NoFollow jQuery Links Security & Risk Analysis

wordpress.org/plugins/nofollow-jquery-links

A simple TinyMCE Plugin to add a js link solution for linking pages together in order to stop search engines crawlers going through those pages.

0 active installs v1.5.3 PHP 5.2.4+ WP 4.6+ Updated Jul 26, 2024
crawlinternal-linkingjquerylink-juiceseo
92
A · Safe
CVEs total0
Unpatched0
Last CVENever
Safety Verdict

Is NoFollow jQuery Links Safe to Use in 2026?

Generally Safe

Score 92/100

NoFollow jQuery Links has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.

No known CVEs Updated 1yr ago
Risk Assessment

The "nofollow-jquery-links" plugin v1.5.3 exhibits a strong security posture based on the provided static analysis. The absence of any identified entry points like AJAX handlers, REST API routes, shortcodes, or cron events significantly limits its attack surface. Furthermore, the code demonstrates good practices by using prepared statements for all SQL queries and ensuring 100% output escaping, which prevents common injection vulnerabilities. The lack of file operations and external HTTP requests also reduces potential exposure. The plugin does implement capability checks, which is a positive sign for privilege escalation prevention. However, the complete absence of taint analysis flows, while seemingly positive, could also indicate a very limited scope of analysis performed or a plugin that has minimal data processing, making it difficult to assess risks related to data handling. The vulnerability history being entirely clear is a significant strength, suggesting a well-maintained and secure codebase over time. Overall, the plugin appears robust with no immediate exploitable vulnerabilities identified in the static analysis. The main weakness is the potential lack of comprehensive taint analysis due to zero flows, which might hide subtle data handling risks if the plugin were to evolve. The bundled Freemius library at v1.0, while not explicitly flagged as a vulnerability, could represent a potential risk if it contains known vulnerabilities in its outdated version and is not maintained independently.

Key Concerns

  • Bundled Freemius v1.0 library is outdated
Vulnerabilities
None known

NoFollow jQuery Links Security Vulnerabilities

No known vulnerabilities — this is a good sign.
Code Analysis
Analyzed Mar 17, 2026

NoFollow jQuery Links Code Analysis

Dangerous Functions
0
Raw SQL Queries
0
0 prepared
Unescaped Output
0
0 escaped
Nonce Checks
0
Capability Checks
2
File Operations
0
External Requests
0
Bundled Libraries
1

Bundled Libraries

Freemius1.0
Attack Surface

NoFollow jQuery Links Attack Surface

Entry Points0
Unprotected0
WordPress Hooks 4
actioninitnex-tm-jslink.php:51
actionwp_enqueue_scriptsnex-tm-jslink.php:53
filtermce_external_pluginsnex-tm-jslink.php:75
filtermce_buttonsnex-tm-jslink.php:76
Maintenance & Trust

NoFollow jQuery Links Maintenance & Trust

Maintenance Signals

WordPress version tested6.6.5
Last updatedJul 26, 2024
PHP min version5.2.4
Downloads2K

Community Trust

Rating0/100
Number of ratings0
Active installs0
Developer Profile

NoFollow jQuery Links Developer Profile

nexist

1 plugin · 0 total installs

88
trust score
Avg Security Score
92/100
Avg Patch Time
30 days
View full developer profile
Detection Fingerprints

How We Detect NoFollow jQuery Links

Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.

Asset Fingerprints

Asset Paths
/wp-content/plugins/nofollow-jquery-links/nex-tm-jslink.js/wp-content/plugins/nofollow-jquery-links/jslink-onclick.js
Script Paths
/wp-content/plugins/nofollow-jquery-links/nex-tm-jslink.js/wp-content/plugins/nofollow-jquery-links/jslink-onclick.js

HTML / DOM Fingerprints

Shortcode Output
<div></div>
FAQ

Frequently Asked Questions about NoFollow jQuery Links