
Tag Manager – Header, Body And Footer Security & Risk Analysis
wordpress.org/plugins/tag-manager-header-body-footerSimple plugin that allow you add head, body and footer codes for google tag manager, analytics & facebook pixel codes.
Is Tag Manager – Header, Body And Footer Safe to Use in 2026?
Generally Safe
Score 100/100Tag Manager – Header, Body And Footer has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.
The "tag-manager-header-body-footer" plugin, version 3.6.2, exhibits a generally strong security posture with several positive indicators. The plugin has a small attack surface, with only two AJAX handlers, and crucially, no unprotected entry points identified in the static analysis. The presence of nonce and capability checks on these handlers further bolsters its defense against common web attacks. Furthermore, the absence of any recorded vulnerabilities, critical or otherwise, in its history suggests a history of secure development practices.
However, there are areas for concern. The most significant is the use of raw SQL queries, with 100% of the four identified queries not utilizing prepared statements. This is a significant risk that could lead to SQL injection vulnerabilities if any user-supplied data is incorporated into these queries without proper sanitization. The taint analysis, while finding no critical or high severity flows, did identify one flow with an unsanitized path, which could potentially be exploited in conjunction with the raw SQL queries. The 73% output escaping rate, while good, still leaves room for improvement and a small risk of Cross-Site Scripting (XSS) vulnerabilities in the remaining unescaped outputs.
In conclusion, the plugin demonstrates good security hygiene in terms of access control and a clean vulnerability history. Nevertheless, the lack of prepared statements for all SQL queries represents a substantial and readily addressable security weakness that requires immediate attention. Addressing this and improving output escaping would significantly strengthen the plugin's overall security.
Key Concerns
- Raw SQL queries without prepared statements
- Flows with unsanitized paths found
- Output escaping not 100% effective
Tag Manager – Header, Body And Footer Security Vulnerabilities
Tag Manager – Header, Body And Footer Code Analysis
SQL Query Safety
Output Escaping
Data Flow Analysis
Tag Manager – Header, Body And Footer Attack Surface
AJAX Handlers 2
WordPress Hooks 13
Maintenance & Trust
Tag Manager – Header, Body And Footer Maintenance & Trust
Maintenance Signals
Community Trust
Tag Manager – Header, Body And Footer Alternatives
GTM4WP – A Google Tag Manager (GTM) plugin for WordPress
duracelltomi-google-tag-manager
Advanced tag management for WordPress with Google Tag Manager
PixelYourSite – Your smart PIXEL (TAG) & API Manager
pixelyoursite
Add Meta Pixel with Conversion API, Google Analytics (GA4) + Consent Mode, Google Tag Manager, and Head & Footer scripts.
Insert Headers And Footers
wp-headers-and-footers
Include inline javascript, stylesheets, CSS code or anything you want in Header and Footer areas of your WordPress with ease.
Pixel Manager for WooCommerce – Conversion Tracking, Google Ads, GA4, TikTok, Dynamic Remarketing
woocommerce-google-adwords-conversion-tracking-tag
Conversion tracking for WooCommerce. Google Ads, GA4, Meta/Facebook Pixel, TikTok & more. Recover 30% more conversions with server-side tracking!
Beehive Analytics – Google Analytics Dashboard
beehive-analytics
View visitor stats and track user behavior from within WordPress. A Google Analytics plugin with dashboard reports and Google Tag Manager support.
Tag Manager – Header, Body And Footer Developer Profile
11 plugins · 51K total installs
How We Detect Tag Manager – Header, Body And Footer
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/tag-manager-header-body-footer/include/admin-output.php/wp-content/plugins/tag-manager-header-body-footer/include/functions.php/wp-content/plugins/tag-manager-header-body-footer/include/install.php/wp-content/plugins/tag-manager-header-body-footer/include/script.php/wp-content/plugins/tag-manager-header-body-footer/include/settings.php/wp-content/plugins/tag-manager-header-body-footer/include/style.php/wp-content/plugins/tag-manager-header-body-footer/notices.phpHTML / DOM Fingerprints
<!-- adding admin notices -->