WP Nofollow Categories Security & Risk Analysis

wordpress.org/plugins/wp-nofollow-categories

Nofollows category links across the site. Adds Noindex to category pages.

70 active installs v0.1.3 PHP + WP 2.3+ Updated Dec 22, 2014
postseo
85
A · Safe
CVEs total0
Unpatched0
Last CVENever
Safety Verdict

Is WP Nofollow Categories Safe to Use in 2026?

Generally Safe

Score 85/100

WP Nofollow Categories has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.

No known CVEs Updated 11yr ago
Risk Assessment

The "wp-nofollow-categories" v0.1.3 plugin exhibits an excellent security posture based on the provided static analysis. The plugin demonstrates a commitment to secure coding practices by having zero identified dangerous functions, zero SQL queries that are not prepared statements, and all output is properly escaped. Furthermore, the absence of file operations, external HTTP requests, and a lack of bundled libraries contribute to a reduced attack surface and fewer potential points of compromise. The comprehensive analysis shows no taint flows, indicating that user-supplied data is not being mishandled in a way that could lead to vulnerabilities.

The vulnerability history is also pristine, with zero known CVEs and no recorded common vulnerability types. This lack of past issues, coupled with the current clean static analysis, suggests a well-maintained and secure codebase. However, the total absence of entry points such as AJAX handlers, REST API routes, shortcodes, and cron events, while good for security in its own right, also implies a limited functionality or a plugin that operates entirely through other means (e.g., filters, hooks called by other plugins/themes). The absence of capability checks and nonce checks, while not explicitly identified as a risk due to the lack of entry points, would become a significant concern if any entry points were introduced without them.

In conclusion, based on the provided data, "wp-nofollow-categories" v0.1.3 appears to be a highly secure plugin. Its strengths lie in its clean code, absence of vulnerabilities, and adherence to best practices like prepared statements and output escaping. The primary area to monitor, should the plugin evolve and introduce new features, would be the implementation of proper authentication and authorization checks for any new entry points.

Vulnerabilities
None known

WP Nofollow Categories Security Vulnerabilities

No known vulnerabilities — this is a good sign.
Code Analysis
Analyzed Mar 16, 2026

WP Nofollow Categories Code Analysis

Dangerous Functions
0
Raw SQL Queries
0
0 prepared
Unescaped Output
0
0 escaped
Nonce Checks
0
Capability Checks
0
File Operations
0
External Requests
0
Bundled Libraries
0
Attack Surface

WP Nofollow Categories Attack Surface

Entry Points0
Unprotected0
WordPress Hooks 3
filterwp_list_categorieswp-nofollow-cat.php:18
filterthe_categorywp-nofollow-cat.php:19
actionwp_headwp-nofollow-cat.php:45
Maintenance & Trust

WP Nofollow Categories Maintenance & Trust

Maintenance Signals

WordPress version tested4.2.39
Last updatedDec 22, 2014
PHP min version
Downloads8K

Community Trust

Rating0/100
Number of ratings0
Active installs70
Developer Profile

WP Nofollow Categories Developer Profile

Vladimir Prelovac

20 plugins · 1.0M total installs

70
trust score
Avg Security Score
87/100
Avg Patch Time
2577 days
View full developer profile
Detection Fingerprints

How We Detect WP Nofollow Categories

Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.

Asset Fingerprints

HTML / DOM Fingerprints

HTML Comments
<!-- wp-nofollow-categories --><!-- /wp-nofollow-categories -->
Data Attributes
rel="nofollow"
FAQ

Frequently Asked Questions about WP Nofollow Categories