Header Footer Custom Html Security & Risk Analysis

wordpress.org/plugins/header-footer-custom-html

All in one light-weight plugin to add custom html, sticky html, custom css, or custom javascript in header and footer in any page/post or all pages/po …

1K active installs v2.0.2 PHP 5.6+ WP 4.8+ Updated May 12, 2025
header-footerheader-footer-cssheader-footer-custom-htmlheader-footer-htmlheader-script
100
A · Safe
CVEs total0
Unpatched0
Last CVENever
Safety Verdict

Is Header Footer Custom Html Safe to Use in 2026?

Generally Safe

Score 100/100

Header Footer Custom Html has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.

No known CVEs Updated 10mo ago
Risk Assessment

The plugin "header-footer-custom-html" v2.0.2 demonstrates a strong security posture based on the provided static analysis. The absence of any AJAX handlers, REST API routes, shortcodes, or cron events significantly limits the plugin's attack surface. Furthermore, the code shows good practices by exclusively using prepared statements for SQL queries and including nonce and capability checks, suggesting an effort to protect against common web vulnerabilities. The high percentage of properly escaped output also indicates a commitment to preventing cross-site scripting (XSS) vulnerabilities.

From a vulnerability history perspective, the lack of any recorded CVEs, past or present, is a positive indicator. This suggests the plugin has either been well-maintained and secured, or has not been a target for exploitation. The absence of critical or high-severity taint flows further reinforces the notion that sensitive data is handled with care within the plugin's code. The only potential area for slight improvement, though not explicitly flagged as a vulnerability in the provided data, is the bundled Freemius library, which, like any third-party code, should be kept up-to-date to mitigate any potential undiscovered vulnerabilities.

Overall, the plugin appears to be developed with security in mind, exhibiting minimal attack surface and employing several key security best practices. The strong vulnerability history further bolsters confidence in its current security. While the bundled Freemius library is a minor point of consideration, the plugin's present state is highly secure.

Key Concerns

  • Bundled library (Freemius v1.0) may be outdated
Vulnerabilities
None known

Header Footer Custom Html Security Vulnerabilities

No known vulnerabilities — this is a good sign.
Code Analysis
Analyzed Mar 16, 2026

Header Footer Custom Html Code Analysis

Dangerous Functions
0
Raw SQL Queries
0
0 prepared
Unescaped Output
17
50 escaped
Nonce Checks
1
Capability Checks
1
File Operations
0
External Requests
0
Bundled Libraries
1

Bundled Libraries

Freemius1.0

Output Escaping

75% escaped67 total outputs
Attack Surface

Header Footer Custom Html Attack Surface

Entry Points0
Unprotected0
WordPress Hooks 32
actionadmin_headadmin\class-enwb-hfch-admin-notices.php:43
actionadmin_initadmin\class-enwb-hfch-admin-notices.php:45
filterpermission_listheader-footer-custom-html.php:65
actionafter_uninstallheader-footer-custom-html.php:67
actionplugins_loadedincludes\class-header-footer-custom-html.php:146
actionadmin_enqueue_scriptsincludes\class-header-footer-custom-html.php:160
actionadmin_enqueue_scriptsincludes\class-header-footer-custom-html.php:161
actionadmin_menuincludes\class-header-footer-custom-html.php:163
actionadmin_menuincludes\class-header-footer-custom-html.php:164
actionafter_boo_admin_settingsincludes\class-header-footer-custom-html.php:165
actionplugin_row_metaincludes\class-header-footer-custom-html.php:170
actioninitincludes\class-header-footer-custom-html.php:185
filtermanage_edit-enwb_hfch_settings_columnsincludes\class-header-footer-custom-html.php:187
filtermanage_enwb_hfch_settings_posts_custom_columnincludes\class-header-footer-custom-html.php:188
actionadd_meta_boxesincludes\class-header-footer-custom-html.php:189
actionsave_postincludes\class-header-footer-custom-html.php:190
actionadmin_enqueue_scriptsincludes\class-header-footer-custom-html.php:192
actionadmin_enqueue_scriptsincludes\class-header-footer-custom-html.php:193
actionwp_enqueue_scriptsincludes\class-header-footer-custom-html.php:206
actionwp_enqueue_scriptsincludes\class-header-footer-custom-html.php:207
actionwp_enqueue_scriptsincludes\class-header-footer-custom-html.php:209
actionwp_headincludes\class-header-footer-custom-html.php:210
actionwp_body_openincludes\class-header-footer-custom-html.php:211
actionwp_footerincludes\class-header-footer-custom-html.php:212
actionwp_footerincludes\class-header-footer-custom-html.php:213
filterenweby_get_custom_html_header_filterincludes\class-header-footer-custom-html.php:215
filterenweby_get_custom_html_footer_filterincludes\class-header-footer-custom-html.php:216
filterenweby_get_custom_script_header_filterincludes\class-header-footer-custom-html.php:217
filterenweby_get_custom_script_footer_filterincludes\class-header-footer-custom-html.php:218
filterenweby_hfch_script_location_header_filterincludes\class-header-footer-custom-html.php:219
filterenweby_hfch_script_location_footer_filterincludes\class-header-footer-custom-html.php:220
filterenweby_get_custom_css_filterincludes\class-header-footer-custom-html.php:221
Maintenance & Trust

Header Footer Custom Html Maintenance & Trust

Maintenance Signals

WordPress version tested6.8.5
Last updatedMay 12, 2025
PHP min version5.6
Downloads16K

Community Trust

Rating60/100
Number of ratings2
Active installs1K
Developer Profile

Header Footer Custom Html Developer Profile

enweby

6 plugins · 4K total installs

94
trust score
Avg Security Score
100/100
Avg Patch Time
30 days
View full developer profile
Detection Fingerprints

How We Detect Header Footer Custom Html

Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.

Asset Fingerprints

Asset Paths
/wp-content/plugins/header-footer-custom-html/assets/css/header-footer-custom-html-admin.css/wp-content/plugins/header-footer-custom-html/assets/js/header-footer-custom-html-admin.js
Version Parameters
header-footer-custom-html/assets/css/header-footer-custom-html-admin.css?ver=header-footer-custom-html/assets/js/header-footer-custom-html-admin.js?ver=

HTML / DOM Fingerprints

CSS Classes
enwbhfch_main_tableenwbhfch_table_headerenwbhfch_table_bodyenwbhfch_content_type_selectenwbhfch_post_type_selectenwbhfch_device_type_selectenwbhfch_setting_title_inputenwbhfch_setting_code_editor+2 more
HTML Comments
<!-- Main Plugin Menu --><!-- Settings Page Content --><!-- HTML/CSS/JS Code Editor --><!-- Settings Form -->+1 more
Data Attributes
data-enwbhfch-setting-iddata-enwbhfch-device-typedata-enwbhfch-content-type
JS Globals
enwbhfch_admin_params
REST Endpoints
/wp-json/header-footer-custom-html/v1/settings/wp-json/header-footer-custom-html/v1/preview
FAQ

Frequently Asked Questions about Header Footer Custom Html