External Links in New Window / New Tab Security & Risk Analysis

wordpress.org/plugins/open-external-links-in-a-new-window

Open external links in a new window or new tab. SEO optimized and XHTML Strict compliant.

30K active installs v1.45 PHP 5.2+ WP 4.0+ Updated Dec 3, 2025
external-linkslinksnew-tabnew-windowtarget-blank
99
A · Safe
CVEs total2
Unpatched0
Last CVEMay 9, 2022
Safety Verdict

Is External Links in New Window / New Tab Safe to Use in 2026?

Generally Safe

Score 99/100

External Links in New Window / New Tab has a strong security track record. Known vulnerabilities have been patched promptly.

2 known CVEsLast CVE: May 9, 2022Updated 4mo ago
Risk Assessment

The 'open-external-links-in-a-new-window' plugin version 1.45 exhibits a strong security posture in its static analysis. It has zero identified entry points that are unprotected, no dangerous functions, and all SQL queries are properly prepared. Furthermore, all output is correctly escaped, and there are no file operations or external HTTP requests, suggesting a clean and contained codebase. The absence of any taint analysis findings reinforces this positive assessment, indicating no identifiable vulnerabilities in data handling or execution flows.

However, the plugin's vulnerability history presents a significant concern. With a total of two known CVEs, both of medium severity, and a last vulnerability reported in May 2022, the plugin has a track record of security issues. The common vulnerability types noted (Cross-site Scripting and issues with `window.opener`) suggest potential risks related to user input processing and how links are handled, even if the current static analysis doesn't flag them. The fact that these past vulnerabilities were eventually patched is a positive sign, but the existence of prior medium-severity flaws warrants caution.

In conclusion, while the current version of the plugin appears robust based on static analysis, its past security incidents indicate a need for ongoing vigilance. Users should ensure they are running the latest available version and remain aware of any new advisories. The plugin's strengths lie in its well-contained code and adherence to secure coding practices in its current iteration, but its historical medium-severity vulnerabilities present a notable weakness.

Key Concerns

  • Past medium severity CVEs exist
  • Vulnerabilities related to window.opener and XSS
Vulnerabilities
2

External Links in New Window / New Tab Security Vulnerabilities

CVEs by Year

2 CVEs in 2022
2022
Patched Has unpatched

Severity Breakdown

Medium
2

2 total CVEs

CVE-2022-1582medium · 6.1Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')

External Links in New Window / New Tab <= 1.42 - Unauthenticated Stored Cross-Site Scripting

May 9, 2022 Patched in 1.43 (624d)
CVE-2022-1583medium · 6.5Use of Web Link to Untrusted Target with window.opener Access

External Links in New Window / New Tab <= 1.42 - Tabnabbing

May 9, 2022 Patched in 1.43 (624d)
Code Analysis
Analyzed Mar 16, 2026

External Links in New Window / New Tab Code Analysis

Dangerous Functions
0
Raw SQL Queries
0
0 prepared
Unescaped Output
0
9 escaped
Nonce Checks
0
Capability Checks
0
File Operations
0
External Requests
0
Bundled Libraries
0

Output Escaping

100% escaped9 total outputs
Attack Surface

External Links in New Window / New Tab Attack Surface

Entry Points0
Unprotected0
WordPress Hooks 10
actionwp_headopen-external-links-in-a-new-window.php:41
actionadmin_menuopen-external-links-in-a-new-window.php:127
actionadmin_initopen-external-links-in-a-new-window.php:136
filterplugin_action_linksopen-external-links-in-a-new-window.php:188
filtersafe_style_cssopen-external-links-in-a-new-window.php:192
filtersafe_style_cssopen-external-links-in-a-new-window.php:424
actionadmin_initwf-flyout\wf-flyout.php:27
actionadmin_enqueue_scriptswf-flyout\wf-flyout.php:73
actionadmin_headwf-flyout\wf-flyout.php:74
actionadmin_footerwf-flyout\wf-flyout.php:75
Maintenance & Trust

External Links in New Window / New Tab Maintenance & Trust

Maintenance Signals

WordPress version tested6.9.4
Last updatedDec 3, 2025
PHP min version5.2
Downloads488K

Community Trust

Rating90/100
Number of ratings77
Active installs30K
Developer Profile

External Links in New Window / New Tab Developer Profile

WebFactory

28 plugins · 3.5M total installs

78
trust score
Avg Security Score
98/100
Avg Patch Time
699 days
View full developer profile
Detection Fingerprints

How We Detect External Links in New Window / New Tab

Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.

Asset Fingerprints

Script Paths
/wp-content/plugins/open-external-links-in-a-new-window/open-external-links-in-a-new-window.php

HTML / DOM Fingerprints

Data Attributes
external_links_in_new_windows_forceexternal_links_in_new_windows_ignore
JS Globals
external_links_in_new_windows_loopexternal_links_in_new_windows_load
FAQ

Frequently Asked Questions about External Links in New Window / New Tab