Skip to main content
Drupal is a registered trademark of Dries Buytaert
Release: OpenID Connect / OAuth client 3.0.0-alpha9 New alpha version released for module openid_connect (3.0.0-alpha9). Release: Timelinr 1.0.1 Minor update available for module timelinr (1.0.1). Usage Milestone: Simplify Module simplify crossed 10,000 active installs. Usage Milestone: Views Reference Filter Module entityreference_filter crossed 10,000 active installs. Usage Milestone: Dropdown Language Module dropdown_language crossed 10,000 active installs. Usage Milestone: Paragraphs Browser Module paragraphs_browser crossed 10,000 active installs. Usage Milestone: OpenAPI Module openapi crossed 10,000 active installs. Usage Milestone: Decoupled Router Module decoupled_router crossed 10,000 active installs. Usage Milestone: Time Field for Drupal 8+ Module time_field crossed 10,000 active installs. Module Revived: Entityqueue Buttons 1.1.2 Module entityqueue_buttons updated after 8 months of inactivity (1.1.2).

Safe External Links

91 sites Security covered Drupal 8–11
View on drupal.org

Safe External Links automatically modifies your website's external links to open in a new browser tab, adding the necessary security attributes to prevent tabnapping attacks. This provides a safer browsing experience for your users by preventing potential phishing and ensuring browser security warnings are avoided.

Most of the clients I worked for asked that external links on their website should open a new browser window or tab. Safe External Links (sel) does this for you automatically and properly. It modifies external links to make them open a new window by adding target="_blank" and rel="noreferrer" or rel="noopener" attributes to the anchor tag.

Properly?

If you simply just have a target="_blank" on outbound links, you put your site visitors at risk of tabnapping.
Tabnapping is a phishing attack that takes advantage of user trust and inattention to detail in regard to tabs, and forces the browser to navigate to an impersonated page after the page is left. Mathias Bynens created a great Github page for demonstrating this attack.
And this is why Google Chrome’s built-in Lighthouse validation warns you if it finds an external link with a _blank target without the appropriate relation:


Lighthouse audit report warning about unsafe cross-origin link destinations.

The solution

The best thing is: Safe External Links can solve these. You only have to download and enable it, change the link formatters and update the filter formats you use.

Processed Drupal components:

  • Menu links
  • Link fields (sel_link field formatter)
  • Formatted texts (filter_sel filter plugin)

Depends on

Dependencies of the latest stable release

No dependencies recorded for this project.

Required by

Tracked projects that depend on this one

No tracked projects depend on this one yet.

Activity

Tracked releases
1
Tracked since
Jun 2025
Latest release
1 year ago
Releases (12 mo)
0 ▼ from 1
Maintenance
Dormant

Releases

Version Type Core Release date
8.x-1.1 Stable 8–11 Jun 28, 2025