
Open in New Window Plugin Security & Risk Analysis
wordpress.org/plugins/open-in-new-window-pluginOpens external links in a new window, keeping your blog page in the browser so you don't lose surfers to another site.
Is Open in New Window Plugin Safe to Use in 2026?
Generally Safe
Score 92/100Open in New Window Plugin has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.
The "open-in-new-window-plugin" v3.0 exhibits a strong security posture in several key areas. The absence of any identified CVEs, coupled with a clean vulnerability history, suggests a generally well-maintained and secure plugin. The static analysis also reveals a commendable lack of dangerous functions, SQL injection risks (all queries use prepared statements), and file operation vulnerabilities. Furthermore, the plugin demonstrates an awareness of security best practices by including nonce and capability checks. The attack surface appears to be minimal, with no identified entry points that are unprotected.
However, a significant concern arises from the output escaping. With 100% of outputs not properly escaped, this presents a notable risk of cross-site scripting (XSS) vulnerabilities. While the taint analysis did not reveal any unsanitized flows, the lack of output escaping means that any user-supplied data that is later displayed could be exploited. This is a critical oversight that needs immediate attention, as XSS can lead to session hijacking, defacement, and other malicious activities.
In conclusion, the plugin has a solid foundation with its minimal attack surface and robust handling of SQL and other potential code risks. The lack of past vulnerabilities is a positive indicator. Nevertheless, the pervasive issue of unescaped output is a serious weakness that significantly lowers its overall security rating and requires urgent remediation to prevent potential XSS attacks.
Key Concerns
- Unescaped output detected
Open in New Window Plugin Security Vulnerabilities
Open in New Window Plugin Release Timeline
Open in New Window Plugin Code Analysis
Output Escaping
Data Flow Analysis
Open in New Window Plugin Attack Surface
WordPress Hooks 2
Maintenance & Trust
Open in New Window Plugin Maintenance & Trust
Maintenance Signals
Community Trust
Open in New Window Plugin Alternatives
External Links – nofollow, noopener & new window
wp-external-links
Internal links & external links manager: open in new window or tab, control nofollow, ugc, sponsored & noopener. SEO friendly.
Open Links In New Tab
open-links-in-new-tab
Opens external links and internal links in a new window depending on user settings. Manage all external & internal links on your site.
WP Open Comment Links in New Window
wp-open-comment-links-in-new-window
Opens all the links (URLs) added in the comments and author URL, in a new tab or window.
Open External Links In New Windows
open-external-links-in-new-window
Opens external links (those to other websites outside of your own domain, eg., Facebook, Twitter, etc) in new windows.
External Links Manager – Open new window in a new tab + nofollow, noreferrer
smart-external-links-manager
Manage external links: new tabs, add rel attribute nofollow, noopener, noreferrer, sponsored, show icon on/off. SEO, secure, XHTML Strict compliant.
Open in New Window Plugin Developer Profile
2 plugins · 2K total installs
How We Detect Open in New Window Plugin
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/open-in-new-window-plugin/open_in_new_window_no.js/wp-content/plugins/open-in-new-window-plugin/open_in_new_window_yes.js/wp-content/plugins/open-in-new-window-plugin/open_in_new_window.jsopen_in_new_window_no.jsopen_in_new_window_yes.jsopen_in_new_window.js