External & Affiliate Links Processor Security & Risk Analysis

wordpress.org/plugins/external-links-nofollow-open-in-new-tab-favicon

Process outbound (external) links to make useful changes, including adding affiliate ID tags, rel=nofollow or target=_blank attributes, and adding ico …

100 active installs v1.5.5 PHP + WP 4.0.1+ Updated Unknown
nofollownofollow-external-linknofollow-external-linksnofollow-linksrel-nofollow
100
A · Safe
CVEs total0
Unpatched0
Last CVENever
Safety Verdict

Is External & Affiliate Links Processor Safe to Use in 2026?

Generally Safe

Score 100/100

External & Affiliate Links Processor has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.

No known CVEs
Risk Assessment

The external-links-nofollow-open-in-new-tab-favicon plugin, version 1.5.5, demonstrates a generally good security posture based on the provided static analysis. The absence of dangerous functions, file operations, and external HTTP requests is a positive sign. Crucially, all SQL queries are using prepared statements, and the vast majority of output is properly escaped, mitigating common injection and Cross-Site Scripting (XSS) vulnerabilities. The plugin also has no known CVEs, indicating a history of stability and security awareness from its developers. The lack of critical or high-severity taint flows further reinforces this positive assessment.

However, there are areas for improvement and potential concerns. The plugin relies entirely on the platform's built-in authorization for its entry points, meaning it lacks explicit capability checks or nonce checks within its own code. While this might be acceptable if all its entry points are inherently secure or rely on WordPress's default role management, it presents a potential risk if any of the 13 shortcodes could be manipulated by users without proper authorization. The absence of nonce checks, in particular, is a missed opportunity to further harden these entry points against CSRF attacks. Despite these minor concerns, the overall security of this plugin appears robust for its intended functionality.

Key Concerns

  • No nonce checks on entry points
  • No capability checks on entry points
  • Minor output escaping concerns (91%)
Vulnerabilities
None known

External & Affiliate Links Processor Security Vulnerabilities

No known vulnerabilities — this is a good sign.
Code Analysis
Analyzed Mar 17, 2026

External & Affiliate Links Processor Code Analysis

Dangerous Functions
0
Raw SQL Queries
0
1 prepared
Unescaped Output
3
32 escaped
Nonce Checks
0
Capability Checks
0
File Operations
0
External Requests
0
Bundled Libraries
0

SQL Query Safety

100% prepared1 total queries

Output Escaping

91% escaped35 total outputs
Attack Surface

External & Affiliate Links Processor Attack Surface

Entry Points13
Unprotected0

Shortcodes 13

[extlink_amazon_com_au_buy] nofollow-external-link.php:440
[extlink_amazon_br_buy] nofollow-external-link.php:441
[extlink_amazon_ca_buy] nofollow-external-link.php:442
[extlink_amazon_cn_buy] nofollow-external-link.php:443
[extlink_amazon_com_buy] nofollow-external-link.php:444
[extlink_amazon_co_jp_buy] nofollow-external-link.php:445
[extlink_amazon_co_uk_buy] nofollow-external-link.php:446
[extlink_amazon_de_buy] nofollow-external-link.php:447
[extlink_amazon_es_buy] nofollow-external-link.php:448
[extlink_amazon_fr_buy] nofollow-external-link.php:449
[extlink_amazon_in_buy] nofollow-external-link.php:450
[extlink_amazon_it_buy] nofollow-external-link.php:451
[extlink_amazon_mx_buy] nofollow-external-link.php:452
WordPress Hooks 8
actionadmin_enqueue_scriptsadmin.php:25
actionadmin_initadmin.php:30
filterplugin_row_metaadmin.php:54
actionadmin_enqueue_scriptsadmin.php:70
actionadmin_menuadmin.php:72
actionadmin_initadmin.php:73
actionwp_enqueue_scriptsnofollow-external-link.php:44
filterthe_contentnofollow-external-link.php:49
Maintenance & Trust

External & Affiliate Links Processor Maintenance & Trust

Maintenance Signals

WordPress version tested4.8.28
Last updatedUnknown
PHP min version
Downloads5K

Community Trust

Rating80/100
Number of ratings4
Active installs100
Developer Profile

External & Affiliate Links Processor Developer Profile

reikiman

1 plugin · 100 total installs

94
trust score
Avg Security Score
100/100
Avg Patch Time
30 days
View full developer profile
Detection Fingerprints

How We Detect External & Affiliate Links Processor

Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.

Asset Fingerprints

Asset Paths
/wp-content/plugins/external-links-nofollow-open-in-new-tab-favicon/style.css
Version Parameters
external-links-nofollow-open-in-new-tab-favicon/style.css?ver=

HTML / DOM Fingerprints

CSS Classes
extlink-icon
Data Attributes
data-no-favicon
FAQ

Frequently Asked Questions about External & Affiliate Links Processor