header-builder\turbo-header-template.php:204
actionadmin_post_tahefobu_create_header_templateheader-footer-template\header-builder\turbo-header-template.php:224
actiontemplate_redirectheader-footer-template\header-builder\turbo-header-template.php:356
filterbody_classheader-footer-template\header-builder\turbo-header-template.php:388
actionwp_enqueue_scriptsheader-footer-template\header-builder\turbo-header-template.php:398
actionwp_headheader-footer-template\header-builder\turbo-header-template.php:438
actionwp_headheader-footer-template\header-builder\turbo-header-template.php:498
filtermanage_tahefobu_header_posts_columnsheader-footer-template\header-builder\turbo-header-template.php:523
actionmanage_tahefobu_header_posts_custom_columnheader-footer-template\header-builder\turbo-header-template.php:527
actionadmin_footer-edit.phpheader-footer-template\header-builder\turbo-header-template.php:555
actionadmin_menuheader-footer-template\header-footer-menu\header-footer-menu.php:15
actionelementor/initheader-footer-template\header-footer-menu\header-footer-menu.php:46
actionwp_enqueue_scriptsheader-footer-template\header-footer-menu\header-footer-menu.php:58
filterelementor/frontend/print_cssheader-footer-template\header-footer-menu\header-footer-menu.php:70
actionadmin_noticesincludes\class-hfb-recommend-turbo-addons.php:12
filterwalker_nav_menu_start_elwidgets\navigation-menu-hf.php:1510
filternav_menu_link_attributeswidgets\navigation-menu-hf.php:1511
filternav_menu_submenu_css_classwidgets\navigation-menu-hf.php:1512
filternav_menu_item_idwidgets\navigation-menu-hf.php:1513
actionupgrader_process_completewppulse\wppulse-plugin-analytics-engine-sdk.php:37
actiondeleted_pluginwppulse\wppulse-plugin-analytics-engine-sdk.php:38
actionadmin_footerwppulse\wppulse-plugin-analytics-engine-sdk.php:42
Maintenance & Trust

Header Footer Builder for Elementor Maintenance & Trust

Maintenance Signals

WordPress version tested6.9.4
Last updatedMar 5, 2026
PHP min version7.4
Downloads48K

Community Trust

Rating100/100
Number of ratings2
Active installs10K
Developer Profile

Header Footer Builder for Elementor Developer Profile

Turbo Addons

4 plugins · 11K total installs

79
trust score
Avg Security Score
100/100
Avg Patch Time
104 days
View full developer profile
Detection Fingerprints

How We Detect Header Footer Builder for Elementor

Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.

Asset Fingerprints

Asset Paths
/wp-content/plugins/header-footer-builder-for-elementor/assets/css/hfbf-frontend.css/wp-content/plugins/header-footer-builder-for-elementor/assets/js/hfbf-frontend.js/wp-content/plugins/header-footer-builder-for-elementor/assets/css/hfbf-admin.css/wp-content/plugins/header-footer-builder-for-elementor/assets/js/hfbf-admin.js/wp-content/plugins/header-footer-builder-for-elementor/assets/js/hfbf-editor.js/wp-content/plugins/header-footer-builder-for-elementor/helper/helper.php
Script Paths
/wp-content/plugins/header-footer-builder-for-elementor/assets/js/hfbf-frontend.js/wp-content/plugins/header-footer-builder-for-elementor/assets/js/hfbf-admin.js/wp-content/plugins/header-footer-builder-for-elementor/assets/js/hfbf-editor.js
Version Parameters
/wp-content/plugins/header-footer-builder-for-elementor/assets/css/hfbf-frontend.css?ver=/wp-content/plugins/header-footer-builder-for-elementor/assets/js/hfbf-frontend.js?ver=/wp-content/plugins/header-footer-builder-for-elementor/assets/css/hfbf-admin.css?ver=/wp-content/plugins/header-footer-builder-for-elementor/assets/js/hfbf-admin.js?ver=/wp-content/plugins/header-footer-builder-for-elementor/assets/js/hfbf-editor.js?ver=

HTML / DOM Fingerprints

CSS Classes
tahefobu-header-footer-builder-for-elementortahefobu-hfbf-frontend
Data Attributes
data-tahefobu-hfbf-frontend
JS Globals
tahefobu_hfbf_params
REST Endpoints
/wp-json/tahefobu/v1/get_template
FAQ

Frequently Asked Questions about Header Footer Builder for Elementor