The HTML rel attribute can contain several values that describe the relationship between the current document and a linked resource. Three of the most commonly misunderstood values are noopener, noreferrer and nofollow.
They are often placed together inside the same link:
<a href="https://example.com/" target="_blank" rel="noopener noreferrer nofollow">Example</a>
That makes it easy to assume they are three versions of the same protection. They are not.
noopeneris mainly about the relationship between browser windows.noreferreris mainly about referrer information and also implies the effect ofnoopener.nofollowis primarily an annotation about the relationship between your page and the linked page, with important implications for search engines.
Understanding the difference matters because adding every value to every external link is not automatically the best configuration.
A normal editorial source may not need nofollow. A paid placement should normally be qualified appropriately for search engines. A privacy-sensitive link may justify noreferrer, but that choice also removes referral information the destination would otherwise receive.
This guide explains what each attribute does, how modern browsers treat target="_blank", when nofollow, sponsored and ugc are appropriate, and how these choices apply to WordPress.
How the rel attribute works
The rel attribute describes the relationship between the current document and the resource referenced by a link.
The current MDN documentation for the HTML rel attribute explains that its value is an unordered set of space-separated keywords.
A link can therefore use one value:
<a href="https://example.com/" rel="nofollow">Example</a>
or several values together:
<a href="https://example.com/" rel="noopener noreferrer">Example</a>
The values do not replace one another. Each token can express a separate relationship or browser behavior.
rel is different from target
target controls where a link is opened.
For example:
target="_blank"
normally opens the destination in a new browsing context, commonly a new browser tab.
rel, on the other hand, describes or modifies the relationship associated with that navigation.
This distinction matters because noopener and noreferrer are frequently discussed in connection with links that open in a new tab, while nofollow has a completely different purpose.
What rel=”noopener” does
noopener prevents the newly opened browsing context from receiving an opener relationship to the page that opened it.
According to the MDN documentation for rel=”noopener”, the destination is opened without granting it access to the originating document through window.opener.
In practical terms, code in the destination page should see:
window.opener === null
rather than receiving an opener reference to the original tab.
Why window.opener historically mattered
When one page opens another page, an opener relationship can allow the new page to interact with the browsing context that launched it in certain ways.
Historically, this created the possibility of attacks commonly associated with reverse tabnabbing.
A malicious destination could potentially navigate the original tab after the visitor had switched attention to the new page.
A simplified scenario would be:
- a visitor opens a legitimate website;
- the visitor clicks an external link that opens in another tab;
- the newly opened website has access to an opener relationship;
- the destination changes the original tab’s location;
- the user later returns to what appears to be the original tab.
The purpose of noopener is to remove that opener relationship.
Modern target=”_blank” already implies noopener
This is where a lot of older WordPress and SEO advice has become outdated.
The current HTML standard specifies that links using:
target="_blank"
behave with no-opener semantics unless an opener relationship is explicitly requested.
Modern MDN documentation likewise states that setting target="_blank" implicitly provides the same relevant protection as rel="noopener".
Therefore, this:
<a href="https://example.com/" target="_blank">Example</a>
already receives no-opener behavior in current conforming browsers.
Explicitly writing:
rel="noopener"
is still useful for clarity, consistency and compatibility with older environments, but it is no longer accurate to claim that every modern target="_blank" link is automatically vulnerable simply because the literal noopener token is missing.
noopener does not hide the referrer
This distinction is important.
noopener does not normally prevent the destination from receiving normal referrer information.
The MDN specification explicitly distinguishes that behavior from noreferrer.
If your objective is to suppress referrer information, noopener alone does not do that.
What rel=”noreferrer” does
noreferrer controls information sent to the destination when a link is followed.
The MDN documentation for rel=”noreferrer” states that the browser omits the Referer HTTP header and otherwise avoids leaking referrer information for that navigation.
There is an unfortunate historical naming detail worth knowing:
- the HTTP header is spelled
Referer; - the HTML relationship is spelled
noreferrer.
The typo in the HTTP header became part of the standard decades ago and humanity collectively decided to keep carrying it around. Web standards are full of little archaeological treasures like that.
What referrer information normally does
When a visitor follows a link, the destination can often receive information about where that visitor came from, subject to browser behavior and the site’s referrer policy.
That information can be useful for:
- analytics;
- traffic attribution;
- referral reports;
- publisher statistics;
- partnership reporting;
- understanding which pages send visitors to another website.
When noreferrer is present, the destination does not receive that normal referrer information for the navigation.
noreferrer also implies noopener
This is one of the most useful relationships to remember.
The HTML standard defines noreferrer so that it also implies noopener behavior.
Therefore:
rel="noreferrer"
already gives you the relevant opener isolation associated with:
rel="noopener"
under the same conditions.
That means:
rel="noopener noreferrer"
is perfectly valid and extremely common, but the noopener token is functionally redundant for the opener behavior when noreferrer is already present.
noreferrer is a privacy decision
Unlike noopener, noreferrer deliberately changes what information the destination receives.
That may be desirable when:
- the current page URL contains information you do not want exposed;
- you deliberately want to hide the origin of the navigation;
- your privacy model requires tighter referrer controls.
But that comes with a trade-off.
The destination may no longer be able to attribute the visit to your website.
Therefore, adding noreferrer to every external link should be a deliberate privacy policy, not a reflex.
What rel=”nofollow” does
nofollow is fundamentally different from both noopener and noreferrer.
It is not primarily a browser-window security mechanism.
It does not hide referrer information.
It describes the relationship between the current page and the linked resource, particularly for search engines.
The HTML standard describes nofollow as indicating that the original author or publisher does not endorse the referenced document, or that another relationship such as a commercial arrangement may exist.
For practical SEO guidance, the most relevant source is Google Search Central’s documentation on qualifying outbound links.
Normal external links do not automatically need nofollow
This is probably the most common SEO misconception surrounding external links.
Google explicitly states that regular links it should interpret normally do not require a special rel qualification.
For example, if an article references an authoritative documentation page because it genuinely supports the content, a normal external link is perfectly valid.
<a href="https://example.com/documentation/">Documentation</a>
You do not need to add:
rel="nofollow"
simply because the destination belongs to another domain.
External does not mean untrusted
An external link may point to:
- official WordPress documentation;
- Google Search Central;
- MDN;
- a scientific paper;
- a trusted vendor;
- an original source for a factual claim.
There is no general SEO principle saying that leaving your own domain requires nofollow.
Normal editorial links are part of how the web works.
nofollow is not a guaranteed crawl block
Google treats nofollow as a qualification or hint rather than a universal instruction that makes a URL invisible.
A linked page may still be discovered through:
- other websites;
- sitemaps;
- internal links;
- previous crawling;
- other discovery mechanisms.
Therefore, nofollow is not a reliable mechanism for preventing a page from being indexed.
If you control a page and want it excluded from search results, indexing directives such as noindex are the relevant mechanism, not an outbound nofollow link from another page.
nofollow vs sponsored vs ugc
Modern Google guidance provides more specific relationship values for several common situations.
Use sponsored for paid relationships
Google recommends:
rel="sponsored"
for links that exist because of advertising, sponsorship or another paid placement.
This can include:
- advertisements;
- sponsored articles;
- paid links;
- commercial placements;
- many affiliate arrangements.
Google still accepts nofollow for these types of links, but its current guidance says that sponsored is preferred because it describes the relationship more precisely.
Use ugc for user-generated content
Google recommends:
rel="ugc"
for links created inside user-generated content.
Common examples include:
- blog comments;
- forum posts;
- community contributions;
- user-submitted profiles or discussions.
Values can be combined when appropriate:
rel="ugc nofollow"
Use nofollow when the more specific values do not fit
Google recommends nofollow when the other values are not appropriate and you would rather Google not associate your site with, or crawl the linked page from, your site.
This makes nofollow a contextual relationship signal rather than a default attribute for everything outside your hostname.
noopener vs noreferrer vs nofollow
The easiest way to understand the three values is to compare the problem each one solves.
| Attribute | Primary purpose | Blocks opener access | Removes referrer | Primary SEO role |
|---|---|---|---|---|
noopener |
Browser-window isolation | Yes | No | No |
noreferrer |
Referrer privacy | Yes | Yes | No direct replacement for SEO link qualification |
nofollow |
Link relationship qualification | No | No | Yes |
noopener does not mean nofollow
A link can use noopener while remaining a completely normal editorial link for search engines.
For example:
<a href="https://example.com/" target="_blank" rel="noopener">Source</a>
does not tell Google that the link is untrusted or unendorsed.
nofollow does not replace noopener
This:
rel="nofollow"
does not remove an opener relationship.
Its job is different.
noreferrer does not replace nofollow
Suppressing the referrer header does not tell a search engine whether a link is sponsored, user-generated or unendorsed.
Privacy and SEO are separate decisions.
How target=”_blank” changes the discussion
target="_blank" is commonly used for external links because it opens the destination in another browsing context.
Whether that is desirable is primarily a user-experience decision.
For the complete trade-off, see Why External Links Should Open in a New Tab.
Opening external links in a new tab is not mandatory
There is no HTML or SEO rule that says external links must use:
target="_blank"
A normal external link can open in the current tab.
Whether to use a new tab depends on the experience you want to provide.
Modern browsers implicitly isolate _blank links
As explained earlier, current HTML behavior treats target="_blank" as having no-opener behavior unless rel="opener" explicitly requests the opener relationship.
That makes explicit noopener partly defensive and partly documentary in modern markup.
Use opener only when you genuinely need it
The HTML standard also defines:
rel="opener"
which can explicitly request an opener relationship for a _blank navigation.
Most ordinary external links have no reason to do this.
If application functionality deliberately depends on communication with the opener window, however, the relationship may be intentional.
How these link attributes work in WordPress
WordPress can generate links from many different systems.
Links may appear in:
- posts;
- pages;
- custom post types;
- classic widgets;
- block widgets;
- Navigation blocks;
- classic menus;
- theme templates;
- plugin output;
- page builders;
- custom fields.
That means there is not necessarily one universal filter that represents every link produced by an entire WordPress website.
WordPress editors can add new-tab behavior
When editing supported links in WordPress, you can often choose whether the destination opens in a new tab.
WordPress then generates the corresponding anchor markup.
But dynamically generated links from plugins and themes can have completely separate behavior.
Internal links should generally remain internal links
A system that automatically modifies external links should first determine whether a URL actually leaves the current website.
Internal links are part of your site’s normal navigation and information architecture.
Blanket external-link rules should not accidentally modify:
- navigation menus;
- internal article links;
- category links;
- breadcrumbs;
- pagination;
- other internal URLs.
Block content creates another processing layer
Modern WordPress sites can generate link markup through rendered blocks in addition to traditional post content.
Plugins that automatically transform links therefore need to understand which content filters they actually process.
For a deeper explanation of block-based WordPress architecture, see WordPress Full Site Editing and Block Widgets, Explained.
How TheOneWP handles external links
TheOneWP includes an External Links module designed to apply a consistent external-link policy to supported WordPress content.
The verified implementation identifies links that point to another domain and can apply:
target="_blank";noopener;noreferrer;nofollow.
Internal links remain unchanged.
Each attribute still has a separate role
Within that generated markup:
noopeneraddresses the opener relationship;noreferrerprevents referrer information from being sent and also implies opener protection;nofollowqualifies the relationship for search engines.
They should therefore not be described as three interchangeable security protections.
Automatic nofollow is an SEO policy choice
Because Google does not require nofollow on normal editorial links, automatically applying it to every external URL represents a deliberate site-wide policy.
This is worth understanding before enabling any external-link automation.
A trusted citation to an authoritative resource and an advertisement are not the same type of relationship merely because both point to another domain.
For paid and user-generated relationships, sponsored and ugc can provide more precise semantics where the implementation allows them.
Practical examples
Normal editorial external link
<a href="https://example.com/research/">Research source</a>
No special rel value is inherently required simply because the destination is external.
Editorial link opening in a new tab
<a href="https://example.com/research/" target="_blank" rel="noopener">Research source</a>
This explicitly expresses the opener policy while preserving normal referrer information.
External link without referrer information
<a href="https://example.com/" target="_blank" rel="noreferrer">External resource</a>
This suppresses the referrer and also implies noopener.
Paid placement
<a href="https://advertiser.example/" rel="sponsored">Sponsor</a>
If it should also open in another tab:
<a href="https://advertiser.example/" target="_blank" rel="sponsored noopener">Sponsor</a>
User-generated link
<a href="https://example.com/" rel="ugc">User link</a>
You can combine relationship values when needed:
<a href="https://example.com/" rel="ugc nofollow">User link</a>
Unendorsed external destination
<a href="https://example.com/" rel="nofollow">External reference</a>
Here, nofollow describes the relationship rather than being attached merely because the hostname differs.
Common mistakes
Adding nofollow to every external link for SEO
Google does not require this.
Normal editorial links can remain ordinary links.
Thinking noopener hides referral traffic
It does not.
noopener controls the opener relationship. noreferrer suppresses the referrer.
Thinking noreferrer is only about security
It also affects analytics and attribution because the destination does not receive normal referrer information.
Thinking nofollow blocks indexing
The linked page may still be discovered and indexed through other sources.
Using nofollow instead of sponsored automatically
Google still accepts nofollow for paid links, but currently prefers sponsored as the more descriptive value.
Assuming _blank still exposes window.opener by default
Modern HTML behavior provides implicit no-opener handling for target="_blank", unless an opener relationship is explicitly requested.
Thinking noreferrer and noopener must always appear together
noreferrer already implies the relevant noopener behavior.
Including both is explicit and common, but not necessary to obtain that opener protection.
Assuming every external site is untrusted
External, untrusted, sponsored and user-generated describe different relationships.
Do not collapse them into one rule unless that is genuinely your intended site policy.
External link attribute checklist
- Decide whether the destination should open in the current tab or a new tab based on user experience.
- Remember that modern
target="_blank"links implicitly receive no-opener behavior. - Use explicit
noopenerwhen you want that intent visible in the markup. - Use
noreferrerwhen suppressing referrer information is intentional. - Remember that
noreferreralso impliesnoopener. - Do not use
noreferrerblindly if referral analytics matter. - Do not add
nofollowto every external link merely because it leaves your domain. - Allow ordinary editorial citations to remain normal links when no qualification is needed.
- Use
sponsoredfor paid placements and advertising relationships. - Use
ugcfor user-generated content where appropriate. - Use
nofollowwhen the other relationship values do not fit and you want to qualify the link. - Do not treat
nofollowas an indexing-control mechanism. - Keep internal links out of blanket external-link transformations.
- Audit links generated by plugins, blocks and widgets separately when necessary.
- Remember that security, privacy and SEO remain separate concerns even when their tokens appear inside the same
relattribute.
Related guides
- Why External Links Should Open in a New Tab
- WordPress Full Site Editing and Block Widgets, Explained
- wp_enqueue_scripts Explained
- WordPress Custom Post Types and SEO
- What Is an XML Sitemap and Why Does It Matter?
- 301 vs. 302 vs. 410: Which Redirect to Use?
- WordPress Privacy and Third-Party Requests
- CDN vs. Self-Hosted Assets in WordPress
Final recommendation
noopener, noreferrer and nofollow can appear inside the same HTML attribute, but they solve three different problems.
The simplest mental model is:
- noopener: controls the opener relationship between browsing contexts;
- noreferrer: withholds referrer information and also implies no-opener behavior;
- nofollow: qualifies the relationship between your page and the linked resource for search engines.
Modern browser behavior also means that target="_blank" already receives implicit no-opener protection in current conforming browsers, so older advice about _blank needs to be interpreted in that context.
For SEO, the equally important correction is that external does not mean nofollow.
Normal editorial links can remain normal links. Paid relationships are better described with sponsored. User-generated links can use ugc. nofollow remains useful when those more precise relationships do not apply and you want to qualify the link.
For privacy, decide deliberately whether you want to suppress the referrer. Do not automatically add noreferrer and then wonder why the destination cannot identify your site as the source of referral traffic.
Once browser security, privacy and SEO are treated as separate decisions, the purpose of these attributes becomes much easier to understand and configure correctly.

