Nofollow for external link Security & Risk Analysis

wordpress.org/plugins/nofollow-for-external-link

Automatically insert rel=nofollow and target=_blank to all the external links into your website posts, pages or menus. Support exclude domain.

10K active installs v1.2.4 PHP + WP 2.8.6+ Updated Apr 28, 2024
linknofollowrel-nofollowrelnofollowseo
92
A · Safe
CVEs total0
Unpatched0
Last CVENever
Safety Verdict

Is Nofollow for external link Safe to Use in 2026?

Generally Safe

Score 92/100

Nofollow for external link has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.

No known CVEs Updated 1yr ago
Risk Assessment

The plugin 'nofollow-for-external-link' version 1.2.4 exhibits a strong security posture based on the provided static analysis. The absence of any identified dangerous functions, SQL queries without prepared statements, file operations, external HTTP requests, and taint flows is highly positive. Furthermore, the plugin appears to have a negligible attack surface with no exposed AJAX handlers, REST API routes, shortcodes, or cron events. The lack of any recorded vulnerabilities (CVEs) in its history further strengthens this positive assessment, suggesting a mature and well-maintained codebase.

However, a notable concern arises from the output escaping. With 50% of outputs not properly escaped, there is a potential risk of cross-site scripting (XSS) vulnerabilities if user-controlled data is not adequately sanitized before being displayed. While the overall risk is low due to the limited attack surface and lack of other vulnerabilities, this unescaped output represents the most significant potential weakness. The absence of nonce and capability checks, while not immediately concerning given the zero attack surface, would be critical if any entry points were to be introduced in future updates.

In conclusion, this plugin demonstrates excellent security practices by minimizing its attack surface and avoiding common pitfalls. The primary area for improvement and potential risk lies in ensuring all output is properly escaped. Without any known vulnerabilities and a clean code analysis, it presents a low-risk profile, but the unescaped outputs warrant attention for future development.

Key Concerns

  • Unescaped output identified
Vulnerabilities
None known

Nofollow for external link Security Vulnerabilities

No known vulnerabilities — this is a good sign.
Code Analysis
Analyzed Mar 16, 2026

Nofollow for external link Code Analysis

Dangerous Functions
0
Raw SQL Queries
0
0 prepared
Unescaped Output
2
2 escaped
Nonce Checks
0
Capability Checks
0
File Operations
0
External Requests
0
Bundled Libraries
0

Output Escaping

50% escaped4 total outputs
Attack Surface

Nofollow for external link Attack Surface

Entry Points0
Unprotected0
WordPress Hooks 5
actionadmin_enqueue_scriptsnofollow-external-link.php:61
actionadmin_initnofollow-external-link.php:67
actionadmin_menunofollow-external-link.php:72
filterthe_contentnofollow-external-link.php:244
filterwp_nav_menu_itemsnofollow-external-link.php:247
Maintenance & Trust

Nofollow for external link Maintenance & Trust

Maintenance Signals

WordPress version tested6.5.8
Last updatedApr 28, 2024
PHP min version
Downloads286K

Community Trust

Rating76/100
Number of ratings36
Active installs10K
Developer Profile

Nofollow for external link Developer Profile

CyberNetikz

5 plugins · 31K total installs

78
trust score
Avg Security Score
98/100
Avg Patch Time
967 days
View full developer profile
Detection Fingerprints

How We Detect Nofollow for external link

Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.

Asset Fingerprints

Asset Paths
/wp-content/plugins/nofollow-for-external-link/nofollow-for-external-link.php
Script Paths
/wp-content/plugins/nofollow-for-external-link/nofollow-for-external-link.php
Version Parameters
nofollow-for-external-link/css/admin-style.css?ver=

HTML / DOM Fingerprints

CSS Classes
cn_admin_banner
Data Attributes
cn_nf_exclude_domainscn_nf_apply_to_menu
FAQ

Frequently Asked Questions about Nofollow for external link