
Inject Header And Footer Security & Risk Analysis
wordpress.org/plugins/inject-header-and-footerThis plugin allows you to easily add scripts, codes, or texts to the header (head section) and footer (footer section) of your WordPress Website and B …
Is Inject Header And Footer Safe to Use in 2026?
Generally Safe
Score 85/100Inject Header And Footer has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.
The "inject-header-and-footer" plugin v1.0 exhibits a generally good security posture in terms of attack surface and known vulnerabilities. It has no recorded CVEs, a clean vulnerability history, and a seemingly minimal attack surface with zero identified entry points. However, a significant concern arises from the code analysis: 100% of output operations are not properly escaped. This means that any data processed by the plugin and then displayed to users or logged could potentially be vulnerable to cross-site scripting (XSS) attacks if that data originates from an untrusted source.
While the absence of SQL injection vulnerabilities due to prepared statements and the lack of dangerous functions are strengths, the unescaped output presents a clear and present danger. The plugin's vulnerability history being entirely clean is positive, suggesting either good development practices or a lack of discovery, but it doesn't negate the risks identified in the static analysis. The lack of explicit capability checks, nonces, and authentication on potential entry points (though none were identified) is a minor concern in isolation, but could become more significant if new entry points are added in future versions without proper security considerations.
Key Concerns
- Unescaped output found
Inject Header And Footer Security Vulnerabilities
Inject Header And Footer Code Analysis
Output Escaping
Inject Header And Footer Attack Surface
WordPress Hooks 6
Maintenance & Trust
Inject Header And Footer Maintenance & Trust
Maintenance Signals
Community Trust
Inject Header And Footer Alternatives
No alternatives data available yet.
Inject Header And Footer Developer Profile
3 plugins · 140 total installs
How We Detect Inject Header And Footer
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/inject-header-and-footer/css/style.cssHTML / DOM Fingerprints
daq-ihaf-orange-colordaq-ihaf-dashboarddaq-ihaf-sidebardaq-ihaf-width-100name="daq_ihaf_header_content"name="daq_ihaf_footer_content"