
Breadcrumb – Breadcrumb for WooCommerce and Custom Post Types Security & Risk Analysis
wordpress.org/plugins/breadcrumbSuper light weight & easy breadcrumb navigation for wordpress site.
Is Breadcrumb – Breadcrumb for WooCommerce and Custom Post Types Safe to Use in 2026?
Generally Safe
Score 100/100Breadcrumb – Breadcrumb for WooCommerce and Custom Post Types has a strong security track record. Known vulnerabilities have been patched promptly. It's a solid choice for most WordPress installations.
The 'breadcrumb' plugin v1.5.54 exhibits a generally strong security posture based on the provided static analysis. The absence of dangerous functions, file operations, and external HTTP requests, coupled with the extensive use of prepared statements for SQL queries and a high percentage of properly escaped output, are commendable practices. The presence of a nonce check and a single capability check also suggests some level of security awareness in its development. However, the taint analysis reveals a concerning finding: two flows with unsanitized paths, even though they are not currently classified as critical or high severity. This indicates a potential for vulnerabilities if these paths are exploited or if the sanitization logic is insufficient for certain inputs. Furthermore, the plugin has a history of one known CVE, specifically Cross-Site Scripting, with the last vulnerability being in early 2023. While there are currently no unpatched vulnerabilities, this history suggests that the plugin has been susceptible to certain attack vectors in the past, warranting continued vigilance. Overall, the plugin is well-implemented in many areas, but the unsanitized paths and past XSS vulnerability are points that require attention and potential mitigation.
Key Concerns
- Flows with unsanitized paths identified
- Past XSS vulnerability history
Breadcrumb – Breadcrumb for WooCommerce and Custom Post Types Security Vulnerabilities
CVEs by Year
Severity Breakdown
1 total CVE
Breadcrumb <= 1.5.32 - Authenticated (Contributor+) Stored Cross-Site Scripting
Breadcrumb – Breadcrumb for WooCommerce and Custom Post Types Release Timeline
Breadcrumb – Breadcrumb for WooCommerce and Custom Post Types Code Analysis
Output Escaping
Data Flow Analysis
Breadcrumb – Breadcrumb for WooCommerce and Custom Post Types Attack Surface
Shortcodes 2
WordPress Hooks 80
Maintenance & Trust
Breadcrumb – Breadcrumb for WooCommerce and Custom Post Types Maintenance & Trust
Maintenance Signals
Community Trust
Breadcrumb – Breadcrumb for WooCommerce and Custom Post Types Alternatives
Breadcrumb NavXT Multidimension Extensions
breadcrumb-navxt-multidimension-extensions
Automates the generation of multidimensional list breadcrumb trails with Breadcrumb NavXT.
Breadcrumb NavXT
breadcrumb-navxt
Adds breadcrumb navigation showing the visitor's path to their current location.
Catch Breadcrumb
catch-breadcrumb
Catch Breadcrumb lets you display Breadcrumb Navigation anywhere on your website elegantly.
Breadcrumb TMC
breadcrumb-tmc
Use [breadcrumb-tmc] shortcode to display the breadcrumb trail.
SEO Breadcrumbs
seo-breadcrumbs
SEO Breadcrumbs is powerful and easy to use plugin that can add five different breadcrumbs navigation to your wordpress website.
Breadcrumb – Breadcrumb for WooCommerce and Custom Post Types Developer Profile
14 plugins · 94K total installs
How We Detect Breadcrumb – Breadcrumb for WooCommerce and Custom Post Types
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/breadcrumb/assets/admin/css/fontawesome.css/wp-content/plugins/breadcrumb/assets/settings-tabs/settings-tabs.css/wp-content/plugins/breadcrumb/assets/settings-tabs/settings-tabs.js/wp-content/plugins/breadcrumb/assets/admin/js/jquery.lazy.js/wp-content/plugins/breadcrumb/assets/admin/css/fontawesome.css/wp-content/plugins/breadcrumb/assets/settings-tabs/settings-tabs.css/wp-content/plugins/breadcrumb/assets/settings-tabs/settings-tabs.js/wp-content/plugins/breadcrumb/assets/admin/js/jquery.lazy.jsbreadcrumb/assets/admin/css/fontawesome.css?ver=breadcrumb/assets/settings-tabs/settings-tabs.css?ver=breadcrumb/assets/settings-tabs/settings-tabs.js?ver=breadcrumb/assets/admin/js/jquery.lazy.js?ver=HTML / DOM Fingerprints
data-dependssettings_tabs_field