Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

To open a link in a new browsing context from PHP, output an HTML anchor with target="_blank". PHP generates the markup; the browser interprets the attribute and decides whether the new context appears as a tab or a window. For example:

<?php
$url = '/destination';
$label = 'Open destination';
?>
<a href="<?= htmlspecialchars($url, ENT_QUOTES, 'UTF-8') ?>"
   target="_blank" rel="noopener">
  <?= htmlspecialchars($label, ENT_QUOTES, 'UTF-8') ?> (opens in a new tab or window)
</a>

What target=”_blank” does in PHP

The attribute belongs on the HTML <a> element that PHP sends to the browser. It requests that the destination open in a new browsing context. Browsers commonly present that context as a tab, but browser behavior and user settings can make it a window instead. PHP does not control that presentation or open the tab itself. See MDN’s anchor element reference and the PHP documentation for the distinction between markup and PHP output.

If you leave out target, a link normally navigates in the current context, equivalent to target="_self". Use _blank when a separate context is useful, and tell users that it will open one so the change in navigation is not a surprise.

Choose the right rel value

For current conforming browsers, target="_blank" implicitly provides noopener behavior: the opened page cannot use window.opener to access the page that opened it. Adding rel="noopener" explicitly can still make the intended isolation clear and accommodate older or unusual user agents.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.
Markup Can the destination access window.opener? Is the Referer header sent?
rel="noopener" No Yes, unless another policy suppresses it
rel="noreferrer" No; it also implies noopener No

Use noreferrer only when you intend to withhold referrer information, which can affect referral analytics as well as privacy. The attribute behavior is described in MDN’s noopener and noreferrer references.

Escape dynamic values in PHP

When a URL or link label is dynamic, escape it for the HTML context in which it appears. htmlspecialchars($value, ENT_QUOTES, 'UTF-8') is appropriate for ordinary HTML attribute and text output. Escaping does not establish that a URL is safe: if an untrusted user can supply the destination, separately validate that its scheme is one your application permits.

Independent reader supportYour contribution helps us test, update, and keep practical guides available for everyone.Support on Ko-Fi

Tell users the link opens separately

Include a short cue in the visible link text, such as “(opens in a new tab or window),” or provide an equivalent accessible cue. Do not promise a tab specifically, because the browser or the user’s settings determine how the new browsing context appears. The HTML Standard’s links section defines the relevant link behavior.

Product prices and availability are accurate as of the date/time indicated and are subject to change. Any price and availability information displayed on Amazon at the time of purchase will apply.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.