Nofollow Adder WordPress Plugin Security & Risk Analysis

wordpress.org/plugins/nofollow-adder

A simple plugin to add 'nofollow' relation attribute to all external links.

0 active installs v1.0 PHP 5.2.4+ WP 4.6+ Updated May 31, 2018
external-links-nofollownofollownofollow-addernofollow-adder-wordpress-pluginrel-nofollow
85
A · Safe
CVEs total0
Unpatched0
Last CVENever
Download
Safety Verdict

Is Nofollow Adder WordPress Plugin Safe to Use in 2026?

Generally Safe

Score 85/100

Nofollow Adder WordPress Plugin has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.

No known CVEs Updated 7yr ago
Risk Assessment

The "nofollow-adder" v1.0 plugin exhibits a strong security posture based on the provided static analysis. The absence of any identified dangerous functions, SQL queries without prepared statements, unsanitized taint flows, or unescaped output is highly commendable. Furthermore, the plugin has no recorded vulnerabilities, including past CVEs, which suggests a history of secure development and maintenance. The total lack of entry points, such as AJAX handlers, REST API routes, shortcodes, and cron events, significantly reduces the plugin's attack surface. This means there are no readily available mechanisms for external interaction that could be exploited.

However, the analysis does reveal a critical deficiency: the complete absence of nonce checks and capability checks. While the current attack surface is zero, this lack of fundamental security controls means that if any entry points were to be introduced in future versions without proper authorization checks, the plugin would be immediately vulnerable to attacks like Cross-Site Request Forgery (CSRF) or unauthorized privilege escalation. The static analysis results, particularly the zero unprotected entry points, are excellent, but the missing security checks represent a significant potential weakness that could be exploited should the plugin's architecture evolve.

In conclusion, the "nofollow-adder" v1.0 plugin is currently very secure due to its minimal attack surface and clean code. Its vulnerability history is pristine, indicating a mature development process. The primary concern lies not with the current state of the code but with the fundamental lack of authorization and security checks that would protect against future vulnerabilities if new features are added. This suggests a need for robust security practices to be integrated moving forward, even with a seemingly inert plugin.

Key Concerns

  • Missing nonce checks
  • Missing capability checks
Vulnerabilities
None known

Nofollow Adder WordPress Plugin Security Vulnerabilities

No known vulnerabilities — this is a good sign.
Code Analysis
Analyzed Mar 17, 2026

Nofollow Adder WordPress Plugin Code Analysis

Dangerous Functions
0
Raw SQL Queries
0
0 prepared
Unescaped Output
0
2 escaped
Nonce Checks
0
Capability Checks
0
File Operations
0
External Requests
0
Bundled Libraries
0

Output Escaping

100% escaped2 total outputs
Attack Surface

Nofollow Adder WordPress Plugin Attack Surface

Entry Points0
Unprotected0
WordPress Hooks 1
actionwp_enqueue_scriptsindex.php:20
Maintenance & Trust

Nofollow Adder WordPress Plugin Maintenance & Trust

Maintenance Signals

WordPress version tested4.7.32
Last updatedMay 31, 2018
PHP min version5.2.4
Downloads1K

Community Trust

Rating0/100
Number of ratings0
Active installs0
Developer Profile

Nofollow Adder WordPress Plugin Developer Profile

Srikant Kumar

1 plugin · 0 total installs

84
trust score
Avg Security Score
85/100
Avg Patch Time
30 days
View full developer profile
Detection Fingerprints

How We Detect Nofollow Adder WordPress Plugin

Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.

Asset Fingerprints

Asset Paths
/wp-content/plugins/nofollow-adder/scripts.js
Script Paths
/wp-content/plugins/nofollow-adder/scripts.js
Version Parameters
nofollow-adder/scripts.js?ver=

HTML / DOM Fingerprints

JS Globals
var rooturl
FAQ

Frequently Asked Questions about Nofollow Adder WordPress Plugin