External & Affiliate Links Processor Security & Risk Analysis
wordpress.org/plugins/external-links-nofollow-open-in-new-tab-faviconProcess outbound (external) links to make useful changes, including adding affiliate ID tags, rel=nofollow or target=_blank attributes, and adding ico …
Is External & Affiliate Links Processor Safe to Use in 2026?
Generally Safe
Score 100/100External & Affiliate Links Processor has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.
The external-links-nofollow-open-in-new-tab-favicon plugin, version 1.5.5, demonstrates a generally good security posture based on the provided static analysis. The absence of dangerous functions, file operations, and external HTTP requests is a positive sign. Crucially, all SQL queries are using prepared statements, and the vast majority of output is properly escaped, mitigating common injection and Cross-Site Scripting (XSS) vulnerabilities. The plugin also has no known CVEs, indicating a history of stability and security awareness from its developers. The lack of critical or high-severity taint flows further reinforces this positive assessment.
However, there are areas for improvement and potential concerns. The plugin relies entirely on the platform's built-in authorization for its entry points, meaning it lacks explicit capability checks or nonce checks within its own code. While this might be acceptable if all its entry points are inherently secure or rely on WordPress's default role management, it presents a potential risk if any of the 13 shortcodes could be manipulated by users without proper authorization. The absence of nonce checks, in particular, is a missed opportunity to further harden these entry points against CSRF attacks. Despite these minor concerns, the overall security of this plugin appears robust for its intended functionality.
Key Concerns
- No nonce checks on entry points
- No capability checks on entry points
- Minor output escaping concerns (91%)
External & Affiliate Links Processor Security Vulnerabilities
External & Affiliate Links Processor Code Analysis
SQL Query Safety
Output Escaping
External & Affiliate Links Processor Attack Surface
Shortcodes 13
WordPress Hooks 8
Maintenance & Trust
External & Affiliate Links Processor Maintenance & Trust
Maintenance Signals
Community Trust
External & Affiliate Links Processor Alternatives
Nofollow for external link
nofollow-for-external-link
Automatically insert rel=nofollow and target=_blank to all the external links into your website posts, pages or menus. Support exclude domain.
DoFollow Case by Case
dofollow-case-by-case
DoFollow Case by Case allows you to selectively apply dofollow to comments and make links in pages or posts nofollow.
Customize External Links and add Icon
customize-external-links-and-add-icon
Customize link attributes, such as nofollow links, remove noreferrer, add icons to indicate external links
WPF Force External Nofollow
wpf-force-external-nofollow
Automatically inserts rel="nofollow" into all the external links on your wordpress posts or pages.
Attributes Class ID Rel Title for WP-links
class-id-for-wp-links
Allow specify rel="nofollow", "title", "class" and "id" attributes for links in visual (TinyMCE) editor.
External & Affiliate Links Processor Developer Profile
1 plugin · 100 total installs
How We Detect External & Affiliate Links Processor
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/external-links-nofollow-open-in-new-tab-favicon/style.cssexternal-links-nofollow-open-in-new-tab-favicon/style.css?ver=HTML / DOM Fingerprints
extlink-icondata-no-favicon