
WP Head Footer Security & Risk Analysis
wordpress.org/plugins/wp-head-footerWP Head Footer allows you to easily add custom code to the header and/or footer of any post, page, or custom post type on your WordPress site without …
Is WP Head Footer Safe to Use in 2026?
Generally Safe
Score 85/100WP Head Footer has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.
The "wp-head-footer" plugin v1.2 demonstrates a strong security posture based on the provided static analysis. The complete absence of identified entry points, dangerous functions, file operations, and external HTTP requests significantly reduces the plugin's attack surface. Furthermore, the code follows good practices by using prepared statements for all SQL queries and implementing nonce and capability checks, which are crucial for preventing common WordPress vulnerabilities.
While the static analysis reveals no critical or high severity taint flows, indicating that data sanitization and handling appear robust, there is a minor concern regarding output escaping. With 26% of the 57 identified outputs not properly escaped, there's a potential for Cross-Site Scripting (XSS) vulnerabilities if the unescaped data originates from user input or external sources without proper sanitization before reaching the output functions.
The plugin's vulnerability history is also a positive indicator, showing no recorded CVEs. This, combined with the clean static analysis, suggests a history of secure development and maintenance. However, the lack of past vulnerabilities doesn't entirely negate the risk associated with the identified output escaping issue. The overall security of the plugin is good, but the minor weakness in output escaping warrants attention.
Key Concerns
- Percentage of unescaped output is notable
WP Head Footer Security Vulnerabilities
WP Head Footer Code Analysis
Output Escaping
WP Head Footer Attack Surface
WordPress Hooks 11
Maintenance & Trust
WP Head Footer Maintenance & Trust
Maintenance Signals
Community Trust
WP Head Footer Alternatives
Enhanced Header / Footer Injections
enhanced-header-footer-injections
Add code to the header and footer sections of your site on a page-per-page basis.
WP Hooks
wp-hooks
WP Hooks allows you to add JavaScript, CSS, meta tags, etc. to your header and footer without modifying your theme.
WP Scripts Customizer
wp-scripts-customizer
WP Scripts Customizer allows to enter scripts you would like output to head and footer of your WordPress theme page via WordPress Theme customizer.
ElementsKit Elementor Addons – Advanced Widgets & Templates Addons for Elementor
elementskit-lite
Join millions who empower their websites with ElementsKit Elementor Addons. Get templates, & 100+ widgets like header-footer, mega menu, custom widget
Ultimate Addons for Elementor
header-footer-elementor
Powerful Elementor addon with advanced Elementor widgets, templates, WooCommerce widgets & Header-Footer builder to build professional websites fa …
WP Head Footer Developer Profile
4 plugins · 90 total installs
How We Detect WP Head Footer
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/wp-head-footer/css/style.css/wp-content/plugins/wp-head-footer/js/script.js/wp-content/plugins/wp-head-footer/js/script.jswp-head-footer/css/style.css?ver=wp-head-footer/js/script.js?ver=HTML / DOM Fingerprints
<!-- WP Head Footer [Site_Wide][Header][10] --><!-- / WP Head Footer [Site_Wide][Header][10] --><!-- WP Head Footer [Site_Wide][Footer][10] --><!-- / WP Head Footer [Site_Wide][Footer][10] -->+4 more