
Insert Code by Angie Makes Security & Risk Analysis
wordpress.org/plugins/wpc-insert-codeEasily insert HTML, Javascript, CSS, into the head and footer areas of your site.
Is Insert Code by Angie Makes Safe to Use in 2026?
Generally Safe
Score 85/100Insert Code by Angie Makes has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.
The static analysis of 'wpc-insert-code' v1.2 reveals a plugin with a very limited attack surface. There are no detected AJAX handlers, REST API routes, shortcodes, or cron events, meaning there are no direct entry points for external interaction. Furthermore, the absence of dangerous functions, file operations, external HTTP requests, and SQL queries executed without prepared statements are strong indicators of good security practices in these critical areas. The plugin also reports no known vulnerabilities in its history, suggesting a history of responsible development.
However, a significant concern lies in the output escaping. With 40 total outputs and only 45% properly escaped, there is a substantial risk of cross-site scripting (XSS) vulnerabilities. This means that user-supplied input could potentially be rendered directly into the output without proper sanitization, allowing attackers to inject malicious scripts. The lack of nonce checks and capability checks, coupled with zero critical or high severity taint flows, suggests that while direct code execution or SQL injection might be mitigated by other factors, the possibility of XSS remains a notable weakness.
In conclusion, 'wpc-insert-code' v1.2 demonstrates a robust defense against many common web application vulnerabilities by minimizing its attack surface and employing prepared statements. The primary weakness is the insufficient output escaping, which presents a clear XSS risk. While its vulnerability history is clean, this does not negate the current findings of potential security flaws. The plugin's strengths are its limited interaction points and database query safety, but its weakness in output sanitization requires attention.
Key Concerns
- Low output escaping rate
- Missing nonce checks
- Missing capability checks
Insert Code by Angie Makes Security Vulnerabilities
Insert Code by Angie Makes Code Analysis
Output Escaping
Insert Code by Angie Makes Attack Surface
WordPress Hooks 15
Maintenance & Trust
Insert Code by Angie Makes Maintenance & Trust
Maintenance Signals
Community Trust
Insert Code by Angie Makes Alternatives
CM Header and Footer – Add custom scripts and styles to your header and footer with ease
cm-header-footer-script-loader
Add custom CSS and JavaScript to headers and footers on your site with the header and footer plugin for enhanced control and design.
Insert Html Snippet
insert-html-snippet
Add HTML, CSS and javascript code to your pages and posts easily using shortcodes.
Insert Adsense Auto Ads
insert-adsense-auto-ads
Easily add your Adsense Auto Ads (or any other javascript code) to the WordPress header section.
mhcode-wp-bootstrap-nav
mhcode-wp-bootstrap-nav
Make bootstrap tags navigation menu in wordpress easyly, here included all tag related navigation menu
Wpfox Infobox rotator
wpfox-infobox-rotator
By using Wpfox infobox rotator, it allows you to add simple info box in wooocommerce Single product page under add to cart , no need to edit theme and …
Insert Code by Angie Makes Developer Profile
5 plugins · 3K total installs
How We Detect Insert Code by Angie Makes
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/wpc-insert-code/assets/css/admin.css/wp-content/plugins/wpc-insert-code/assets/js/admin.jswpc-insert-code/assets/css/admin.css?ver=wpc-insert-code/assets/js/admin.js?ver=