{"id":180656,"date":"2024-01-09T19:35:37","date_gmt":"2024-01-09T19:35:37","guid":{"rendered":"https:\/\/wordpress.org\/plugins\/simple-header-and-footer\/"},"modified":"2026-09-24T18:59:08","modified_gmt":"2026-09-24T18:59:08","slug":"simple-header-and-footer","status":"publish","type":"plugin","link":"https:\/\/bal.wordpress.org\/plugins\/simple-header-and-footer\/","author":21060336,"comment_status":"closed","ping_status":"closed","template":"","meta":{"version":"1.1.1","stable_tag":"1.1.1","tested":"7.1.2","requires":"5.8","requires_php":"7.4","requires_plugins":null,"header_name":"Simple Header and Footer","header_author":"Alberto Reineri","header_description":"Easily and basic plugin that allows you to insert code in the header (between head tags) and in the footer (before the end body tag). Ideal for inserting Analytics scripts or other tools easily and quickly.","assets_banners_color":"716d1c","last_updated":"2026-09-24 18:59:08","external_support_url":"","external_repository_url":"","donate_link":"","header_plugin_uri":"","header_author_uri":"https:\/\/albertoreineri.it","rating":5,"author_block_rating":0,"active_installs":50,"downloads":1447,"num_ratings":1,"support_threads":0,"support_threads_resolved":0,"author_block_count":0,"sections":["description","installation","faq","changelog"],"tags":{"1.0.0":{"tag":"1.0.0","author":"albertoreineri","date":"2024-02-11 22:01:17","revision":3034289},"1.1.0":{"tag":"1.1.0","author":"albertoreineri","date":"2026-09-24 09:22:07","revision":3710962},"1.1.1":{"tag":"1.1.1","author":"albertoreineri","date":"2026-09-24 18:59:08","revision":3711897}},"upgrade_notice":{"1.1.1":"<p>Important fix. If you updated to 1.1.0 and your header\/footer code is now printed on your pages as text, update and check the settings page: your script tags were removed and need to be added back.<\/p>","1.1.0":"<p>Security update. Adds CSRF protection and removes PHP execution. If you relied on PHP in your header\/footer code, it is saved on the settings page after updating.<\/p>"},"ratings":{"1":0,"2":0,"3":0,"4":0,"5":1},"assets_icons":{"icon-128x128.jpg":{"filename":"icon-128x128.jpg","revision":3019498,"resolution":"128x128","location":"assets","locale":"","width":128,"height":128},"icon-256x256.jpg":{"filename":"icon-256x256.jpg","revision":3019498,"resolution":"256x256","location":"assets","locale":"","width":256,"height":256},"icon.svg":{"filename":"icon.svg","revision":3019498,"resolution":false,"location":"assets","locale":false}},"assets_banners":{"banner-1544x500.jpg":{"filename":"banner-1544x500.jpg","revision":3019498,"resolution":"1544x500","location":"assets","locale":"","width":1544,"height":500},"banner-772x250.jpg":{"filename":"banner-772x250.jpg","revision":3019498,"resolution":"772x250","location":"assets","locale":"","width":772,"height":250}},"assets_blueprints":{},"all_blocks":[],"tagged_versions":["1.0.0","1.1.0","1.1.1"],"block_files":[],"assets_screenshots":{"screenshot-1.png":{"filename":"screenshot-1.png","revision":3032136,"resolution":"1","location":"assets","locale":"","width":1920,"height":926}},"screenshots":{"1":"Simple Header and Footer settings screen."}},"plugin_section":[],"plugin_tags":[232,7855,2640,1431,2864],"plugin_category":[35,36],"plugin_contributors":[223672],"plugin_business_model":[],"class_list":["post-180656","plugin","type-plugin","status-publish","hentry","plugin_tags-analytics","plugin_tags-facebook-pixel","plugin_tags-footer","plugin_tags-header","plugin_tags-scripts","plugin_category-advertising","plugin_category-analytics","plugin_contributors-albertoreineri","plugin_committers-albertoreineri"],"banners":{"banner":"https:\/\/ps.w.org\/simple-header-and-footer\/assets\/banner-772x250.jpg?rev=3019498","banner_2x":"https:\/\/ps.w.org\/simple-header-and-footer\/assets\/banner-1544x500.jpg?rev=3019498","banner_rtl":false,"banner_2x_rtl":false},"icons":{"svg":"https:\/\/ps.w.org\/simple-header-and-footer\/assets\/icon.svg?rev=3019498","icon":"https:\/\/ps.w.org\/simple-header-and-footer\/assets\/icon.svg?rev=3019498","icon_2x":false,"generated":false},"screenshots":[{"src":"https:\/\/ps.w.org\/simple-header-and-footer\/assets\/screenshot-1.png?rev=3032136","caption":"Simple Header and Footer settings screen."}],"raw_content":"<!--section=description-->\n<p>Simple Header and Footer lets you add Google Analytics, Facebook Pixel, custom tracking code, verification meta tags and more, with a single straightforward settings page. No need to install a complex plugin with thousands of unnecessary features, and no need to edit your theme files.<\/p>\n\n<ul>\n<li><strong>Header:<\/strong> printed inside the <code>&lt;head&gt;<\/code> tag.<\/li>\n<li><strong>Footer:<\/strong> printed just before the <code>&lt;\/body&gt;<\/code> tag.<\/li>\n<li><strong>Code editor<\/strong> with syntax highlighting.<\/li>\n<li>Your code stays in place when you change or update your theme.<\/li>\n<\/ul>\n\n<h4>A note on security<\/h4>\n\n<p>This plugin outputs the HTML and JavaScript you write, exactly as written, on every page of your site. That is what makes it useful for tracking scripts, and it also means the settings page should be treated like access to your theme files. Only users with the <code>unfiltered_html<\/code> capability (Administrators on a standard install; Super Admins on Multisite) can save raw scripts. Everyone else has their code filtered the same way WordPress filters the Custom HTML block.<\/p>\n\n<p>This plugin does not run PHP code.<\/p>\n\n<h4>Privacy and GDPR<\/h4>\n\n<p>This plugin does not collect or process any personal user data. The scripts you add may do so: check the privacy requirements of the services you connect.<\/p>\n\n<h4>Translation<\/h4>\n\n<p>You can contribute to translate this plugin in your language on <a href=\"https:\/\/translate.wordpress.org\">WordPress Translate<\/a>.<\/p>\n\n<!--section=installation-->\n<ol>\n<li>Upload the <code>simple-header-and-footer<\/code> folder to the <code>\/wp-content\/plugins\/<\/code> directory.<\/li>\n<li>Activate the plugin through the 'Plugins' menu in WordPress.<\/li>\n<li>Go to <strong>Settings &gt; Simple Header &amp; Footer<\/strong>, paste your code and save.<\/li>\n<\/ol>\n\n<!--section=faq-->\n<dl>\n<dt id=\"can%20i%20run%20php%20code%20with%20this%20plugin%3F\"><h3>Can I run PHP code with this plugin?<\/h3><\/dt>\n<dd><p>No. Earlier versions could execute PHP stored in the header\/footer fields; that feature was removed in 1.1.0 for security. If you were using it, your previous code was saved for you on the plugin's settings page.<\/p><\/dd>\n<dt id=\"my%20tracking%20code%20is%20printed%20on%20the%20page%20as%20text.%20what%20happened%3F\"><h3>My tracking code is printed on the page as text. What happened?<\/h3><\/dt>\n<dd><p>Version 1.1.0 could remove the <code>&lt;script&gt;<\/code> tags from saved code while updating. This was fixed in 1.1.1, but the tags that were already removed can't be recovered automatically: open Settings &gt; Simple Header &amp; Footer, wrap your code in <code>&lt;script&gt;<\/code> and <code>&lt;\/script&gt;<\/code> tags (and re-add any script tag that loads an external file, like the Google tag loader) and save.<\/p><\/dd>\n<dt id=\"why%20were%20my%20scripts%20removed%20when%20i%20saved%3F\"><h3>Why were my scripts removed when I saved?<\/h3><\/dt>\n<dd><p>Your account does not have the <code>unfiltered_html<\/code> capability, which WordPress requires to save raw scripts (this is the default on Multisite sub-sites). Ask a Super Admin, or save the code from an account that has it.<\/p><\/dd>\n<dt id=\"where%20exactly%20is%20the%20code%20printed%3F\"><h3>Where exactly is the code printed?<\/h3><\/dt>\n<dd><p>Header code is printed with the <code>wp_head<\/code> hook (late, priority 11). Footer code is printed with the <code>wp_footer<\/code> hook. Your theme needs to call both, as any well-built theme does.<\/p><\/dd>\n\n<\/dl>\n\n<!--section=changelog-->\n<h4>1.1.1<\/h4>\n\n<ul>\n<li>Fixed: version 1.1.0 could remove the <code>&lt;script&gt;<\/code> tags from your saved code while updating, so the code was printed on the page as plain text. The update no longer rewrites your saved code, and background requests can no longer alter it.<\/li>\n<li>If your header or footer code shows up as text on your site, the settings page now tells you: wrap it in <code>&lt;script&gt;<\/code> tags again and save.<\/li>\n<li>Updates that don't come from a logged-in user (WP-CLI, imports) no longer go through the script filter.<\/li>\n<\/ul>\n\n<h4>1.1.0<\/h4>\n\n<ul>\n<li>Security: the settings can no longer be saved without a valid security token (CSRF protection).<\/li>\n<li>Security: removed the ability to execute PHP code from the header\/footer fields. Existing code that contained PHP is preserved on the settings page so nothing is lost.<\/li>\n<li>Security: raw script saving is restricted to users with the <code>unfiltered_html<\/code> capability.<\/li>\n<li>The settings page now uses the WordPress Settings API and only accepts the two fields it displays.<\/li>\n<li>Removed unused code and the cache-busting timestamp on the admin stylesheet.<\/li>\n<li>Added a gentle, dismissible review request on the settings page (shown after a week).<\/li>\n<li>Tested with WordPress 7.1.<\/li>\n<\/ul>\n\n<h4>1.0.0<\/h4>\n\n<ul>\n<li>Initial release.<\/li>\n<\/ul>","raw_excerpt":"Insert code in your site&#039;s header and footer. Ideal for Google Analytics, Facebook Pixel and other tracking scripts.","jetpack_sharing_enabled":true,"_links":{"self":[{"href":"https:\/\/bal.wordpress.org\/plugins\/wp-json\/wp\/v2\/plugin\/180656","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/bal.wordpress.org\/plugins\/wp-json\/wp\/v2\/plugin"}],"about":[{"href":"https:\/\/bal.wordpress.org\/plugins\/wp-json\/wp\/v2\/types\/plugin"}],"replies":[{"embeddable":true,"href":"https:\/\/bal.wordpress.org\/plugins\/wp-json\/wp\/v2\/comments?post=180656"}],"author":[{"embeddable":true,"href":"https:\/\/bal.wordpress.org\/plugins\/wp-json\/wporg\/v1\/users\/albertoreineri"}],"wp:attachment":[{"href":"https:\/\/bal.wordpress.org\/plugins\/wp-json\/wp\/v2\/media?parent=180656"}],"wp:term":[{"taxonomy":"plugin_section","embeddable":true,"href":"https:\/\/bal.wordpress.org\/plugins\/wp-json\/wp\/v2\/plugin_section?post=180656"},{"taxonomy":"plugin_tags","embeddable":true,"href":"https:\/\/bal.wordpress.org\/plugins\/wp-json\/wp\/v2\/plugin_tags?post=180656"},{"taxonomy":"plugin_category","embeddable":true,"href":"https:\/\/bal.wordpress.org\/plugins\/wp-json\/wp\/v2\/plugin_category?post=180656"},{"taxonomy":"plugin_contributors","embeddable":true,"href":"https:\/\/bal.wordpress.org\/plugins\/wp-json\/wp\/v2\/plugin_contributors?post=180656"},{"taxonomy":"plugin_business_model","embeddable":true,"href":"https:\/\/bal.wordpress.org\/plugins\/wp-json\/wp\/v2\/plugin_business_model?post=180656"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}