
Simple Header Footer Scripts Security & Risk Analysis
wordpress.org/plugins/simple-header-footer-scriptsVery simple Header Footer Scripts plugin with no ads or paid upgrades.
Is Simple Header Footer Scripts Safe to Use in 2026?
Generally Safe
Score 100/100Simple Header Footer Scripts has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.
The "simple-header-footer-scripts" plugin v1.0.0 exhibits a generally good security posture based on the provided static analysis. The absence of known vulnerabilities, critical taint flows, and dangerous function usage are strong indicators of secure development practices. Furthermore, the plugin utilizes prepared statements for its SQL queries and implements nonce and capability checks for its AJAX handler, which are essential security mechanisms. The presence of only one entry point and no unprotected endpoints further strengthens its security profile.
However, there is a notable concern regarding output escaping. With 50% of its outputs not properly escaped, this presents a potential Cross-Site Scripting (XSS) vulnerability. If user-controlled data is ever processed and outputted without proper sanitization, an attacker could inject malicious scripts. While there are no known historical vulnerabilities, this code-level weakness creates a risk that needs to be addressed. The single file operation could also be a point of interest if not handled securely, though no specific risks are identified in the analysis.
In conclusion, the plugin is well-developed in many areas, particularly in its handling of SQL and access control. The primary weakness lies in its output escaping. Addressing the unescaped outputs should be the top priority to mitigate potential XSS risks and further enhance the plugin's overall security.
Key Concerns
- Half of output calls are not properly escaped
Simple Header Footer Scripts Security Vulnerabilities
Simple Header Footer Scripts Code Analysis
Output Escaping
Data Flow Analysis
Simple Header Footer Scripts Attack Surface
AJAX Handlers 1
WordPress Hooks 9
Maintenance & Trust
Simple Header Footer Scripts Maintenance & Trust
Maintenance Signals
Community Trust
Simple Header Footer Scripts Alternatives
Per Page Headers and Footers Code
per-page-headers-and-footers-code
This plugin allows you to add header and footer code to your wordpress website on a per page basis.
Headers Security Advanced & HSTS WP
headers-security-advanced-hsts-wp
Best all-in-one WordPress security plugin, uses HTTP & HSTS response headers to avoid vulnerabilities: XSS, injection, clickjacking. Force HTTP/HTTPS.
WP Hide & Security Enhancer
wp-hide-security-enhancer
Protect your website by concealing vulnerable WordPress traces, plugins, themes, login/admin url. 2FA, Captcha, Firewall, Security Headers etc.
HTTP Headers
http-headers
HTTP Headers adds CORS & security HTTP headers to your website.
Unique Headers
unique-headers
Adds the ability to use unique custom header images on individual pages, posts or categories or tags.
Simple Header Footer Scripts Developer Profile
2 plugins · 20 total installs
How We Detect Simple Header Footer Scripts
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/simple-header-footer-scripts/assets/css/shf-admin.css/wp-content/plugins/simple-header-footer-scripts/assets/js/shf-admin.js/wp-content/plugins/simple-header-footer-scripts/assets/js/shf-admin.jssimple-header-footer-scripts/assets/css/shf-admin.css?ver=simple-header-footer-scripts/assets/js/shf-admin.js?ver=HTML / DOM Fingerprints
shf-settingsdata-shf-hook-id