
JSON-LD Breadcrumbs Security & Risk Analysis
wordpress.org/plugins/json-ld-breadcrumbsAdds JSON-LD based breadcrumb schema to your site visible only to the Search Engines such as Google.
Is JSON-LD Breadcrumbs Safe to Use in 2026?
Generally Safe
Score 100/100JSON-LD Breadcrumbs has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.
The "json-ld-breadcrumbs" v1.0.5 plugin exhibits a strong security posture based on the provided static analysis. The plugin has no apparent attack surface from AJAX handlers, REST API routes, shortcodes, or cron events, which are all common entry points for vulnerabilities. The code also demonstrates good practices with 100% of SQL queries using prepared statements and a high percentage (89%) of output being properly escaped. Furthermore, there are no dangerous functions, file operations, external HTTP requests, or bundled libraries, which significantly reduces the potential for exploitation.
The vulnerability history is also clean, with zero known CVEs, indicating a history of secure development or prompt patching. The absence of any recorded vulnerabilities, regardless of severity, is a positive sign. While the taint analysis reports zero flows, this could also be due to the limited attack surface and the plugin's likely straightforward functionality of generating JSON-LD for breadcrumbs. This plugin appears to be developed with security in mind, minimizing potential risks through a small footprint and careful coding practices.
However, it's important to note the complete absence of capability checks and nonce checks. While this might be acceptable if the plugin genuinely has no user-modifiable settings or direct interaction points that could be exploited for privilege escalation or CSRF, it's a potential area of concern if its functionality were to expand or if there are implicit trust assumptions in its implementation. Overall, the plugin is very secure, with the only potential minor concern being the lack of explicit capability and nonce checks which could be a risk if its functionality evolved.
Key Concerns
- No capability checks
- No nonce checks
- Minor unescaped output
JSON-LD Breadcrumbs Security Vulnerabilities
JSON-LD Breadcrumbs Release Timeline
JSON-LD Breadcrumbs Code Analysis
Output Escaping
JSON-LD Breadcrumbs Attack Surface
WordPress Hooks 2
Maintenance & Trust
JSON-LD Breadcrumbs Maintenance & Trust
Maintenance Signals
Community Trust
JSON-LD Breadcrumbs Alternatives
dig Breadcrumb
dig-breadcrumb
Generate breadcrumb navigation for all posts, pages, custom post types, categories, and taxonomies on WordPress, considering their publication status.
Schema
schema
Get the next generation of Schema Structured Data to enhance your WordPress site presentation in Google search results.
FAQ Schema For Pages And Posts
faq-schema-for-pages-and-posts
FAQ Schema For Pages And Posts by Krystian Szastok Founder of RobotZebra - a London based SEO agency, allows you to turn questions and answers on your …
Schema App Structured Data
schema-app-structured-data-for-schemaorg
Get Schema.org structured data for all pages, posts, categories and profile pages on activation. Use Schema App to customize any Schema Markup.
Schema Default Image
schema-default-image
Add ability to set a default Featured image for schema.org markup, an extension for the Schema plugin.
JSON-LD Breadcrumbs Developer Profile
16 plugins · 14K total installs
How We Detect JSON-LD Breadcrumbs
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/json-ld-breadcrumbs/assets/css/breadcrumbs.min.css/wp-content/plugins/json-ld-breadcrumbs/assets/js/breadcrumbs.min.js/wp-content/plugins/json-ld-breadcrumbs/assets/js/breadcrumbs.min.jsjson-ld-breadcrumbs/assets/css/breadcrumbs.min.css?ver=json-ld-breadcrumbs/assets/js/breadcrumbs.min.js?ver=