Skip to main content
drupalreleases
Release: Cms 2.2.3 — Update released for Drupal core (2.2.3)! Release: Easy Breadcrumb 2.0.11 — Minor update available for module easy_breadcrumb (2.0.11). Release: Bootstrap 8.x-3.42 — Minor update available for theme bootstrap (8.x-3.42). Release: Search API attachments 10.0.13 — Minor update available for module search_api_attachments (10.0.13). Release: Editoria11y Accessibility Checker 3.0.10 — Minor update available for module editoria11y (3.0.10). Release: Editoria11y Accessibility Checker 2.2.24 — Minor update available for module editoria11y (2.2.24). Release: Mismatched entity and/or field definitions 1.2.1 — Minor update available for module meaofd (1.2.1). Release: Lupus Custom Elements Renderer 2.8.1 — Minor update available for module lupus_ce_renderer (2.8.1). Module Revived: Bootstrap 8.x-3.41 — Theme bootstrap updated after 6 months of inactivity (8.x-3.41). Security Coverage: Component Library — Module component_library now has official Drupal security advisory coverage.

No Referrer

5,111 sites Security covered Drupal 11 · not 10
View on drupal.org

This module enhances privacy and security for outgoing links by automatically adding `rel="noreferrer"`, `rel="noopener"`, and `referrerpolicy="no-referrer"` attributes. It offers control to selectively enable or disable these attributes and allows for a domain-based allowlist to prevent their application to trusted external sites.

The rel="noreferrer" attribute enhances privacy by instructing the browser to not send a Referer header when users click on (or prefetch) a link. It also enhances security by preventing the linked page from gaining access to the linking page via the window.opener object.

No Referrer module provides a filter which, if enabled for a text format, adds rel="noreferrer" to external links, rel="noopener" to links with a target, and referrerpolicy="no-referrer" to external resources. You can toggle these attributes on and off if, for example, you want only the security protections of rel="noopener" without the privacy protections of rel="noreferrer".

You will probably want to enable the Add referrerpolicy="no-referrer", rel="noopener" and/or rel="noreferrer" filter on all of your text formats.

No Referrer module also adds rel="noopener" and rel="noreferrer" to links generated by code (e.g. link fields and menu items). On Drupal 7, processing each link may have a small negative impact on site performance, so there is a setting to enable this behavior.

The settings page allows site administrators to define a list of allowed domains for which rel="noreferrer" and referrerpolicy="no-referrer" will not be added. For a network of sites which should share a common list of allowed domains, you can publish your domain allowlist as a JSON file, or subscribe to another site's domain allowlist.

You can support development by contributing or sponsoring.

Depends on

Dependencies of the latest stable release

No dependencies recorded for this project.

Required by

Tracked projects that depend on this one

No tracked projects depend on this one yet.

Activity

Tracked releases
11
Tracked since
Apr 2024
Latest release
3 months ago
Releases (12 mo)
3 ▲ from 1
Maintenance
Active

Release Timeline

Releases

Version Type Core Release date
3.x-dev Dev 11 Jul 7, 2026
2.0.4 Stable 10–11 Jul 4, 2026
3.0.1 Stable 11 Jul 4, 2026
3.0.0 Stable 11 Dec 20, 2024
8.x-1.18 Stable 8–11 May 22, 2024
2.0.3 Stable 10–11 May 22, 2024
2.0.2 Stable 10 May 21, 2024
2.0.1 Stable 10 Apr 13, 2024
2.0.0 Stable 10 Apr 10, 2024
2.x-dev Dev 10–11 Apr 10, 2024
8.x-1.17 Stable 8–10 Apr 10, 2024