
Per Page Headers and Footers Code Security & Risk Analysis
wordpress.org/plugins/per-page-headers-and-footers-codeThis plugin allows you to add header and footer code to your wordpress website on a per page basis.
Is Per Page Headers and Footers Code Safe to Use in 2026?
Generally Safe
Score 85/100Per Page Headers and Footers Code has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.
The plugin "per-page-headers-and-footers-code" v1.0.0 exhibits a mixed security posture. On the positive side, it utilizes prepared statements for all SQL queries and includes a nonce check and capability check for its single AJAX handler. There is no recorded vulnerability history, suggesting a good track record so far. However, a significant concern is the lack of authentication checks on its sole AJAX entry point. This unprotected AJAX handler represents a direct attack vector that could be exploited by unauthenticated users.
Furthermore, the static analysis reveals that none of the 21 identified output points are properly escaped. This is a critical vulnerability that could lead to Cross-Site Scripting (XSS) attacks. If malicious data is processed and then outputted without proper sanitization, an attacker could inject arbitrary JavaScript code into pages viewed by other users. While taint analysis shows no flows, this is likely due to the limited scope of the analysis or the specific nature of the code. The presence of an unprotected AJAX handler and widespread unescaped output are the most pressing security risks associated with this plugin.
Key Concerns
- AJAX handler without auth check
- Unescaped output
Per Page Headers and Footers Code Security Vulnerabilities
Per Page Headers and Footers Code Code Analysis
Output Escaping
Per Page Headers and Footers Code Attack Surface
AJAX Handlers 1
WordPress Hooks 11
Maintenance & Trust
Per Page Headers and Footers Code Maintenance & Trust
Maintenance Signals
Community Trust
Per Page Headers and Footers Code Alternatives
No alternatives data available yet.
Per Page Headers and Footers Code Developer Profile
1 plugin · 0 total installs
How We Detect Per Page Headers and Footers Code
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/per-page-headers-and-footers-code/assets/js/admin.js/wp-content/plugins/per-page-headers-and-footers-code/assets/css/admin.css/wp-content/plugins/per-page-headers-and-footers-code/assets/libraries/ace/ace.jsper-page-headers-and-footers-code/assets/js/admin.js?ver=per-page-headers-and-footers-code/assets/css/admin.css?ver=HTML / DOM Fingerprints
meta-fieldmeta-field-hide_header_scriptsdata-ace-modedata-ace-theme