
Structured Content (JSON-LD) #wpsc Security & Risk Analysis
wordpress.org/plugins/structured-contentAdd flexible content boxes with JSON-LD microdata output according to schema.org e.g. FAQPage, ProfilePage, Event, Course, LocalBusiness, JobPosting a …
Is Structured Content (JSON-LD) #wpsc Safe to Use in 2026?
Generally Safe
Score 94/100Structured Content (JSON-LD) #wpsc has a strong security track record. Known vulnerabilities have been patched promptly.
The "structured-content" plugin version 1.7.0 presents a mixed security posture. On the positive side, the plugin demonstrates good practices by using prepared statements for all SQL queries and having no critical or high severity vulnerabilities in its historical CVE record that are currently unpatched. The static analysis also shows a low attack surface with all identified entry points (shortcodes) not having explicit authentication checks, which is a potential concern. However, the lack of explicit capability checks on these shortcodes means that any authenticated user could potentially interact with them, which might not be intended.
A significant concern from the static analysis is the output escaping. With 990 total outputs and only 69% properly escaped, there's a considerable risk of Cross-Site Scripting (XSS) vulnerabilities. This is further echoed by the plugin's historical vulnerability types, which include 'Improper Neutralization of Input During Web Page Generation ('Cross-Site Scripting')'. The presence of 9 total known CVEs, although none are currently unpatched, suggests a history of security weaknesses, particularly in deserialization and XSS, which warrants careful attention.
In conclusion, while the plugin has addressed past critical vulnerabilities and uses secure SQL practices, the high percentage of unescaped output and the historical trend of XSS vulnerabilities are significant risks. The lack of explicit authentication or permission checks on shortcodes, despite not being directly listed as "unprotected" in the attack surface metric, also contributes to a potential security gap. Continuous monitoring and updating are crucial given its vulnerability history.
Key Concerns
- High percentage of unescaped output
- Lack of explicit capability checks on shortcodes
- History of medium severity vulnerabilities
- Bundled library: TinyMCE (potential for outdated library)
Structured Content (JSON-LD) #wpsc Security Vulnerabilities
CVEs by Year
Severity Breakdown
9 total CVEs
Structured Content (JSON-LD) #wpsc <= 1.6.4 - Authenticated (Contributor+) Stored Cross-Site Scripting via FAQ Block
Structured Content <= 1.6.4 - Authenticated (Contributor+) Stored Cross-Site Scripting via sc_fs_local_business Shortcode
Structured Content <= 1.6.3 - Authenticated (Contributor+) Stored Cross-Site Scripting
Structured Content (JSON-LD) #wpsc <= 1.6.3 - Authenticated (Contributor+) Stored Cross-Site Scripting via sc_fs_local_business Shortcode
Structured Content <= 1.6.2 - Authenticated (Contributor+) Stored Cross-Site Scripting
Structured Content <= 1.6.1 - Authenticated (Contributor+) Stored Cross-Site Scripting via Classic Editor Shortcode
Structured Content <= 1.5.3 - Authenticated (Contributor+) PHP Object Injection
Structured Content <= 1.5.3 - Authenticated (Contributor+) Stored Cross-Site Scripting
Structured Content <= 1.5.0 - Authenticated (Contributor+) Stored Cross-Site Scripting via Shortcode
Structured Content (JSON-LD) #wpsc Code Analysis
Bundled Libraries
Output Escaping
Structured Content (JSON-LD) #wpsc Attack Surface
Shortcodes 9
WordPress Hooks 18
Maintenance & Trust
Structured Content (JSON-LD) #wpsc Maintenance & Trust
Maintenance Signals
Community Trust
Structured Content (JSON-LD) #wpsc Alternatives
WP Recipe Maker
wp-recipe-maker
The easy and user-friendly recipe plugin for everyone. Automatic JSON-LD metadata for food AND how-to recipes will improve your SEO!
Recipe Card Blocks Lite
recipe-card-blocks-by-wpzoom
Recipe Card Blocks with Schema Markup — create SEO-optimized recipes with Gutenberg, Elementor & AMP support
Create
mediavine-create
Complete tool for creating and publishing recipes and other schema types on your site.
WP Delicious – Recipe Plugin for Food Bloggers (formerly Delicious Recipes)
delicious-recipes
WP Delicious is an SEO-optimized and Schema-friendly recipe plugin for food bloggers to create and display unlimited recipes.
Cooked – Recipe Management
cooked
Cooked is the absolute best way to create & display recipes with WordPress. SEO optimized, galleries, timers, and much more.
Structured Content (JSON-LD) #wpsc Developer Profile
1 plugin · 40K total installs
How We Detect Structured Content (JSON-LD) #wpsc
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/structured-content/dist/css/blocks.style.build.css/wp-content/plugins/structured-content/dist/js/blocks.editor.build.js/wp-content/plugins/structured-content/dist/js/frontend.build.js/wp-content/plugins/structured-content/dist/js/blocks.editor.build.js/wp-content/plugins/structured-content/dist/js/frontend.build.jsstructured-content/dist/css/blocks.style.build.css?ver=structured-content/dist/js/blocks.editor.build.js?ver=structured-content/dist/js/frontend.build.js?ver=HTML / DOM Fingerprints
structured-content-editorwp-block-structured-content<!-- wp:structured-content/card --><!-- /wp:structured-content/card --><!-- wp:structured-content/featured-page --><!-- /wp:structured-content/featured-page -->+28 moredata-typedata-alignwpstructuredContentGutenberg[structured_content[/structured_content]