Easy Header Footer – Speedup, Security and Minify Security & Risk Analysis

wordpress.org/plugins/remove-wp-meta-tags

It is a very lightweight plugin for customizing WordPress header, add custom code and enable, disable or remove the unwanted meta tags and links from …

100 active installs v3.2.2 PHP 5.6+ WP 4.6+ Updated Jun 20, 2019
codecontentcssfooterheader
85
A · Safe
CVEs total0
Unpatched0
Last CVENever
Safety Verdict

Is Easy Header Footer – Speedup, Security and Minify Safe to Use in 2026?

Generally Safe

Score 85/100

Easy Header Footer – Speedup, Security and Minify has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.

No known CVEs Updated 6yr ago
Risk Assessment

The "remove-wp-meta-tags" plugin version 3.2.2 exhibits a mixed security posture. On the positive side, it demonstrates good practices by utilizing prepared statements for all SQL queries and incorporating a reasonable number of nonce and capability checks. There are no known critical or high severity vulnerabilities recorded in its history, nor are there any detected critical or high severity taint flows. This suggests a generally well-maintained codebase regarding common web vulnerabilities.

However, a significant concern arises from the presence of an unprotected AJAX handler. With one AJAX handler and none of the AJAX handlers having authentication checks, this represents a direct entry point for potential attackers. Furthermore, the low percentage of properly escaped output (7%) indicates a risk of Cross-Site Scripting (XSS) vulnerabilities, as user-supplied data might be rendered directly in the browser without proper sanitization. While no specific XSS vulnerabilities were flagged in the taint analysis, this lack of robust output escaping significantly increases the potential attack surface for reflected or stored XSS.

The plugin's history of zero vulnerabilities, while positive, should also be viewed with caution. It could indicate a small attack surface or a lack of rigorous security auditing. The absence of past vulnerabilities doesn't guarantee future immunity, especially when combined with identified weaknesses like the unprotected AJAX handler and insufficient output escaping. Overall, the plugin has strengths in SQL handling and nonce usage, but the unprotected AJAX endpoint and poor output escaping present notable security risks.

Key Concerns

  • Unprotected AJAX handler
  • Low percentage of properly escaped output
Vulnerabilities
None known

Easy Header Footer – Speedup, Security and Minify Security Vulnerabilities

No known vulnerabilities — this is a good sign.
Version History

Easy Header Footer – Speedup, Security and Minify Release Timeline

v3.2.2Current
v3.2.1
v3.2.0
v3.1.3
v3.1.2
v3.1.1
v3.1.0
v3.0.7
v3.0.6
v3.0.5
v3.0.4
v3.0.3
v3.0.2
v3.0.1
v3.0.0
v2.0.5
Code Analysis
Analyzed Mar 16, 2026

Easy Header Footer – Speedup, Security and Minify Code Analysis

Dangerous Functions
0
Raw SQL Queries
0
0 prepared
Unescaped Output
41
3 escaped
Nonce Checks
8
Capability Checks
9
File Operations
1
External Requests
0
Bundled Libraries
0

Output Escaping

7% escaped44 total outputs
Data Flows · Security
All sanitized

Data Flow Analysis

2 flows
ehf_process_settings_import (admin\settings\tools.php:40)
Source (user input) Sink (dangerous op) Sanitizer Transform Unsanitized Sanitized
Attack Surface
1 unprotected

Easy Header Footer – Speedup, Security and Minify Attack Surface

Entry Points1
Unprotected1

AJAX Handlers 1

authwp_ajax_ehf_trigger_flush_rewrite_rulesremove-wp-meta-tags.php:114
WordPress Hooks 55
actionadmin_noticesadmin\donate.php:12
actionadmin_initadmin\donate.php:13
actionadmin_initadmin\loader.php:17
actionadmin_menuadmin\loader.php:19
actionadd_meta_boxesadmin\meta-box.php:15
actionsave_postadmin\meta-box.php:16
actionadmin_noticesadmin\notice.php:12
actionadmin_initadmin\notice.php:13
actionadmin_initadmin\settings\tools.php:35
actionadmin_noticesadmin\settings\tools.php:64
actionadmin_initadmin\settings\tools.php:67
actionadmin_noticesadmin\settings\tools.php:87
actionadmin_initadmin\settings\tools.php:90
actioninitincludes\disable-settings.php:12
filterwp_resource_hintsincludes\disable-settings.php:28
filterxmlrpc_enabledincludes\disable-settings.php:33
filterwp_headersincludes\disable-settings.php:35
filterbloginfo_urlincludes\disable-settings.php:44
filterrest_authentication_errorsincludes\disable-settings.php:58
filterjson_enabledincludes\disable-settings.php:83
filterjson_jsonp_enabledincludes\disable-settings.php:84
filterrest_enabledincludes\disable-settings.php:87
filterrest_jsonp_enabledincludes\disable-settings.php:88
actioninitincludes\header-footer.php:12
actionwp_headincludes\header-footer.php:20
actionwp_footerincludes\header-footer.php:21
actionwp_body_openincludes\header-footer.php:24
actionamp_post_template_cssincludes\header-footer.php:28
actionamp_post_template_footerincludes\header-footer.php:29
actionamp_post_template_cssincludes\header-footer.php:30
actioninitincludes\meta-settings.php:12
actionwp_default_scriptsincludes\meta-settings.php:13
filterthe_generatorincludes\meta-settings.php:20
actionwp_headincludes\meta-settings.php:23
filterls_meta_generatorincludes\meta-settings.php:24
actionwp_headincludes\meta-settings.php:27
actionwpincludes\meta-settings.php:43
actiontemplate_redirectincludes\minify-settings.php:12
actioninitincludes\script-settings.php:12
filterstyle_loader_srcincludes\script-settings.php:19
filterscript_loader_srcincludes\script-settings.php:24
filterscript_loader_tagincludes\script-settings.php:29
filterstyle_loader_tagincludes\script-settings.php:34
actioninitincludes\security-settings.php:12
filterredirect_canonicalincludes\security-settings.php:24
actionsend_headersincludes\security-settings.php:30
actionsend_headersincludes\security-settings.php:37
actionsend_headersincludes\security-settings.php:44
actionsend_headersincludes\security-settings.php:56
actionsend_headersincludes\security-settings.php:61
actionplugins_loadedremove-wp-meta-tags.php:44
actionadmin_noticesremove-wp-meta-tags.php:84
actionadmin_enqueue_scriptsremove-wp-meta-tags.php:100
actionadmin_initremove-wp-meta-tags.php:112
filterplugin_row_metaremove-wp-meta-tags.php:153
Maintenance & Trust

Easy Header Footer – Speedup, Security and Minify Maintenance & Trust

Maintenance Signals

WordPress version tested5.2.24
Last updatedJun 20, 2019
PHP min version5.6
Downloads8K

Community Trust

Rating100/100
Number of ratings5
Active installs100
Developer Profile

Easy Header Footer – Speedup, Security and Minify Developer Profile

Sayan Datta

5 plugins · 48K total installs

71
trust score
Avg Security Score
89/100
Avg Patch Time
218 days
View full developer profile
Detection Fingerprints

How We Detect Easy Header Footer – Speedup, Security and Minify

Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.

Asset Fingerprints

Asset Paths
/wp-content/plugins/remove-wp-meta-tags/admin/assets/css/admin.min.css/wp-content/plugins/remove-wp-meta-tags/admin/assets/js/admin.min.js
Version Parameters
remove-wp-meta-tags/admin/assets/css/admin.min.css?ver=remove-wp-meta-tags/admin/assets/js/admin.min.js?ver=

HTML / DOM Fingerprints

FAQ

Frequently Asked Questions about Easy Header Footer – Speedup, Security and Minify