
Breadcrumb Block Security & Risk Analysis
wordpress.org/plugins/breadcrumb-blockA simple breadcrumb trail block that supports JSON-LD structured data and is compatible with Woocommerce
Is Breadcrumb Block Safe to Use in 2026?
Generally Safe
Score 100/100Breadcrumb Block has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.
The "breadcrumb-block" plugin version 1.1.0 demonstrates a strong security posture based on the provided static analysis. There are no identified entry points with unprotected access, no dangerous functions being used, and all SQL queries are properly prepared. The plugin also shows good practice in output escaping, with 85% of outputs being properly escaped, and it avoids common risky operations like file manipulation and external HTTP requests. The absence of any historical vulnerabilities further reinforces its apparent security.
Despite the overall positive findings, the complete lack of nonce checks and capability checks across all identified (albeit zero) entry points is a notable concern. While the attack surface is currently reported as zero, any future additions to these entry points without these fundamental security mechanisms in place would introduce significant risk. The taint analysis showing zero flows is reassuring, but it's important to remember that static analysis has limitations and may not catch all potential issues.
In conclusion, the plugin is currently in a good state of security with no readily apparent vulnerabilities. The developers appear to be following secure coding practices. However, the lack of explicit nonce and capability checks, even with a zero attack surface, represents a potential future weakness if the plugin evolves. The historical absence of vulnerabilities is a positive indicator, but vigilance should remain a priority.
Key Concerns
- No nonce checks implemented
- No capability checks implemented
- 15% of output not properly escaped
Breadcrumb Block Security Vulnerabilities
Breadcrumb Block Code Analysis
Output Escaping
Breadcrumb Block Attack Surface
WordPress Hooks 3
Maintenance & Trust
Breadcrumb Block Maintenance & Trust
Maintenance Signals
Community Trust
Breadcrumb Block Alternatives
Classic Menu Sync for Block
classic-menu-sync-for-block
Automatically synchronizes Navigation blocks with classic WordPress menus using the native import system.
Enable Navigation Icons
enable-navigation-icons
Easily add icons to Navigation Block items in WordPress.
Taxonomy Submenu
taxonomy-submenu
A Gutenberg block that creates dynamic submenu items from any taxonomy and offers complete styling control beyond the default WordPress submenu block.
Breadcrumb NavXT
breadcrumb-navxt
Adds breadcrumb navigation showing the visitor's path to their current location.
GutenKit – Page Builder Blocks, Patterns, and Templates for Gutenberg Block Editor
gutenkit-blocks-addon
GutenKit – Ultimate no-code Gutenberg blocks to design stunning web pages and visually stunning posts in WordPress block editor.
Breadcrumb Block Developer Profile
8 plugins · 27K total installs
How We Detect Breadcrumb Block
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/breadcrumb-block/build/index.js/wp-content/plugins/breadcrumb-block/build/index.css/wp-content/plugins/breadcrumb-block/build/index.jsbreadcrumb-block/build/index.css?ver=breadcrumb-block/build/index.js?ver=HTML / DOM Fingerprints
hide-home-pagehide-current-pagedata-bb-crumb-gap<nav aria-label="Breadcrumbs"><ol><li><a href="">