
Breadcrumbs Shortcode Security & Risk Analysis
wordpress.org/plugins/breadcrumbs-shortcode[ โ ๐๐๐๐๐๐ ๐๐๐๐๐๐๐ b๐ ๐ซ๐๐๐๐ ] Show breadcrumbs for posts, pages and categories
Is Breadcrumbs Shortcode Safe to Use in 2026?
Generally Safe
Score 92/100Breadcrumbs Shortcode has a strong security track record. Known vulnerabilities have been patched promptly.
The "breadcrumbs-shortcode" plugin v1.48 exhibits a mixed security posture. While it boasts a zero attack surface, zero shortcodes, and a notable percentage of SQL queries using prepared statements, there are significant areas of concern. The presence of the `unserialize` function is a critical red flag, as it can lead to Remote Code Execution if user-controlled data is unserialized without proper validation. This is further exacerbated by taint analysis revealing flows with unsanitized paths, including one of high severity. The plugin's history shows one medium severity Cross-Site Scripting (XSS) vulnerability discovered in August 2022, indicating a past struggle with output sanitization. Although there are no currently unpatched CVEs, the past XSS vulnerability and the current code signals, particularly the `unserialize` function and unsanitized taint flows, suggest a non-negligible risk. The plugin demonstrates some good practices like capability checks and nonces, but these are undermined by the potential for deserialization vulnerabilities and inadequate input sanitization in critical flows.
Key Concerns
- Presence of unserialize function
- High severity taint flow found
- Flows with unsanitized paths found
- Past medium severity XSS vulnerability
- Only 52% of output properly escaped
Breadcrumbs Shortcode Security Vulnerabilities
CVEs by Year
Severity Breakdown
1 total CVE
Breadcrumbs Shortcode <= 1.44 - Reflected Cross-Site Scripting
Breadcrumbs Shortcode Code Analysis
Dangerous Functions Found
SQL Query Safety
Output Escaping
Data Flow Analysis
Breadcrumbs Shortcode Attack Surface
WordPress Hooks 34
Maintenance & Trust
Breadcrumbs Shortcode Maintenance & Trust
Maintenance Signals
Community Trust
Breadcrumbs Shortcode Alternatives
Category Posts Shortcode
category-posts-shortcode
A simple plugin that adds a shortcode to display posts from a specified category.
Posts by Category
posts-by-category
Display a list of posts from a specific category or tag.
KS Elementor Shortcode Slider
ks-elementor-shortcode-slider
KS Elementor Shortcode Slider is a plugin for creating custom sliders in Elementor using shortcodes or posts, with category selection.
Display Category Posts Via Shortcode Lite
display-category-posts-via-shortcode-lite
Displays posts with their featured images from a specified category in a responsive grid using a simple shortcode. After installation simply go to Se …
MD Taxonomy Totals
md-taxonomy-totals
Display total published posts count using the [mdtt_total_posts] shortcode, with optional filtering by category or tag.
Breadcrumbs Shortcode Developer Profile
16 plugins ยท 51K total installs
How We Detect Breadcrumbs Shortcode
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/breadcrumbs-shortcode/assets/breadcrumbs.cssbreadcrumbs-shortcode/assets/breadcrumbs.css?ver=HTML / DOM Fingerprints
delimiterdelimiter1data-shortcodedata-shortcode-id[breadcrumbs<span class="delimiter"><span class="delimiter1">