
External Links in New Window / New Tab Security & Risk Analysis
wordpress.org/plugins/open-external-links-in-a-new-windowOpen external links in a new window or new tab. SEO optimized and XHTML Strict compliant.
Is External Links in New Window / New Tab Safe to Use in 2026?
Generally Safe
Score 99/100External Links in New Window / New Tab has a strong security track record. Known vulnerabilities have been patched promptly.
The 'open-external-links-in-a-new-window' plugin version 1.45 exhibits a strong security posture in its static analysis. It has zero identified entry points that are unprotected, no dangerous functions, and all SQL queries are properly prepared. Furthermore, all output is correctly escaped, and there are no file operations or external HTTP requests, suggesting a clean and contained codebase. The absence of any taint analysis findings reinforces this positive assessment, indicating no identifiable vulnerabilities in data handling or execution flows.
However, the plugin's vulnerability history presents a significant concern. With a total of two known CVEs, both of medium severity, and a last vulnerability reported in May 2022, the plugin has a track record of security issues. The common vulnerability types noted (Cross-site Scripting and issues with `window.opener`) suggest potential risks related to user input processing and how links are handled, even if the current static analysis doesn't flag them. The fact that these past vulnerabilities were eventually patched is a positive sign, but the existence of prior medium-severity flaws warrants caution.
In conclusion, while the current version of the plugin appears robust based on static analysis, its past security incidents indicate a need for ongoing vigilance. Users should ensure they are running the latest available version and remain aware of any new advisories. The plugin's strengths lie in its well-contained code and adherence to secure coding practices in its current iteration, but its historical medium-severity vulnerabilities present a notable weakness.
Key Concerns
- Past medium severity CVEs exist
- Vulnerabilities related to window.opener and XSS
External Links in New Window / New Tab Security Vulnerabilities
CVEs by Year
Severity Breakdown
2 total CVEs
External Links in New Window / New Tab <= 1.42 - Unauthenticated Stored Cross-Site Scripting
External Links in New Window / New Tab <= 1.42 - Tabnabbing
External Links in New Window / New Tab Code Analysis
Output Escaping
External Links in New Window / New Tab Attack Surface
WordPress Hooks 10
Maintenance & Trust
External Links in New Window / New Tab Maintenance & Trust
Maintenance Signals
Community Trust
External Links in New Window / New Tab Alternatives
Open Links In New Tab
open-links-in-new-tab
Opens external links and internal links in a new window depending on user settings. Manage all external & internal links on your site.
External Links – nofollow, noopener & new window
wp-external-links
Internal links & external links manager: open in new window or tab, control nofollow, ugc, sponsored & noopener. SEO friendly.
Daisy Links – open links in new tab, add nofollow attribute, disable right click on links
daisy-links
Manage external links effortlessly! open links in new tab, add nofollow attribute, disable right click on links.
External Links Manager – Open new window in a new tab + nofollow, noreferrer
smart-external-links-manager
Manage external links: new tabs, add rel attribute nofollow, noopener, noreferrer, sponsored, show icon on/off. SEO, secure, XHTML Strict compliant.
Affiliatize Me
affiliatize-me
Make all your links affiliate links.
External Links in New Window / New Tab Developer Profile
28 plugins · 3.5M total installs
How We Detect External Links in New Window / New Tab
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/open-external-links-in-a-new-window/open-external-links-in-a-new-window.phpHTML / DOM Fingerprints
external_links_in_new_windows_forceexternal_links_in_new_windows_ignoreexternal_links_in_new_windows_loopexternal_links_in_new_windows_load