
NoLiP – Nofollow Links in Posts Reborn Security & Risk Analysis
wordpress.org/plugins/nolip-nofollow-links-in-posts-rebornAdds the rel="nofollow" to links in posts within a selected category. Useful for sponsored posts.
Is NoLiP – Nofollow Links in Posts Reborn Safe to Use in 2026?
Generally Safe
Score 85/100NoLiP – Nofollow Links in Posts Reborn has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.
The nolip-nofollow-links-in-posts-reborn plugin v2.0 exhibits a mixed security posture. While it demonstrates good practices by avoiding SQL injection through prepared statements, having no file operations, and no external HTTP requests, several critical concerns are present. The plugin utilizes the `unserialize` function three times, which is a known vector for remote code execution if attacker-controlled data is passed to it. Additionally, 100% of its output is not properly escaped, creating a significant risk of cross-site scripting (XSS) vulnerabilities. The taint analysis reveals two flows with unsanitized paths, though they are not classified as critical or high severity in this report, they still indicate potential areas where malicious input could lead to unexpected behavior or exploits. The plugin's vulnerability history is clean, with no recorded CVEs, which is a positive sign. However, the presence of dangerous functions and unescaped output, coupled with the taint analysis findings, suggests that the clean history may be due to limited exposure or an incomplete analysis rather than inherent robust security. The absence of any attack surface entry points like AJAX handlers, REST API routes, or shortcodes is a strength, but it also means the security of the `unserialize` function and output handling is paramount and currently deficient.
Key Concerns
- Dangerous function: unserialize usage
- Unescaped output detected
- Taint flow with unsanitized path
- Taint flow with unsanitized path
NoLiP – Nofollow Links in Posts Reborn Security Vulnerabilities
NoLiP – Nofollow Links in Posts Reborn Code Analysis
Dangerous Functions Found
Output Escaping
Data Flow Analysis
NoLiP – Nofollow Links in Posts Reborn Attack Surface
WordPress Hooks 7
Maintenance & Trust
NoLiP – Nofollow Links in Posts Reborn Maintenance & Trust
Maintenance Signals
Community Trust
NoLiP – Nofollow Links in Posts Reborn Alternatives
MWW Disclaimer Buttons
mww-disclaimer-buttons
The FTC requires that you put disclosures at the top of your post if you were compensated in any way (affiliate links, free products, or payment).
Affiliate Link Marker
affiliate-link-marker
Mark your Affiliate Links with a *, add rel="nofollow sponsored noopener" to affiliate links and attach a disclosure at the end of e …
External Links – nofollow, noopener & new window
wp-external-links
Internal links & external links manager: open in new window or tab, control nofollow, ugc, sponsored & noopener. SEO friendly.
RaraTheme Companion
raratheme-companion
23 extremely useful custom widgets to create an engaging website.
External Links
sem-external-links
The external links plugin for WordPress lets you process outgoing links differently from internal links.
NoLiP – Nofollow Links in Posts Reborn Developer Profile
1 plugin · 10 total installs
How We Detect NoLiP – Nofollow Links in Posts Reborn
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/nolip-nofollow-links-in-posts-reborn/nolip.php