
Nofollow for External Link TAP Security & Risk Analysis
wordpress.org/plugins/nofollow-for-external-link-tapJust simple, if you use this plugins, rel=nofollow and target=_blank will be insert automatically, for all the external links of your website posts or …
Is Nofollow for External Link TAP Safe to Use in 2026?
Generally Safe
Score 85/100Nofollow for External Link TAP has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.
The "nofollow-for-external-link-tap" v1.0.0 plugin exhibits a strong initial security posture based on the provided static analysis. The plugin has no identified attack surface entries, no dangerous function usage, no file operations, and no external HTTP requests, which are all positive indicators. The output escaping is also fully implemented, and there are no recorded vulnerabilities or CVEs associated with this plugin. This suggests a well-developed and secure piece of code with no immediately obvious exploitable flaws.
However, the lack of explicit capability checks and nonce checks on AJAX handlers or REST API routes (even though there are none currently) represents a potential future risk if the plugin were to be expanded. While the SQL queries use prepared statements for half of their occurrences, this still leaves a portion potentially open to injection if not handled with extreme care. The absence of taint analysis results could mean that either no sensitive data flows were identified or the analysis was not comprehensive enough to detect them. Given the lack of identified vulnerabilities, the plugin's current security seems robust, but future development should prioritize implementing thorough authentication and authorization checks for any new entry points.
In conclusion, "nofollow-for-external-link-tap" v1.0.0 currently appears to be a secure plugin with no known vulnerabilities and good coding practices observed in the static analysis. The strengths lie in its minimal attack surface and proper output escaping. The main weakness, though not currently exploitable, is the absence of explicit authorization checks, which is a foundational security practice for any WordPress plugin. Users can likely feel confident in its current state, but developers should be mindful of adding these checks if extending functionality.
Key Concerns
- SQL queries not fully using prepared statements
- Missing capability checks
- Missing nonce checks
Nofollow for External Link TAP Security Vulnerabilities
Nofollow for External Link TAP Release Timeline
Nofollow for External Link TAP Code Analysis
SQL Query Safety
Output Escaping
Nofollow for External Link TAP Attack Surface
WordPress Hooks 9
Maintenance & Trust
Nofollow for External Link TAP Maintenance & Trust
Maintenance Signals
Community Trust
Nofollow for External Link TAP Alternatives
External Links
sem-external-links
The external links plugin for WordPress lets you process outgoing links differently from internal links.
NoFollowr
nofollowr
Browsing a site as an admin, icons are added to external links indicating their nofollow status. Clicking the icons toggles nofollow status via Ajax.
External & Affiliate Links Processor
external-links-nofollow-open-in-new-tab-favicon
Process outbound (external) links to make useful changes, including adding affiliate ID tags, rel=nofollow or target=_blank attributes, and adding ico …
Daisy Links – open links in new tab, add nofollow attribute, disable right click on links
daisy-links
Manage external links effortlessly! open links in new tab, add nofollow attribute, disable right click on links.
Nofollow External Link
nofollow-external-link
Insert 'rel=nofollow' and 'target=_blank' to all the external links automatically into your website posts or pages.
Nofollow for External Link TAP Developer Profile
5 plugins · 80 total installs
How We Detect Nofollow for External Link TAP
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/nofollow-for-external-link-tap/assets/css/admin.css/wp-content/plugins/nofollow-for-external-link-tap/assets/js/admin.jsnofollow-for-external-link-tap/assets/css/admin.css?ver=nofollow-for-external-link-tap/assets/js/admin.js?ver=