
WP Better SEO Links Security & Risk Analysis
wordpress.org/plugins/wp-better-seo-linksAdds a checkbox in the insert link popup box for including rel="nofollow", rel="sponsored", and rel="ugc" in links as yo …
Is WP Better SEO Links Safe to Use in 2026?
Generally Safe
Score 85/100WP Better SEO Links has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.
The plugin "wp-better-seo-links" v1.0 exhibits a very limited attack surface, with no identified AJAX handlers, REST API routes, shortcodes, or cron events. This absence of direct entry points is a positive security indicator. Furthermore, the code analysis shows no dangerous functions, no file operations, no external HTTP requests, and all SQL queries utilize prepared statements, which are strong security practices. The lack of any known CVEs in its history also suggests a stable and potentially secure plugin.
However, a significant concern arises from the output escaping. With 9 total outputs and 0% properly escaped, this indicates a high risk of Cross-Site Scripting (XSS) vulnerabilities. Any data rendered by the plugin that is not sanitized could be exploited by attackers to inject malicious scripts into the website. The absence of nonce and capability checks, while not directly exploitable due to the lack of other entry points, suggests that if any new entry points were introduced or if existing ones were overlooked in the analysis, the plugin would lack fundamental authorization and validation mechanisms.
In conclusion, while the plugin's minimal attack surface and good SQL practices are commendable, the complete lack of output escaping presents a critical security weakness that could lead to XSS vulnerabilities. The absence of nonce and capability checks, though less immediately concerning in this specific version, points to a potential lack of defensive depth. The overall security posture is therefore mixed, with a potentially exploitable flaw overshadowing the otherwise clean analysis.
Key Concerns
- 0% output escaping
- Missing nonce checks
- Missing capability checks
WP Better SEO Links Security Vulnerabilities
WP Better SEO Links Code Analysis
Output Escaping
WP Better SEO Links Attack Surface
WordPress Hooks 8
Maintenance & Trust
WP Better SEO Links Maintenance & Trust
Maintenance Signals
Community Trust
WP Better SEO Links Alternatives
Title and Nofollow For Links (Classic Editor)
title-and-nofollow-for-links
The plugin adds a title and a rel="nofollow" checkbox to the insert link popup box. Only for Classic Editor, NOT Block Editor.
External Links Modifier
external-links-modifier
External Links Modifier automatically updates external links in your posts to open in a new tab with rel="nofollow noreferrer".
External Links – nofollow, noopener & new window
wp-external-links
Internal links & external links manager: open in new window or tab, control nofollow, ugc, sponsored & noopener. SEO friendly.
External Links
sem-external-links
The external links plugin for WordPress lets you process outgoing links differently from internal links.
NoFollow Link
nofollow-link
NoFollow Link adds a button to the post editor to add nofollow attribute to any links in the post.
WP Better SEO Links Developer Profile
1 plugin · 100 total installs
How We Detect WP Better SEO Links
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
HTML / DOM Fingerprints
<!-- Ultimate Nofollow Plugin | shortcode insertion failed | given href resource not valid, href must begin with: name="itswphelp_item[nofollow_comments]"name="itswphelp_item[nofollow_blogroll]"name="itswphelp_blogroll_nofollow_checkbox"name="itswphelp_blogroll_sponsored_checkbox"<a href= rel="nofollow">