BreadcrumbsPress Security & Risk Analysis

wordpress.org/plugins/breadcrumbspress

Breadcrumbs based navigation, fully responsive and customizable, supporting post types, all types of archives, 404 pages, search results, and more.

80 active installs v4.6 PHP 7.4+ WP 6.1+ Updated Nov 12, 2025
breadcrumbbreadcrumbscrumbdev4pressnavigation
100
A · Safe
CVEs total0
Unpatched0
Last CVENever
Safety Verdict

Is BreadcrumbsPress Safe to Use in 2026?

Generally Safe

Score 100/100

BreadcrumbsPress has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.

No known CVEs Updated 6mo ago
Risk Assessment

Based on the provided static analysis and vulnerability history, BreadcrumbsPress v4.6 exhibits a generally strong security posture. The absence of identified vulnerabilities in its history, coupled with a clean static analysis with no critical or high severity taint flows, suggests a well-maintained and secure plugin. The plugin also demonstrates good practices by having no direct SQL queries without prepared statements and a high percentage of properly escaped output.

However, there are areas for improvement that slightly temper the overall positive assessment. The complete lack of any capability checks, nonce checks, and unprotected entry points is unusual. While the current analysis shows no issues, this can be a future risk if new entry points are added or existing code is modified without adequate security measures. The bundled Freemius library also presents a potential, albeit low, risk if it's an older version or has known vulnerabilities not yet addressed.

In conclusion, BreadcrumbsPress v4.6 appears to be a secure plugin based on the current data, with no known exploitable vulnerabilities. The primary concern lies in the potential for future security gaps due to the lack of fundamental security checks like capability and nonce verification across all entry points. The bundled Freemius library should also be monitored for potential updates and vulnerabilities.

Key Concerns

  • No capability checks found
  • No nonce checks found
  • Bundled Freemius v1.0 library
  • 74% output escaping, some potential for XSS
Vulnerabilities
None known

BreadcrumbsPress Security Vulnerabilities

No known vulnerabilities — this is a good sign.
Version History

BreadcrumbsPress Release Timeline

v4.6Current
v4.5
v2.3
v2.2
v2.1
v2.0.1
v2.0
v1.0.1
Code Analysis
Analyzed Mar 16, 2026

BreadcrumbsPress Code Analysis

Dangerous Functions
0
Raw SQL Queries
0
0 prepared
Unescaped Output
20
58 escaped
Nonce Checks
0
Capability Checks
0
File Operations
0
External Requests
0
Bundled Libraries
1

Bundled Libraries

Freemius1.0

Output Escaping

74% escaped78 total outputs
Attack Surface

BreadcrumbsPress Attack Surface

Entry Points0
Unprotected0
WordPress Hooks 23
actioninitcore\basic\Plugin.php:68
actiontemplate_redirectcore\basic\Plugin.php:69
actiond4plib_shared_enqueue_preparecore\basic\Plugin.php:72
actionwp_enqueue_scriptscore\basic\Plugin.php:96
actiondebugpress-tracker-plugins-callcore\basic\Plugin.php:131
actionwp_headcore\basic\Plugin.php:133
actionbreadcrumbspress_load_settingscore\basic\Settings.php:180
actionbreadcrumbspress_settings_initcore\basic\Settings.php:181
filterbreadcrumbspress_blog_settings_getcore\basic\Settings.php:183
actionbreadcrumbspress_plugin_core_readycore\data\PostType.php:136
actionbreadcrumbspress_plugin_core_readycore\data\Taxonomy.php:46
filterbbp_no_breadcrumbcore\expand\bbPress.php:45
actionbreadcrumbspress_builder_for_post_type_archive_productcore\expand\WooCommerce.php:66
actionbreadcrumbspress_builder_for_post_type_single_productcore\expand\WooCommerce.php:67
actionbreadcrumbspress_builder_for_taxonomy_term_product_catcore\expand\WooCommerce.php:68
actionbreadcrumbspress_builder_for_taxonomy_term_product_tagcore\expand\WooCommerce.php:69
filterbreadcrumbspress_generator_buildcore\extend\Plugin.php:31
filterbreadcrumbspress_generator_completecore\extend\Plugin.php:32
actionbreadcrumbspress_plugin_core_readycore\extend\Plugin.php:33
filtersupport_forum_urlcore\freemius.php:47
filterpricing/disable_single_packagecore\freemius.php:49
filterpricing/show_annual_in_monthlycore\freemius.php:50
filtercheckout/parameterscore\freemius.php:51
Maintenance & Trust

BreadcrumbsPress Maintenance & Trust

Maintenance Signals

WordPress version tested6.7.5
Last updatedNov 12, 2025
PHP min version7.4
Downloads4K

Community Trust

Rating0/100
Number of ratings0
Active installs80
Developer Profile

BreadcrumbsPress Developer Profile

Milan Petrovic

17 plugins · 12K total installs

76
trust score
Avg Security Score
95/100
Avg Patch Time
1106 days
View full developer profile
Detection Fingerprints

How We Detect BreadcrumbsPress

Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.

Asset Fingerprints

Asset Paths
/wp-content/plugins/breadcrumbspress/core/assets/css/breadcrumbspress.css/wp-content/plugins/breadcrumbspress/core/assets/css/breadcrumbspress-rtl.css/wp-content/plugins/breadcrumbspress/core/assets/js/breadcrumbspress.js
Script Paths
/wp-content/plugins/breadcrumbspress/core/assets/js/breadcrumbspress.js
Version Parameters
breadcrumbspress/core/assets/css/breadcrumbspress.css?ver=breadcrumbspress/core/assets/css/breadcrumbspress-rtl.css?ver=breadcrumbspress/core/assets/js/breadcrumbspress.js?ver=

HTML / DOM Fingerprints

CSS Classes
breadcrumbspress-container
Data Attributes
data-breadcrumbspress-id
JS Globals
breadcrumbspress_settings
Shortcode Output
[breadcrumbspress]
FAQ

Frequently Asked Questions about BreadcrumbsPress