Header Footer Code Manager Security & Risk Analysis

wordpress.org/plugins/header-footer-code-manager

Easily add tracking code snippets, conversion pixels, or other scripts required by third party services for analytics, marketing, or chat features.

600K active installs v1.1.44 PHP 5.6.20+ WP 4.9+ Updated Jan 22, 2026
code-managerfooterfunctions-phpheadersnippet
98
A · Safe
CVEs total4
Unpatched0
Last CVEJul 4, 2023
Safety Verdict

Is Header Footer Code Manager Safe to Use in 2026?

Generally Safe

Score 98/100

Header Footer Code Manager has a strong security track record. Known vulnerabilities have been patched promptly.

4 known CVEsLast CVE: Jul 4, 2023Updated 2mo ago
Risk Assessment

The "header-footer-code-manager" plugin v1.1.44 exhibits a generally good security posture regarding its entry points, with no unprotected AJAX handlers or REST API routes identified in the static analysis. The code also demonstrates strong adherence to secure coding practices with a high percentage of SQL queries using prepared statements and outputs being properly escaped. The presence of 12 nonce checks and 3 capability checks further indicates an effort to secure sensitive operations. However, the plugin's history of four known CVEs, including one high-severity vulnerability, is a significant concern. The common vulnerability types (CSRF, XSS, SQL Injection) suggest potential for attackers to manipulate data or user actions, despite the current analysis showing no critical taint flows and good sanitization practices for current code. The last vulnerability was reported in July 2023, indicating that while there are no *currently* unpatched vulnerabilities, the plugin has had a history of exploitable flaws, and vigilance is required.

While the static analysis of the current version shows no immediate critical vulnerabilities and a sound approach to input/output handling, the past vulnerability record cannot be ignored. The plugin has demonstrated a pattern of introducing vulnerabilities that require patching. This suggests that ongoing security reviews and prompt patching of any future vulnerabilities will be crucial for maintaining a secure environment. The plugin's strengths lie in its current code's robustness against common static analysis pitfalls, but its historical susceptibility to exploit types that often stem from incomplete input validation or authentication bypasses warrants careful monitoring.

Key Concerns

  • History of high severity vulnerabilities
  • History of medium severity vulnerabilities
  • History of Cross-Site Request Forgery (CSRF)
  • History of Cross-site Scripting (XSS)
  • History of SQL Injection
Vulnerabilities
4

Header Footer Code Manager Security Vulnerabilities

CVEs by Year

1 CVE in 2021
2021
2 CVEs in 2022
2022
1 CVE in 2023
2023
Patched Has unpatched

Severity Breakdown

High
1
Medium
3

4 total CVEs

CVE-2023-39989medium · 5.4Cross-Site Request Forgery (CSRF)

Header Footer Code Manager <= 1.1.34 - Cross-Site Request Forgery via process_bulk_action

Jul 4, 2023 Patched in 1.1.35 (203d)
CVE-2022-0899medium · 6.1Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')

Header Footer Code Manager <= 1.1.23 - Cross-Site Scripting

Jun 25, 2022 Patched in 1.1.24 (577d)
CVE-2022-0710medium · 6.1Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')

Header Footer Code Manager <= 1.1.16 - Reflected Cross-Site Scripting

Feb 18, 2022 Patched in 1.1.17 (704d)
CVE-2021-24791high · 7.2Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')

Header Footer Code Manager <= 1.1.13 - Authenticated SQL Injections

Oct 11, 2021 Patched in 1.1.14 (834d)
Code Analysis
Analyzed Mar 16, 2026

Header Footer Code Manager Code Analysis

Dangerous Functions
0
Raw SQL Queries
3
29 prepared
Unescaped Output
15
143 escaped
Nonce Checks
12
Capability Checks
3
File Operations
1
External Requests
0
Bundled Libraries
0

SQL Query Safety

91% prepared32 total queries

Output Escaping

91% escaped158 total outputs
Data Flows
All sanitized

Data Flow Analysis

3 flows
hfcm_request_handler (99robots-header-footer-code-manager.php:765)
Source (user input) Sink (dangerous op) Sanitizer Transform Unsanitized Sanitized
Attack Surface

Header Footer Code Manager Attack Surface

Entry Points2
Unprotected0

AJAX Handlers 1

authwp_ajax_hfcm-request99robots-header-footer-code-manager.php:39

Shortcodes 1

[hfcm] 99robots-header-footer-code-manager.php:35
WordPress Hooks 11
actionplugins_loaded99robots-header-footer-code-manager.php:24
actionadmin_enqueue_scripts99robots-header-footer-code-manager.php:25
actionplugins_loaded99robots-header-footer-code-manager.php:26
actionadmin_menu99robots-header-footer-code-manager.php:27
actionadmin_init99robots-header-footer-code-manager.php:34
actionwp_head99robots-header-footer-code-manager.php:36
actionwp_footer99robots-header-footer-code-manager.php:37
actionthe_content99robots-header-footer-code-manager.php:38
actionadmin_notices99robots-header-footer-code-manager.php:326
actionadmin_notices99robots-header-footer-code-manager.php:328
actionwp_enqueue_scripts99robots-header-footer-code-manager.php:909
Maintenance & Trust

Header Footer Code Manager Maintenance & Trust

Maintenance Signals

WordPress version tested6.9.4
Last updatedJan 22, 2026
PHP min version5.6.20
Downloads8.4M

Community Trust

Rating98/100
Number of ratings304
Active installs600K
Developer Profile

Header Footer Code Manager Developer Profile

DraftPress Team

12 plugins · 613K total installs

70
trust score
Avg Security Score
87/100
Avg Patch Time
1011 days
View full developer profile
Detection Fingerprints

How We Detect Header Footer Code Manager

Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.

Asset Fingerprints

Asset Paths
/wp-content/plugins/header-footer-code-manager/js/hfcm-admin-script.js/wp-content/plugins/header-footer-code-manager/css/hfcm-admin-style.css
Script Paths
/wp-content/plugins/header-footer-code-manager/js/hfcm-admin-script.js
Version Parameters
header-footer-code-manager/css/hfcm-admin-style.css?ver=header-footer-code-manager/js/hfcm-admin-script.js?ver=

HTML / DOM Fingerprints

CSS Classes
hfcm-snippet-itemhfcm-tabhfcm-tab-contenthfcm-form-grouphfcm-inputhfcm-labelhfcm-selecthfcm-textarea
HTML Comments
<!-- HFCM Snippet Manager --><!-- HFCM Admin Scripts --><!-- HFCM Styles --><!-- HFCM Import Settings -->+1 more
Data Attributes
data-hfcm-iddata-hfcm-typedata-hfcm-location
JS Globals
hfcm_admin_scripthfcm_vars
REST Endpoints
/wp-json/hfcm/v1/snippets
Shortcode Output
[hfcm id=
FAQ

Frequently Asked Questions about Header Footer Code Manager