
dig Breadcrumb Security & Risk Analysis
wordpress.org/plugins/dig-breadcrumbGenerate breadcrumb navigation for all posts, pages, custom post types, categories, and taxonomies on WordPress, considering their publication status.
Is dig Breadcrumb Safe to Use in 2026?
Generally Safe
Score 92/100dig Breadcrumb has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.
The dig-breadcrumb plugin v0.1 exhibits a generally strong security posture based on the provided static analysis. The plugin demonstrates excellent coding practices by having 100% of its SQL queries use prepared statements and 100% of its output properly escaped, which are crucial for preventing common vulnerabilities like SQL injection and cross-site scripting (XSS). The absence of file operations and external HTTP requests further reduces the attack surface. The fact that there are no recorded vulnerabilities, including critical or high severity ones, and no unpatched CVEs in its history is a very positive indicator of its development quality and ongoing maintenance.
However, a significant concern arises from the lack of any recorded nonce checks or capability checks. While the current attack surface appears small and primarily consists of a single shortcode without apparent unprotected entry points in the static analysis, the absence of these fundamental security mechanisms means that the plugin is not robustly protected against potential authorization or CSRF vulnerabilities if the attack surface were to expand or if existing entry points were misused. The lack of taint analysis results also makes it difficult to definitively assess the security of data flow within the plugin. In conclusion, while the plugin has a good foundation with secure coding for database interactions and output handling, the missing authorization and CSRF checks represent a notable weakness that could become a risk if the plugin's functionality or integration with other WordPress features evolves.
Key Concerns
- Missing Nonce Checks
- Missing Capability Checks
dig Breadcrumb Security Vulnerabilities
dig Breadcrumb Code Analysis
Output Escaping
dig Breadcrumb Attack Surface
Shortcodes 1
WordPress Hooks 4
Maintenance & Trust
dig Breadcrumb Maintenance & Trust
Maintenance Signals
Community Trust
dig Breadcrumb Alternatives
Breadcrumb Navigation for SEO with Microdata
breadcrumb-navigation-for-seo-with-microdata
With this Plugin you can generate a breadcrumb navigation with Microdata format from schema.org. The breadcrumbs will be shown in Google snippets.
JSON-LD Breadcrumbs
json-ld-breadcrumbs
Adds JSON-LD based breadcrumb schema to your site visible only to the Search Engines such as Google.
Article JSON-LD
article-json-ld
A straightforward solution to add Schema.org microdata as a JSON-LD script on your site posts.
Microdata to JSON-LD Converter
microdata-to-json-ld-converter
A powerful tool to convert your existing Schema.org Microdata into the preferred JSON-LD format, clean up your HTML, and maintain structured data.
Breadcrumb NavXT
breadcrumb-navxt
Adds breadcrumb navigation showing the visitor's path to their current location.
dig Breadcrumb Developer Profile
3 plugins · 0 total installs
How We Detect dig Breadcrumb
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
HTML / DOM Fingerprints
dig-breadcrumbbreadcrumb-separatoritemscopeitemtype="http://schema.org/BreadcrumbList"[dig_breadcrumb]