
Nofollow Links in Posts Security & Risk Analysis
wordpress.org/plugins/nofollow-links-in-postsAdds the rel="nofollow" to links in posts within a selected category. Useful for sponsored posts.
Is Nofollow Links in Posts Safe to Use in 2026?
Generally Safe
Score 85/100Nofollow Links in Posts has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.
The nofollow-links-in-posts plugin v1.1.1 exhibits a concerning security posture despite having no recorded historical vulnerabilities or critical taint analysis findings. The static analysis reveals significant weaknesses, most notably the presence of three instances of the `unserialize` function, which is notoriously dangerous if used with untrusted input. Compounding this, 100% of its output is not properly escaped, meaning any data processed by the plugin could be rendered in a way that leads to cross-site scripting (XSS) vulnerabilities. The lack of any authorization checks on entry points, while the attack surface appears minimal at 0, still leaves room for potential issues if functionality is added later without proper checks.
While the plugin has no known CVEs and uses prepared statements for its SQL queries, these strengths are overshadowed by the critical risks introduced by `unserialize` and unescaped output. The absence of vulnerability history is a positive sign, but it does not negate the inherent dangers identified in the current codebase. The plugin's strengths lie in its adherence to prepared statements and lack of external dependencies or file operations. However, the identified code signals present immediate and severe risks that require attention before this plugin can be considered secure.
Key Concerns
- Presence of dangerous unserialize function
- 100% of output not properly escaped
- 0 unprotected entry points (potential future risk)
Nofollow Links in Posts Security Vulnerabilities
Nofollow Links in Posts Release Timeline
Nofollow Links in Posts Code Analysis
Dangerous Functions Found
Output Escaping
Data Flow Analysis
Nofollow Links in Posts Attack Surface
WordPress Hooks 7
Maintenance & Trust
Nofollow Links in Posts Maintenance & Trust
Maintenance Signals
Community Trust
Nofollow Links in Posts Alternatives
NoLiP – Nofollow Links in Posts Reborn
nolip-nofollow-links-in-posts-reborn
Adds the rel="nofollow" to links in posts within a selected category. Useful for sponsored posts.
MWW Disclaimer Buttons
mww-disclaimer-buttons
The FTC requires that you put disclosures at the top of your post if you were compensated in any way (affiliate links, free products, or payment).
Affiliate Link Marker
affiliate-link-marker
Mark your Affiliate Links with a *, add rel="nofollow sponsored noopener" to affiliate links and attach a disclosure at the end of e …
External Links – nofollow, noopener & new window
wp-external-links
Internal links & external links manager: open in new window or tab, control nofollow, ugc, sponsored & noopener. SEO friendly.
RaraTheme Companion
raratheme-companion
23 extremely useful custom widgets to create an engaging website.
Nofollow Links in Posts Developer Profile
1 plugin · 10 total installs
How We Detect Nofollow Links in Posts
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/nofollow-links-in-posts/css/style.cssnofollow-links-in-posts/css/style.css?ver=