
SEO Breadcrumbs Security & Risk Analysis
wordpress.org/plugins/seo-breadcrumbsSEO Breadcrumbs is powerful and easy to use plugin that can add five different breadcrumbs navigation to your wordpress website.
Is SEO Breadcrumbs Safe to Use in 2026?
Generally Safe
Score 85/100SEO Breadcrumbs has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.
The "seo-breadcrumbs" v7.0 plugin exhibits a generally positive security posture based on the provided static analysis. The absence of AJAX handlers, REST API routes, cron events, and external HTTP requests significantly reduces its attack surface. Furthermore, the fact that all SQL queries utilize prepared statements is a strong indicator of good security practice in database interaction. The lack of any recorded vulnerabilities in its history, including critical or high severity ones, suggests a well-maintained and secure codebase over time.
However, there are areas for concern. The low percentage of properly escaped output (37%) is a significant risk. This indicates that user-supplied data or dynamic content might be outputted without proper sanitization, potentially leading to Cross-Site Scripting (XSS) vulnerabilities. The complete absence of nonce checks and capability checks, despite the presence of a shortcode, is also a notable weakness. While the static analysis shows no direct vulnerabilities, a shortcode without these security measures could be a point of exploitation if it interacts with user input or performs sensitive actions.
In conclusion, the plugin benefits from a minimal attack surface and secure database practices. The vulnerability history is a strong positive. Nevertheless, the significant number of unescaped outputs and the lack of nonce/capability checks on its shortcode represent potential security weaknesses that require attention to fully solidify its security. Addressing these specific issues would further enhance the plugin's overall security.
Key Concerns
- Low percentage of properly escaped output
- Missing nonce checks on shortcode
- Missing capability checks on shortcode
SEO Breadcrumbs Security Vulnerabilities
SEO Breadcrumbs Code Analysis
Output Escaping
SEO Breadcrumbs Attack Surface
Shortcodes 1
WordPress Hooks 6
Maintenance & Trust
SEO Breadcrumbs Maintenance & Trust
Maintenance Signals
Community Trust
SEO Breadcrumbs Alternatives
Catch Breadcrumb
catch-breadcrumb
Catch Breadcrumb lets you display Breadcrumb Navigation anywhere on your website elegantly.
amr breadcrumb navigation
breadcrumb-navigation-widget
Produces a breadcrumb trail through the page tree - a single page from each level of the page hierarchy (no nesting, no indenting).
Breadcrumb NavXT
breadcrumb-navxt
Adds breadcrumb navigation showing the visitor's path to their current location.
Flexy Breadcrumb
flexy-breadcrumb
Flexy Breadcrumb is a super light weight plugin that is easy to navigate through current page hierarchy.
Breadcrumb Trail
breadcrumb-trail
A powerful script for adding breadcrumbs to your site that supports Schema.org HTML5-valid microdata.
SEO Breadcrumbs Developer Profile
1 plugin · 300 total installs
How We Detect SEO Breadcrumbs
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/seo-breadcrumbs/css/admin-settings-page-styles.css/wp-content/plugins/seo-breadcrumbs/js/jquery.custom.js/wp-content/plugins/seo-breadcrumbs/css/seo-breadcrumbs-styles.css/wp-content/plugins/seo-breadcrumbs/json/styles.json/wp-content/plugins/seo-breadcrumbs/js/jquery.custom.jsseo-breadcrumbs/css/admin-settings-page-styles.css?ver=seo-breadcrumbs/js/jquery.custom.js?ver=seo-breadcrumbs/css/seo-breadcrumbs-styles.css?ver=HTML / DOM Fingerprints
breadcrumbs-itemcrumbseparator<!-- This breadcrumbs Generated by [ SEO Breadcrumbs ] Plugin. -->itemprop="itemListElement"itemscopeitemtype="http://schema.org/ListItem"itemprop="item"itemprop="name"itemprop="position"<ol itemscope itemtype="http://schema.org/BreadcrumbList">