No Opener, No Phishers

#4.78 / 9 rate

No Opener, No Phishers

641 users

2019-06-17

Jamie Farrelly

Extension Information

5 star
88%
4 star
0%
3 star
12%
2 star
0%
1 star
0%

Supported Languages

Description

Reduce the risk of falling victim to phishing attacks.

Any website that uses target="_blank" on their links, allows user generated content and doesn't use the rel="noopener" attribute on their links (I'm looking at you Facebook, Twitter etc.) is vulnerable to a scarily simple phishing attack.

For an example of this kind of attack, view this example that I've made: https://jamiefarrelly.github.io/Rel-NoOpener-Example/

This Chrome extension is as simple as it gets, all it does is add "noopener noreferrer" to the rel attribute on all links on the pages that you're visiting so that you won't fall victim to this type of phishing attack.

Open source on Github https://github.com/JamieFarrelly/No-Opener-No-Phishers

Reviews

Gaurav
Gaurav

It would have been nicer if the extension allowed making exceptions for some sites via a whitelist.

Justin Butler
Justin Butler

PSA: This is no longer required if you're on version 88 or newer on any platform that uses Chromium (e.g. Chrome, New Edge, Brave, etc.). https://www.chromestatus.com/feature/6140064063029248

Sam Prince
Sam Prince

This feature is now baked into Chrome so the extension can be removed for most purposes. Where a site links to a target other than "_blank", e.g. "_potato" the same security issue still exists. Not sure if this extension only works with _blank links

Similar extensions

Opener Detector
Opener Detector

Harry Cutts

Security Tweaks
Security Tweaks

loora

Privacy Crawler
Privacy Crawler

privacy-crawler

NoDetour
NoDetour

Patrick H. Lauke

Redirect AMP to HTML
Redirect AMP to HTML

Aleksandersen

Site Bleacher
Site Bleacher

wooque

Google link fixer
Google link fixer

littlelightlittlefire

Ignore Google Scripts
Ignore Google Scripts

em_te

Block Unreachable Scripts
Block Unreachable Scripts

em_te

LocalCDN
LocalCDN

Emanuel Bennici

WebAPI Blocker
WebAPI Blocker

Yubi

Local Cache
Local Cache

Unknown