Carbon Breadcrumbs Security & Risk Analysis

wordpress.org/plugins/carbon-breadcrumbs

A basic WordPress plugin for breadcrumbs with advanced capabilities for extending.

60 active installs v1.0.2 PHP + WP 3.8+ Updated Apr 11, 2016
adminbreadcrumbbreadcrumbscarbontrail
85
A · Safe
CVEs total0
Unpatched0
Last CVENever
Safety Verdict

Is Carbon Breadcrumbs Safe to Use in 2026?

Generally Safe

Score 85/100

Carbon Breadcrumbs has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.

No known CVEs Updated 9yr ago
Risk Assessment

The "carbon-breadcrumbs" v1.0.2 plugin exhibits an exceptionally strong security posture based on the provided static analysis. The absence of any identified attack surface entries, dangerous functions, file operations, external HTTP requests, or SQL queries without prepared statements is highly commendable. Furthermore, the complete output escaping and lack of taint analysis findings indicate robust defensive programming practices within the codebase. The plugin's vulnerability history also reflects a clean record, with zero known CVEs, suggesting a stable and well-maintained security profile over time.

While the analysis reveals no immediate or inherent security flaws, the complete absence of certain security mechanisms like nonce checks and capability checks on potential entry points (if any were present) represents a theoretical concern. In scenarios where an attack surface might be implicitly introduced or expanded in future versions, these checks would become critical. However, based solely on the current analysis, the plugin appears to be very secure.

Key Concerns

  • No nonce checks found
  • No capability checks found
Vulnerabilities
None known

Carbon Breadcrumbs Security Vulnerabilities

No known vulnerabilities — this is a good sign.
Code Analysis
Analyzed Mar 16, 2026

Carbon Breadcrumbs Code Analysis

Dangerous Functions
0
Raw SQL Queries
0
0 prepared
Unescaped Output
0
21 escaped
Nonce Checks
0
Capability Checks
0
File Operations
0
External Requests
0
Bundled Libraries
0

Output Escaping

100% escaped21 total outputs
Attack Surface

Carbon Breadcrumbs Attack Surface

Entry Points0
Unprotected0
WordPress Hooks 6
actioninitadmin\Carbon_Breadcrumb_Admin.php:31
actionadmin_menuadmin\Carbon_Breadcrumb_Admin.php:32
filtercarbon_breadcrumbs_renderer_default_optionsadmin\Carbon_Breadcrumb_Admin.php:67
actionadmin_menuadmin\Carbon_Breadcrumb_Admin_Settings.php:24
actionadmin_initadmin\Carbon_Breadcrumb_Admin_Settings.php:27
actionplugins_loadedcore\Carbon_Breadcrumb_L10n.php:17
Maintenance & Trust

Carbon Breadcrumbs Maintenance & Trust

Maintenance Signals

WordPress version tested4.5.33
Last updatedApr 11, 2016
PHP min version
Downloads3K

Community Trust

Rating96/100
Number of ratings4
Active installs60
Developer Profile

Carbon Breadcrumbs Developer Profile

Marin Atanasov

7 plugins · 4K total installs

90
trust score
Avg Security Score
86/100
Avg Patch Time
1 days
View full developer profile
Detection Fingerprints

How We Detect Carbon Breadcrumbs

Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.

Asset Fingerprints

Asset Paths
/wp-content/plugins/carbon-breadcrumbs/admin/js/carbon-breadcrumbs-admin.js/wp-content/plugins/carbon-breadcrumbs/core/js/carbon-breadcrumbs.js/wp-content/plugins/carbon-breadcrumbs/core/css/carbon-breadcrumbs.css
Script Paths
/wp-content/plugins/carbon-breadcrumbs/admin/js/carbon-breadcrumbs-admin.js/wp-content/plugins/carbon-breadcrumbs/core/js/carbon-breadcrumbs.js
Version Parameters
carbon-breadcrumbs/admin/js/carbon-breadcrumbs-admin.js?ver=carbon-breadcrumbs/core/js/carbon-breadcrumbs.js?ver=carbon-breadcrumbs/core/css/carbon-breadcrumbs.css?ver=

HTML / DOM Fingerprints

CSS Classes
carbon-breadcrumbs
JS Globals
carbon_breadcrumb_l10n
FAQ

Frequently Asked Questions about Carbon Breadcrumbs