SOGO Add Script to Individual Pages Header Footer Security & Risk Analysis

wordpress.org/plugins/oh-add-script-header-footer

Simple plugin to add script to header and footer for individual pages & posts

20K active installs v3.9 PHP + WP 3.5+ Updated Jan 20, 2020
footerheaderjavascriptjsre-marketing-code
85
A · Safe
CVEs total0
Unpatched0
Last CVENever
Safety Verdict

Is SOGO Add Script to Individual Pages Header Footer Safe to Use in 2026?

Generally Safe

Score 85/100

SOGO Add Script to Individual Pages Header Footer has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.

No known CVEs Updated 6yr ago
Risk Assessment

The 'oh-add-script-header-footer' plugin version 3.9 exhibits a generally strong security posture with no recorded vulnerabilities and good adherence to common security practices like prepared statements for SQL queries and the presence of nonce and capability checks. The static analysis reveals no direct attack vectors like AJAX handlers, REST API routes, or shortcodes, which is a positive sign. However, a significant concern arises from the taint analysis, which identified one flow with an unsanitized path. This, combined with a low percentage (10%) of properly escaped outputs, indicates a potential for cross-site scripting (XSS) vulnerabilities if user-supplied data is not handled carefully within these flows or outputted. The plugin also makes external HTTP requests, which, while not inherently insecure, adds an external dependency that could be a vector if the target services are compromised. The absence of historical vulnerabilities is reassuring but should not overshadow the identified code-level concerns.

Key Concerns

  • Flow with unsanitized path
  • Low percentage of properly escaped output
Vulnerabilities
None known

SOGO Add Script to Individual Pages Header Footer Security Vulnerabilities

No known vulnerabilities — this is a good sign.
Version History

SOGO Add Script to Individual Pages Header Footer Release Timeline

No version history available.
Code Analysis
Analyzed Mar 16, 2026

SOGO Add Script to Individual Pages Header Footer Code Analysis

Dangerous Functions
0
Raw SQL Queries
0
0 prepared
Unescaped Output
19
2 escaped
Nonce Checks
2
Capability Checks
2
File Operations
0
External Requests
2
Bundled Libraries
0

Output Escaping

10% escaped21 total outputs
Data Flows · Security
1 unsanitized

Data Flow Analysis

1 flows1 with unsanitized paths
<oh-settings-page> (oh-settings-page.php:0)
Source (user input) Sink (dangerous op) Sanitizer Transform Unsanitized Sanitized
Attack Surface

SOGO Add Script to Individual Pages Header Footer Attack Surface

Entry Points0
Unprotected0
WordPress Hooks 7
actioninitoh-add-script-header-footer.php:17
actionwp_headoh-add-script-header-footer.php:100
actionwp_footeroh-add-script-header-footer.php:101
actionadd_meta_boxesoh-add-script-header-footer.php:115
actionsave_postoh-add-script-header-footer.php:119
actionadmin_menuoh-settings-page.php:22
actionadmin_initoh-settings-page.php:23
Maintenance & Trust

SOGO Add Script to Individual Pages Header Footer Maintenance & Trust

Maintenance Signals

WordPress version tested5.3.21
Last updatedJan 20, 2020
PHP min version
Downloads383K

Community Trust

Rating86/100
Number of ratings31
Active installs20K
Developer Profile

SOGO Add Script to Individual Pages Header Footer Developer Profile

SOGO

4 plugins · 25K total installs

84
trust score
Avg Security Score
85/100
Avg Patch Time
30 days
View full developer profile
Detection Fingerprints

How We Detect SOGO Add Script to Individual Pages Header Footer

Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.

Asset Fingerprints

HTML / DOM Fingerprints

FAQ

Frequently Asked Questions about SOGO Add Script to Individual Pages Header Footer