
Catch Breadcrumb Security & Risk Analysis
wordpress.org/plugins/catch-breadcrumbCatch Breadcrumb lets you display Breadcrumb Navigation anywhere on your website elegantly.
Is Catch Breadcrumb Safe to Use in 2026?
Generally Safe
Score 100/100Catch Breadcrumb has a strong security track record. Known vulnerabilities have been patched promptly. It's a solid choice for most WordPress installations.
The catch-breadcrumb plugin version 2.4 exhibits a generally good security posture based on the provided static analysis. A significant strength is the complete absence of unprotected entry points, including AJAX handlers, REST API routes, and shortcodes. The plugin also demonstrates strong adherence to security best practices with 100% of its SQL queries using prepared statements and a high rate of output escaping (93%). Furthermore, the presence of nonce and capability checks on all identified entry points indicates a proactive approach to access control. The lack of dangerous functions, file operations, and external HTTP requests further contributes to a reduced attack surface. However, the vulnerability history, although currently unpatched, does reveal a past medium-severity Cross-Site Scripting (XSS) vulnerability. While this issue is historical and has no currently unpatched CVEs, it serves as a reminder that even plugins with strong static analysis can be susceptible to certain types of vulnerabilities. The zero taint flows found in this analysis are positive, but it's worth noting that taint analysis capabilities might be limited. Overall, catch-breadcrumb v2.4 presents as a secure plugin with good development practices, with the only significant historical concern being a past XSS vulnerability.
Key Concerns
- Historical medium severity XSS vulnerability
Catch Breadcrumb Security Vulnerabilities
CVEs by Year
Severity Breakdown
1 total CVE
Catch Breadcrumb <= 1.5.4 - Reflected Cross-Site Scripting
Catch Breadcrumb Release Timeline
Catch Breadcrumb Code Analysis
Output Escaping
Catch Breadcrumb Attack Surface
AJAX Handlers 3
Shortcodes 1
WordPress Hooks 24
Maintenance & Trust
Catch Breadcrumb Maintenance & Trust
Maintenance Signals
Community Trust
Catch Breadcrumb Alternatives
SEO Breadcrumbs
seo-breadcrumbs
SEO Breadcrumbs is powerful and easy to use plugin that can add five different breadcrumbs navigation to your wordpress website.
Breadcrumb NavXT
breadcrumb-navxt
Adds breadcrumb navigation showing the visitor's path to their current location.
Flexy Breadcrumb
flexy-breadcrumb
Flexy Breadcrumb is a super light weight plugin that is easy to navigate through current page hierarchy.
Breadcrumb Trail
breadcrumb-trail
A powerful script for adding breadcrumbs to your site that supports Schema.org HTML5-valid microdata.
RDFa Breadcrumb
rdfa-breadcrumb
An easy template tag for showing a breadcrumb menu on your site and on google search results with built in RDFa Markup.
Catch Breadcrumb Developer Profile
156 plugins · 226K total installs
How We Detect Catch Breadcrumb
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/catch-breadcrumb/admin/css/catch-breadcrumb-admin.css/wp-content/plugins/catch-breadcrumb/admin/js/catch-breadcrumb-admin.js/wp-content/plugins/catch-breadcrumb/public/css/catch-breadcrumb-public.css/wp-content/plugins/catch-breadcrumb/public/js/catch-breadcrumb-public.js/wp-content/plugins/catch-breadcrumb/admin/js/catch-breadcrumb-admin.js/wp-content/plugins/catch-breadcrumb/public/js/catch-breadcrumb-public.jscatch-breadcrumb/admin/css/catch-breadcrumb-admin.css?ver=catch-breadcrumb/admin/js/catch-breadcrumb-admin.js?ver=catch-breadcrumb/public/css/catch-breadcrumb-public.css?ver=catch-breadcrumb/public/js/catch-breadcrumb-public.js?ver=HTML / DOM Fingerprints
catch-breadcrumbcatch_breadcrumb_options[catch_breadcrumb][catch_breadcrumb type="post"][catch_breadcrumb type="page"][catch_breadcrumb type="category"]