Nofollow for External Link TAP Security & Risk Analysis

wordpress.org/plugins/nofollow-for-external-link-tap

Just simple, if you use this plugins, rel=nofollow and target=_blank will be insert automatically, for all the external links of your website posts or …

20 active installs v1.0.0 PHP + WP 3.5.1+ Updated Feb 25, 2015
external-linknofollowreltarget
85
A · Safe
CVEs total0
Unpatched0
Last CVENever
Safety Verdict

Is Nofollow for External Link TAP Safe to Use in 2026?

Generally Safe

Score 85/100

Nofollow for External Link TAP has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.

No known CVEs Updated 11yr ago
Risk Assessment

The "nofollow-for-external-link-tap" v1.0.0 plugin exhibits a strong initial security posture based on the provided static analysis. The plugin has no identified attack surface entries, no dangerous function usage, no file operations, and no external HTTP requests, which are all positive indicators. The output escaping is also fully implemented, and there are no recorded vulnerabilities or CVEs associated with this plugin. This suggests a well-developed and secure piece of code with no immediately obvious exploitable flaws.

However, the lack of explicit capability checks and nonce checks on AJAX handlers or REST API routes (even though there are none currently) represents a potential future risk if the plugin were to be expanded. While the SQL queries use prepared statements for half of their occurrences, this still leaves a portion potentially open to injection if not handled with extreme care. The absence of taint analysis results could mean that either no sensitive data flows were identified or the analysis was not comprehensive enough to detect them. Given the lack of identified vulnerabilities, the plugin's current security seems robust, but future development should prioritize implementing thorough authentication and authorization checks for any new entry points.

In conclusion, "nofollow-for-external-link-tap" v1.0.0 currently appears to be a secure plugin with no known vulnerabilities and good coding practices observed in the static analysis. The strengths lie in its minimal attack surface and proper output escaping. The main weakness, though not currently exploitable, is the absence of explicit authorization checks, which is a foundational security practice for any WordPress plugin. Users can likely feel confident in its current state, but developers should be mindful of adding these checks if extending functionality.

Key Concerns

  • SQL queries not fully using prepared statements
  • Missing capability checks
  • Missing nonce checks
Vulnerabilities
None known

Nofollow for External Link TAP Security Vulnerabilities

No known vulnerabilities — this is a good sign.
Version History

Nofollow for External Link TAP Release Timeline

v1.0.0Current
Code Analysis
Analyzed Mar 16, 2026

Nofollow for External Link TAP Code Analysis

Dangerous Functions
0
Raw SQL Queries
1
1 prepared
Unescaped Output
0
2 escaped
Nonce Checks
0
Capability Checks
0
File Operations
0
External Requests
0
Bundled Libraries
0

SQL Query Safety

50% prepared2 total queries

Output Escaping

100% escaped2 total outputs
Attack Surface

Nofollow for External Link TAP Attack Surface

Entry Points0
Unprotected0
WordPress Hooks 9
actionadmin_enqueue_scriptsadmin\class-nfel-tap-admin.php:73
actionadmin_enqueue_scriptsadmin\class-nfel-tap-admin.php:74
actionadmin_menuadmin\class-nfel-tap-admin.php:77
action@TODOadmin\class-nfel-tap-admin.php:89
filter@TODOadmin\class-nfel-tap-admin.php:90
actionplugins_loadednfel-tap.php:64
actioninitpublic\class-nfel-tap.php:69
actionwpmu_new_blogpublic\class-nfel-tap.php:72
filterthe_contentpublic\class-nfel-tap.php:82
Maintenance & Trust

Nofollow for External Link TAP Maintenance & Trust

Maintenance Signals

WordPress version tested4.1.42
Last updatedFeb 25, 2015
PHP min version
Downloads3K

Community Trust

Rating100/100
Number of ratings1
Active installs20
Developer Profile

Nofollow for External Link TAP Developer Profile

todoapuestas

5 plugins · 80 total installs

84
trust score
Avg Security Score
85/100
Avg Patch Time
30 days
View full developer profile
Detection Fingerprints

How We Detect Nofollow for External Link TAP

Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.

Asset Fingerprints

Asset Paths
/wp-content/plugins/nofollow-for-external-link-tap/assets/css/admin.css/wp-content/plugins/nofollow-for-external-link-tap/assets/js/admin.js
Version Parameters
nofollow-for-external-link-tap/assets/css/admin.css?ver=nofollow-for-external-link-tap/assets/js/admin.js?ver=

HTML / DOM Fingerprints

FAQ

Frequently Asked Questions about Nofollow for External Link TAP