Free tools Windows power users keep installed

One-click scans. No signup required.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

rel="noopener" prevents a page opened from a link from receiving a JavaScript reference back to the page that opened it. It matters most with links using target="_blank", because it blocks the destination from using window.opener to manipulate the original page. It does not, by itself, hide the referring page from the destination.

What rel="noopener" does

When a link opens a new tab or window, the new page can ordinarily receive a window.opener reference to the page that launched it. The noopener link relation tells the browser not to provide that reference; the opened page sees window.opener as null. This helps prevent reverse-tabnabbing-style attacks, in which a destination page attempts to change the original page’s location.

For example, a link can explicitly request opener isolation like this:

<a href="https://example.com" target="_blank" rel="noopener">Example</a>

The HTML standard’s behavior is documented by MDN’s noopener reference. The relation is also defined for <area> and <form> elements, not just links.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

Do you need noopener with target="_blank"?

In modern browsers, using target="_blank" on an <a>, <area>, or <form> implicitly provides noopener behavior, according to MDN. Adding rel="noopener" explicitly can still make the intended security behavior clear in the markup and is useful when you want the code to state that intention directly.

That protection is about the relationship between the new browsing context and the opener page. It does not prevent every kind of malicious behavior on the destination site, and it does not control whether a new tab opens; that comes from target="_blank".

noopener vs. noreferrer

noreferrer has a distinct privacy effect: it tells the browser to omit the HTTP Referer header when navigating to the destination. It also behaves as though noopener were specified. MDN documents that distinction in its noreferrer reference.

Attribute value Opener access Referrer information When it fits
noopener The destination does not receive a window.opener reference. Does not specifically request suppression of the Referer header. Use when you want opener isolation without the extra referrer suppression.
noreferrer noopener The destination does not receive a window.opener reference. The browser omits the Referer header. Use when you also intend to withhold referrer information.

Choose noreferrer deliberately: omitting the referrer can affect analytics or other destination-side attribution. Do not treat noopener as a referrer-hiding feature.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

Why WordPress may add or change the attribute

WordPress link markup has varied over time. A Gutenberg update published by Make WordPress Core on May 4, 2018 listed adding ref="noreferrer noopener" for links with target="_blank" (Gutenberg update, May 4, 2018). A WordPress Core developer-chat summary dated October 18, 2023 records discussion of ticket #53843, “Remove adding of rel=”noopener” to links with target=”_blank”” (Core chat summary, October 18, 2023).

Those records describe changes and discussion, not a rule that every WordPress release behaves identically. The editor, WordPress version, theme, plugins, or filters may affect the final HTML. If you need to know what a particular published link does, check the rendered output rather than assuming WordPress always adds or removes an attribute.

How to check a WordPress link’s rendered markup

  1. Open the page or post in the WordPress editor and select the link in its block. Check the link settings for the option to open it in a new tab; the exact control can vary by editor version.
  2. If the link is in a Custom HTML block, inspect the anchor markup directly. For a new-tab link with explicit opener isolation, the relevant pattern is target="_blank" rel="noopener".
  3. Save or publish the page, then open the public page and inspect its rendered HTML or DOM using your browser’s developer tools. Confirm the actual target and rel values.
  4. If the rendered attributes differ from what you entered, check whether the theme, an SEO or security plugin, or a link-rewriting filter modifies them.
Independent reader supportYour contribution helps us test, update, and keep practical guides available for everyone.Support on Ko-Fi

Should external links open in a new tab?

noopener addresses opener access; it does not make opening a new tab the right choice for every link. A new tab can surprise readers, change their navigation flow, and make the Back button behave differently than expected. When a link does open a new tab or window, make that outcome clear in the link text or an accessible label. MDN’s guidance on noopener notes the need to inform users about links that open a new browsing context, and WordPress Core discussion has also cautioned about the effect of target="_blank" on reader control (Core chat summary, October 18, 2023).

Product prices and availability are accurate as of the date/time indicated and are subject to change. Any price and availability information displayed on Amazon at the time of purchase will apply.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.