Simple Header Footer Scripts Security & Risk Analysis

wordpress.org/plugins/simple-header-footer-scripts

Very simple Header Footer Scripts plugin with no ads or paid upgrades.

10 active installs v1.0.0 PHP + WP 4.8+ Updated Unknown
headheaderheader-codeheader-scriptsheaders
100
A · Safe
CVEs total0
Unpatched0
Last CVENever
Safety Verdict

Is Simple Header Footer Scripts Safe to Use in 2026?

Generally Safe

Score 100/100

Simple Header Footer Scripts has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.

No known CVEs
Risk Assessment

The "simple-header-footer-scripts" plugin v1.0.0 exhibits a generally good security posture based on the provided static analysis. The absence of known vulnerabilities, critical taint flows, and dangerous function usage are strong indicators of secure development practices. Furthermore, the plugin utilizes prepared statements for its SQL queries and implements nonce and capability checks for its AJAX handler, which are essential security mechanisms. The presence of only one entry point and no unprotected endpoints further strengthens its security profile.

However, there is a notable concern regarding output escaping. With 50% of its outputs not properly escaped, this presents a potential Cross-Site Scripting (XSS) vulnerability. If user-controlled data is ever processed and outputted without proper sanitization, an attacker could inject malicious scripts. While there are no known historical vulnerabilities, this code-level weakness creates a risk that needs to be addressed. The single file operation could also be a point of interest if not handled securely, though no specific risks are identified in the analysis.

In conclusion, the plugin is well-developed in many areas, particularly in its handling of SQL and access control. The primary weakness lies in its output escaping. Addressing the unescaped outputs should be the top priority to mitigate potential XSS risks and further enhance the plugin's overall security.

Key Concerns

  • Half of output calls are not properly escaped
Vulnerabilities
None known

Simple Header Footer Scripts Security Vulnerabilities

No known vulnerabilities — this is a good sign.
Code Analysis
Analyzed Mar 16, 2026

Simple Header Footer Scripts Code Analysis

Dangerous Functions
0
Raw SQL Queries
0
0 prepared
Unescaped Output
14
14 escaped
Nonce Checks
4
Capability Checks
4
File Operations
1
External Requests
0
Bundled Libraries
0

Output Escaping

50% escaped28 total outputs
Data Flows
All sanitized

Data Flow Analysis

2 flows
settings_import (admin\class-shf-settings.php:222)
Source (user input) Sink (dangerous op) Sanitizer Transform Unsanitized Sanitized
Attack Surface

Simple Header Footer Scripts Attack Surface

Entry Points1
Unprotected0

AJAX Handlers 1

authwp_ajax_shf_dismiss_welcome_noticeadmin\class-shf-admin.php:95
WordPress Hooks 9
actioninitadmin\class-shf-admin.php:88
actionplugins_loadedadmin\class-shf-admin.php:89
actionadmin_menuadmin\class-shf-admin.php:90
actionadmin_initadmin\class-shf-admin.php:91
actionadmin_enqueue_scriptsadmin\class-shf-admin.php:92
actionadmin_noticesadmin\class-shf-admin.php:93
actionadmin_initadmin\class-shf-settings.php:57
actionshf_after_optionsadmin\class-shf-settings.php:58
actionshf_after_optionsadmin\class-shf-settings.php:59
Maintenance & Trust

Simple Header Footer Scripts Maintenance & Trust

Maintenance Signals

WordPress version tested4.9.29
Last updatedUnknown
PHP min version
Downloads1K

Community Trust

Rating0/100
Number of ratings0
Active installs10
Developer Profile

Simple Header Footer Scripts Developer Profile

Bharat Mandava

2 plugins · 20 total installs

89
trust score
Avg Security Score
93/100
Avg Patch Time
30 days
View full developer profile
Detection Fingerprints

How We Detect Simple Header Footer Scripts

Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.

Asset Fingerprints

Asset Paths
/wp-content/plugins/simple-header-footer-scripts/assets/css/shf-admin.css/wp-content/plugins/simple-header-footer-scripts/assets/js/shf-admin.js
Script Paths
/wp-content/plugins/simple-header-footer-scripts/assets/js/shf-admin.js
Version Parameters
simple-header-footer-scripts/assets/css/shf-admin.css?ver=simple-header-footer-scripts/assets/js/shf-admin.js?ver=

HTML / DOM Fingerprints

CSS Classes
shf-settings
Data Attributes
data-shf-hook-id
FAQ

Frequently Asked Questions about Simple Header Footer Scripts