
Nofollow for external link Security & Risk Analysis
wordpress.org/plugins/nofollow-for-external-linkAutomatically insert rel=nofollow and target=_blank to all the external links into your website posts, pages or menus. Support exclude domain.
Is Nofollow for external link Safe to Use in 2026?
Generally Safe
Score 92/100Nofollow for external link has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.
The plugin 'nofollow-for-external-link' version 1.2.4 exhibits a strong security posture based on the provided static analysis. The absence of any identified dangerous functions, SQL queries without prepared statements, file operations, external HTTP requests, and taint flows is highly positive. Furthermore, the plugin appears to have a negligible attack surface with no exposed AJAX handlers, REST API routes, shortcodes, or cron events. The lack of any recorded vulnerabilities (CVEs) in its history further strengthens this positive assessment, suggesting a mature and well-maintained codebase.
However, a notable concern arises from the output escaping. With 50% of outputs not properly escaped, there is a potential risk of cross-site scripting (XSS) vulnerabilities if user-controlled data is not adequately sanitized before being displayed. While the overall risk is low due to the limited attack surface and lack of other vulnerabilities, this unescaped output represents the most significant potential weakness. The absence of nonce and capability checks, while not immediately concerning given the zero attack surface, would be critical if any entry points were to be introduced in future updates.
In conclusion, this plugin demonstrates excellent security practices by minimizing its attack surface and avoiding common pitfalls. The primary area for improvement and potential risk lies in ensuring all output is properly escaped. Without any known vulnerabilities and a clean code analysis, it presents a low-risk profile, but the unescaped outputs warrant attention for future development.
Key Concerns
- Unescaped output identified
Nofollow for external link Security Vulnerabilities
Nofollow for external link Code Analysis
Output Escaping
Nofollow for external link Attack Surface
WordPress Hooks 5
Maintenance & Trust
Nofollow for external link Maintenance & Trust
Maintenance Signals
Community Trust
Nofollow for external link Alternatives
WPF Force External Nofollow
wpf-force-external-nofollow
Automatically inserts rel="nofollow" into all the external links on your wordpress posts or pages.
Extend Link
extend-link
Add classes, IDs, titles, rel attributes, and download options to links. Includes H1–H6 heading support and built-in link status checker for SEO.
External & Affiliate Links Processor
external-links-nofollow-open-in-new-tab-favicon
Process outbound (external) links to make useful changes, including adding affiliate ID tags, rel=nofollow or target=_blank attributes, and adding ico …
Attributes Class ID Rel Title for WP-links
class-id-for-wp-links
Allow specify rel="nofollow", "title", "class" and "id" attributes for links in visual (TinyMCE) editor.
WP Nofollow More Links
wp-nofollow-more-links
Adds the nofollow rel attribute to the more (read more) links.
Nofollow for external link Developer Profile
5 plugins · 31K total installs
How We Detect Nofollow for external link
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/nofollow-for-external-link/nofollow-for-external-link.php/wp-content/plugins/nofollow-for-external-link/nofollow-for-external-link.phpnofollow-for-external-link/css/admin-style.css?ver=HTML / DOM Fingerprints
cn_admin_bannercn_nf_exclude_domainscn_nf_apply_to_menu