
Breadcrumb NavXT Security & Risk Analysis
wordpress.org/plugins/breadcrumb-navxtAdds breadcrumb navigation showing the visitor's path to their current location.
Is Breadcrumb NavXT Safe to Use in 2026?
Generally Safe
Score 98/100Breadcrumb NavXT has a strong security track record. Known vulnerabilities have been patched promptly.
The breadcrumb-navxt plugin v7.5.1 exhibits a generally good security posture, with robust practices like 100% prepared SQL statements and nearly all output being properly escaped. The plugin also demonstrates a solid implementation of nonces and capability checks, which are crucial for WordPress security. However, a significant concern arises from the presence of one AJAX handler that lacks any authentication checks. This creates a direct attack vector that could be exploited by unauthenticated users to potentially trigger unintended actions within the plugin.
The vulnerability history reveals two past medium-severity CVEs, one of which was recently patched in 2026. The types of vulnerabilities (Authorization Bypass and Exposure of Sensitive Information) are notable and suggest that attackers have successfully found ways to circumvent authorization or access restricted data in previous versions. While there are no currently unpatched vulnerabilities, this history indicates a potential for such issues to reappear if not carefully managed.
In conclusion, while the plugin excels in many secure coding practices, the single unprotected AJAX endpoint represents a critical weakness that must be addressed immediately. The past CVEs, although patched, warrant continued vigilance to ensure that similar authorization and information exposure issues do not re-emerge in future development. The plugin's strengths lie in its SQL and output handling, but the identified entry point and historical patterns necessitate a cautious approach.
Key Concerns
- Unprotected AJAX handler
- Medium severity vulnerabilities in history (x2)
Breadcrumb NavXT Security Vulnerabilities
CVEs by Year
Severity Breakdown
2 total CVEs
Breadcrumb NavXT <= 7.5.0 - Missing Authorization to Sensitive Information Exposure
Breadcrumb NavXT <= 6.1.0 - Sensitive Data Exposure
Breadcrumb NavXT Code Analysis
SQL Query Safety
Output Escaping
Breadcrumb NavXT Attack Surface
AJAX Handlers 1
WordPress Hooks 24
Maintenance & Trust
Breadcrumb NavXT Maintenance & Trust
Maintenance Signals
Community Trust
Breadcrumb NavXT Alternatives
X3P0: Breadcrumbs
x3p0-breadcrumbs
Add breadcrumb navigation to any site. Works with block and classic themes. Auto-detects site structure and custom post types. Improves SEO.
Catch Breadcrumb
catch-breadcrumb
Catch Breadcrumb lets you display Breadcrumb Navigation anywhere on your website elegantly.
SEO Breadcrumbs
seo-breadcrumbs
SEO Breadcrumbs is powerful and easy to use plugin that can add five different breadcrumbs navigation to your wordpress website.
Breadcrumb NavXT Multidimension Extensions
breadcrumb-navxt-multidimension-extensions
Automates the generation of multidimensional list breadcrumb trails with Breadcrumb NavXT.
WP Breadcrumb
breadcrumbs-builder
Breadcrumb Builder will allow you to add Breadcrumbs navigation section to your site and your visitors will know current path.
Breadcrumb NavXT Developer Profile
3 plugins · 800K total installs
How We Detect Breadcrumb NavXT
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/breadcrumb-navxt/css/bcn_editor_styles.css/wp-content/plugins/breadcrumb-navxt/css/bcn_styles.css/wp-content/plugins/breadcrumb-navxt/includes/blocks/build/style.css/wp-content/plugins/breadcrumb-navxt/includes/blocks/build/editor.css/wp-content/plugins/breadcrumb-navxt/js/bcn_admin.js/wp-content/plugins/breadcrumb-navxt/js/bcn_frontend.js/wp-content/plugins/breadcrumb-navxt/includes/blocks/build/index.jsbreadcrumb-navxt/css/bcn_editor_styles.css?ver=breadcrumb-navxt/css/bcn_styles.css?ver=breadcrumb-navxt/js/bcn_admin.js?ver=breadcrumb-navxt/js/bcn_frontend.js?ver=breadcrumb-navxt/includes/blocks/build/style.css?ver=breadcrumb-navxt/includes/blocks/build/editor.css?ver=breadcrumb-navxt/includes/blocks/build/index.js?ver=HTML / DOM Fingerprints
bcn_breadcrumbsdata-bcn-rest-noncedata-bcn-rest-urlbcn_globals/wp-json/breadcrumb-navxt/v1/trail