JSON-LD Breadcrumbs Security & Risk Analysis

wordpress.org/plugins/json-ld-breadcrumbs

Adds JSON-LD based breadcrumb schema to your site visible only to the Search Engines such as Google.

1K active installs v1.0.5 PHP + WP 4.4+ Updated Jan 19, 2026
breadcrumbgooglejson-ldschemaschema-org
100
A · Safe
CVEs total0
Unpatched0
Last CVENever
Safety Verdict

Is JSON-LD Breadcrumbs Safe to Use in 2026?

Generally Safe

Score 100/100

JSON-LD Breadcrumbs has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.

No known CVEs Updated 3mo ago
Risk Assessment

The "json-ld-breadcrumbs" v1.0.5 plugin exhibits a strong security posture based on the provided static analysis. The plugin has no apparent attack surface from AJAX handlers, REST API routes, shortcodes, or cron events, which are all common entry points for vulnerabilities. The code also demonstrates good practices with 100% of SQL queries using prepared statements and a high percentage (89%) of output being properly escaped. Furthermore, there are no dangerous functions, file operations, external HTTP requests, or bundled libraries, which significantly reduces the potential for exploitation.

The vulnerability history is also clean, with zero known CVEs, indicating a history of secure development or prompt patching. The absence of any recorded vulnerabilities, regardless of severity, is a positive sign. While the taint analysis reports zero flows, this could also be due to the limited attack surface and the plugin's likely straightforward functionality of generating JSON-LD for breadcrumbs. This plugin appears to be developed with security in mind, minimizing potential risks through a small footprint and careful coding practices.

However, it's important to note the complete absence of capability checks and nonce checks. While this might be acceptable if the plugin genuinely has no user-modifiable settings or direct interaction points that could be exploited for privilege escalation or CSRF, it's a potential area of concern if its functionality were to expand or if there are implicit trust assumptions in its implementation. Overall, the plugin is very secure, with the only potential minor concern being the lack of explicit capability and nonce checks which could be a risk if its functionality evolved.

Key Concerns

  • No capability checks
  • No nonce checks
  • Minor unescaped output
Vulnerabilities
None known

JSON-LD Breadcrumbs Security Vulnerabilities

No known vulnerabilities — this is a good sign.
Version History

JSON-LD Breadcrumbs Release Timeline

v1.0.5Current
v1.0.4
v1.0.3
v1.0.2
v1.0.1
v1.0.0
Code Analysis
Analyzed Mar 16, 2026

JSON-LD Breadcrumbs Code Analysis

Dangerous Functions
0
Raw SQL Queries
0
0 prepared
Unescaped Output
1
8 escaped
Nonce Checks
0
Capability Checks
0
File Operations
0
External Requests
0
Bundled Libraries
0

Output Escaping

89% escaped9 total outputs
Attack Surface

JSON-LD Breadcrumbs Attack Surface

Entry Points0
Unprotected0
WordPress Hooks 2
actionwp_headclass-json-ld-breadcrumbs.php:68
actionwpjson-ld-breadcrumbs.php:25
Maintenance & Trust

JSON-LD Breadcrumbs Maintenance & Trust

Maintenance Signals

WordPress version tested6.9.4
Last updatedJan 19, 2026
PHP min version
Downloads12K

Community Trust

Rating100/100
Number of ratings2
Active installs1K
Developer Profile

JSON-LD Breadcrumbs Developer Profile

Pratik Chaskar

16 plugins · 14K total installs

79
trust score
Avg Security Score
100/100
Avg Patch Time
131 days
View full developer profile
Detection Fingerprints

How We Detect JSON-LD Breadcrumbs

Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.

Asset Fingerprints

Asset Paths
/wp-content/plugins/json-ld-breadcrumbs/assets/css/breadcrumbs.min.css/wp-content/plugins/json-ld-breadcrumbs/assets/js/breadcrumbs.min.js
Script Paths
/wp-content/plugins/json-ld-breadcrumbs/assets/js/breadcrumbs.min.js
Version Parameters
json-ld-breadcrumbs/assets/css/breadcrumbs.min.css?ver=json-ld-breadcrumbs/assets/js/breadcrumbs.min.js?ver=

HTML / DOM Fingerprints

FAQ

Frequently Asked Questions about JSON-LD Breadcrumbs