
BreadcrumbsPress Security & Risk Analysis
wordpress.org/plugins/breadcrumbspressBreadcrumbs based navigation, fully responsive and customizable, supporting post types, all types of archives, 404 pages, search results, and more.
Is BreadcrumbsPress Safe to Use in 2026?
Generally Safe
Score 100/100BreadcrumbsPress has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.
Based on the provided static analysis and vulnerability history, BreadcrumbsPress v4.6 exhibits a generally strong security posture. The absence of identified vulnerabilities in its history, coupled with a clean static analysis with no critical or high severity taint flows, suggests a well-maintained and secure plugin. The plugin also demonstrates good practices by having no direct SQL queries without prepared statements and a high percentage of properly escaped output.
However, there are areas for improvement that slightly temper the overall positive assessment. The complete lack of any capability checks, nonce checks, and unprotected entry points is unusual. While the current analysis shows no issues, this can be a future risk if new entry points are added or existing code is modified without adequate security measures. The bundled Freemius library also presents a potential, albeit low, risk if it's an older version or has known vulnerabilities not yet addressed.
In conclusion, BreadcrumbsPress v4.6 appears to be a secure plugin based on the current data, with no known exploitable vulnerabilities. The primary concern lies in the potential for future security gaps due to the lack of fundamental security checks like capability and nonce verification across all entry points. The bundled Freemius library should also be monitored for potential updates and vulnerabilities.
Key Concerns
- No capability checks found
- No nonce checks found
- Bundled Freemius v1.0 library
- 74% output escaping, some potential for XSS
BreadcrumbsPress Security Vulnerabilities
BreadcrumbsPress Release Timeline
BreadcrumbsPress Code Analysis
Bundled Libraries
Output Escaping
BreadcrumbsPress Attack Surface
WordPress Hooks 23
Maintenance & Trust
BreadcrumbsPress Maintenance & Trust
Maintenance Signals
Community Trust
BreadcrumbsPress Alternatives
Breadcrumb NavXT
breadcrumb-navxt
Adds breadcrumb navigation showing the visitor's path to their current location.
Flexy Breadcrumb
flexy-breadcrumb
Flexy Breadcrumb is a super light weight plugin that is easy to navigate through current page hierarchy.
Breadcrumb Trail
breadcrumb-trail
A powerful script for adding breadcrumbs to your site that supports Schema.org HTML5-valid microdata.
Catch Breadcrumb
catch-breadcrumb
Catch Breadcrumb lets you display Breadcrumb Navigation anywhere on your website elegantly.
RDFa Breadcrumb
rdfa-breadcrumb
An easy template tag for showing a breadcrumb menu on your site and on google search results with built in RDFa Markup.
BreadcrumbsPress Developer Profile
17 plugins · 12K total installs
How We Detect BreadcrumbsPress
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/breadcrumbspress/core/assets/css/breadcrumbspress.css/wp-content/plugins/breadcrumbspress/core/assets/css/breadcrumbspress-rtl.css/wp-content/plugins/breadcrumbspress/core/assets/js/breadcrumbspress.js/wp-content/plugins/breadcrumbspress/core/assets/js/breadcrumbspress.jsbreadcrumbspress/core/assets/css/breadcrumbspress.css?ver=breadcrumbspress/core/assets/css/breadcrumbspress-rtl.css?ver=breadcrumbspress/core/assets/js/breadcrumbspress.js?ver=HTML / DOM Fingerprints
breadcrumbspress-containerdata-breadcrumbspress-idbreadcrumbspress_settings[breadcrumbspress]