Description
Simple Header and Footer lets you add Google Analytics, Facebook Pixel, custom tracking code, verification meta tags and more, with a single straightforward settings page. No need to install a complex plugin with thousands of unnecessary features, and no need to edit your theme files.
- Header: printed inside the
<head>tag. - Footer: printed just before the
</body>tag. - Code editor with syntax highlighting.
- Your code stays in place when you change or update your theme.
A note on security
This plugin outputs the HTML and JavaScript you write, exactly as written, on every page of your site. That is what makes it useful for tracking scripts, and it also means the settings page should be treated like access to your theme files. Only users with the unfiltered_html capability (Administrators on a standard install; Super Admins on Multisite) can save raw scripts. Everyone else has their code filtered the same way WordPress filters the Custom HTML block.
This plugin does not run PHP code.
Privacy and GDPR
This plugin does not collect or process any personal user data. The scripts you add may do so: check the privacy requirements of the services you connect.
Translation
You can contribute to translate this plugin in your language on WordPress Translate.
Installation
- Upload the
simple-header-and-footerfolder to the/wp-content/plugins/directory. - Activate the plugin through the ‘Plugins’ menu in WordPress.
- Go to Settings > Simple Header & Footer, paste your code and save.
FAQ
-
Can I run PHP code with this plugin?
-
No. Earlier versions could execute PHP stored in the header/footer fields; that feature was removed in 1.1.0 for security. If you were using it, your previous code was saved for you on the plugin’s settings page.
-
My tracking code is printed on the page as text. What happened?
-
Version 1.1.0 could remove the
<script>tags from saved code while updating. This was fixed in 1.1.1, but the tags that were already removed can’t be recovered automatically: open Settings > Simple Header & Footer, wrap your code in<script>and</script>tags (and re-add any script tag that loads an external file, like the Google tag loader) and save. -
Why were my scripts removed when I saved?
-
Your account does not have the
unfiltered_htmlcapability, which WordPress requires to save raw scripts (this is the default on Multisite sub-sites). Ask a Super Admin, or save the code from an account that has it. -
Where exactly is the code printed?
-
Header code is printed with the
wp_headhook (late, priority 11). Footer code is printed with thewp_footerhook. Your theme needs to call both, as any well-built theme does.
Contributors & Developers
“Simple Header and Footer” is open source software. The following people have contributed to this plugin.
ContributorsTranslate “Simple Header and Footer” into your language.
Interested in development?
Browse the code, check out the SVN repository, or subscribe to the development log by RSS.
Changelog
1.1.1
- Fixed: version 1.1.0 could remove the
<script>tags from your saved code while updating, so the code was printed on the page as plain text. The update no longer rewrites your saved code, and background requests can no longer alter it. - If your header or footer code shows up as text on your site, the settings page now tells you: wrap it in
<script>tags again and save. - Updates that don’t come from a logged-in user (WP-CLI, imports) no longer go through the script filter.
1.1.0
- Security: the settings can no longer be saved without a valid security token (CSRF protection).
- Security: removed the ability to execute PHP code from the header/footer fields. Existing code that contained PHP is preserved on the settings page so nothing is lost.
- Security: raw script saving is restricted to users with the
unfiltered_htmlcapability. - The settings page now uses the WordPress Settings API and only accepts the two fields it displays.
- Removed unused code and the cache-busting timestamp on the admin stylesheet.
- Added a gentle, dismissible review request on the settings page (shown after a week).
- Tested with WordPress 7.1.
1.0.0
- Initial release.

