
ZD Header Tags Security & Risk Analysis
wordpress.org/plugins/zd-header-tagsPut tags in between
Is ZD Header Tags Safe to Use in 2026?
Generally Safe
Score 85/100ZD Header Tags has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.
The "zd-header-tags" v2.1 plugin exhibits a strong security posture from an attack surface perspective, with zero identified entry points that are unprotected. The absence of AJAX handlers, REST API routes, shortcodes, and cron events without proper authorization checks is a significant positive. Furthermore, the plugin's code shows good practices in handling SQL queries exclusively through prepared statements and includes nonce and capability checks, indicating an awareness of basic WordPress security principles. However, a critical weakness is revealed in the output escaping. With 100% of outputs being unescaped, this presents a significant risk for cross-site scripting (XSS) vulnerabilities. The vulnerability history is clean, with no recorded CVEs, which, combined with the lack of taint analysis findings, suggests a current lack of known exploitable issues in this version. Despite the clean history and robust handling of SQL, the pervasive lack of output escaping represents a major blind spot and a clear and present danger for potential XSS attacks. The strength lies in its minimal attack surface and responsible SQL handling, but the weakness in output sanitization is a serious concern that overshadows these positives.
Key Concerns
- All outputs are unescaped
ZD Header Tags Security Vulnerabilities
ZD Header Tags Code Analysis
Output Escaping
ZD Header Tags Attack Surface
WordPress Hooks 5
Maintenance & Trust
ZD Header Tags Maintenance & Trust
Maintenance Signals
Community Trust
ZD Header Tags Alternatives
Add IDs to Header Tags
add-ids-to-header-tags
Useful for folks that write long-form content containing subheaders, this will add an ID tag to any header tag in your content for deep linking.
Vanilla Bean – Meta Maid
vanilla-bean-meta-maid
Meta Maid is the simplest of plugins, allowing you to add meta tags, script tags and tracking code to
Simple SEO Meta
simple-seo-metadata
Edit meta description, meta keywords and title for each page, post, post type.
WPCode – Insert Headers and Footers + Custom Code Snippets – WordPress Code Manager
insert-headers-and-footers
Easily add code snippets in WordPress. Insert header & footer scripts, add PHP code snippets with conditional logic, insert ads pixel code, and more.
ElementsKit Elementor Addons – Advanced Widgets & Templates Addons for Elementor
elementskit-lite
Join millions who empower their websites with ElementsKit Elementor Addons. Get templates, & 100+ widgets like header-footer, mega menu, custom widget
ZD Header Tags Developer Profile
2 plugins · 80 total installs
How We Detect ZD Header Tags
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/zd-header-tags/zdstyle.css/wp-content/plugins/zd-header-tags/js/header.jszd-header-tags/js/header.js?ver=zd-header-tags/zdstyle.css?ver=HTML / DOM Fingerprints
zdheadertag_noncename