rel="noopener noreferrer" is used for security and privacy when opening external links in a new tab; 1. rel="noopener" prevents the new page from accessing the window.opener object, blocking it from manipulating the original page; 2. rel="noreferrer" includes noopener functionality and additionally prevents the Referer header from being sent, keeping the source URL private; 3. using both is common but redundant since noreferrer already implies noopener; 4. these attributes should be used with target="_blank" on external, untrusted, or user-generated links to prevent security risks and protect referral data; 5. for internal links, usage is optional but harmless. This practice enhances both security and user privacy.
When you see rel="noopener noreferrer"
in an HTML link, it's a security and performance-related attribute added to <a></a>
tags, especially when using target="_blank"
(which opens the link in a new tab or window). Let’s break down what each part means and why it matters.

? What is rel="noopener"
?
rel="noopener"
is used to prevent the new page from gaining control over the window.opener
property.
When you open a link with target="_blank"
without rel="noopener"
, the new page runs in the same process as your page and can access the window.opener
object. This means it can technically navigate your original page (e.g., change its URL via window.opener.location = ...
) — a potential security risk.

Using rel="noopener"
ensures the new page cannot access the opener window, making your site more secure.
Example:

<a href="https://example.com" target="_blank" rel="noopener"> Open site </a>
Now, even if example.com
tries to run window.opener.location.replace(...)
, it won’t work — window.opener
will be null
.
? Note:
rel="noopener"
is mainly needed when the link goes to an external or untrusted site.
? What is rel="noreferrer"
?
rel="noreferrer"
goes a step further:
- It implies
noopener
(sowindow.opener
is also blocked). - It prevents the Referer header from being sent to the target site.
This means the destination site won’t know where the user came from — your site’s URL stays private.
Use case: You might use this when linking to external sites and you don’t want them to see your domain in their analytics.
<a href="https://example.com" target="_blank" rel="noreferrer"> Private link </a>
?? Trade-off: If you use noreferrer
, the traffic will show up as "direct" or "unknown" in the target site’s analytics.
? Should you use both? rel="noopener noreferrer"
Yes, sometimes — but it's redundant in practice.
noreferrer
already includes the behavior ofnoopener
in most browsers.- So
rel="noreferrer"
alone is enough if you want both security and privacy. - But many developers still write
rel="noopener noreferrer"
just to be explicit or for compatibility with older tools.
<!-- Common pattern, slightly redundant but safe --> <a href="https://example.com" target="_blank" rel="noopener noreferrer"> Safe external link </a>
? When should you use these?
Use rel="noopener"
(or noreferrer
) whenever you use target="_blank"
on external links, especially:
- Links to third-party websites
- User-generated content (e.g., comments, forums)
- Affiliate links where you don’t trust the destination
For internal links (same site), it’s less critical but doesn’t hurt.
?? What about rel="noopenner"
alone?
Yes, just rel="noopener"
is sufficient for most security needs. It stops the performance and security risks from window.opener
without hiding referral info.
TL;DR
-
rel="noopener"
→ blockswindow.opener
access (security/performance) -
rel="noreferrer"
→ blocks referrer info and includesnoopener
- Use
rel="noopener"
(ornoreferrer
) withtarget="_blank"
on external links -
rel="noopener noreferrer"
is common but slightly redundant
Basically, it's a best practice for safer external links.
The above is the detailed content of What does rel='noopener noreferrer' mean?. For more information, please follow other related articles on the PHP Chinese website!

Hot AI Tools

Undress AI Tool
Undress images for free

Undresser.AI Undress
AI-powered app for creating realistic nude photos

AI Clothes Remover
Online AI tool for removing clothes from photos.

Clothoff.io
AI clothes remover

Video Face Swap
Swap faces in any video effortlessly with our completely free AI face swap tool!

Hot Article

Hot Tools

Notepad++7.3.1
Easy-to-use and free code editor

SublimeText3 Chinese version
Chinese version, very easy to use

Zend Studio 13.0.1
Powerful PHP integrated development environment

Dreamweaver CS6
Visual web development tools

SublimeText3 Mac version
God-level code editing software (SublimeText3)

The rational use of semantic tags in HTML can improve page structure clarity, accessibility and SEO effects. 1. Used for independent content blocks, such as blog posts or comments, it must be self-contained; 2. Used for classification related content, usually including titles, and is suitable for different modules of the page; 3. Used for auxiliary information related to the main content but not core, such as sidebar recommendations or author profiles. In actual development, labels should be combined and other, avoid excessive nesting, keep the structure simple, and verify the rationality of the structure through developer tools.

To use HTML button elements to achieve clickable buttons, you must first master its basic usage and common precautions. 1. Create buttons with tags and define behaviors through type attributes (such as button, submit, reset), which is submitted by default; 2. Add interactive functions through JavaScript, which can be written inline or bind event listeners through ID to improve maintenance; 3. Use CSS to customize styles, including background color, border, rounded corners and hover/active status effects to enhance user experience; 4. Pay attention to common problems: make sure that the disabled attribute is not enabled, JS events are correctly bound, layout occlusion, and use the help of developer tools to troubleshoot exceptions. Master this

Metadata in HTMLhead is crucial for SEO, social sharing, and browser behavior. 1. Set the page title and description, use and keep it concise and unique; 2. Add OpenGraph and Twitter card information to optimize social sharing effects, pay attention to the image size and use debugging tools to test; 3. Define the character set and viewport settings to ensure multi-language support is adapted to the mobile terminal; 4. Optional tags such as author copyright, robots control and canonical prevent duplicate content should also be configured reasonably.

TolearnHTMLin2025,chooseatutorialthatbalanceshands-onpracticewithmodernstandardsandintegratesCSSandJavaScriptbasics.1.Prioritizehands-onlearningwithstep-by-stepprojectslikebuildingapersonalprofileorbloglayout.2.EnsureitcoversmodernHTMLelementssuchas,

How to make HTML mail templates with good compatibility? First, you need to build a structure with tables to avoid using div flex or grid layout; secondly, all styles must be inlined and cannot rely on external CSS; then the picture should be added with alt description and use a public URL, and the buttons should be simulated with a table or td with background color; finally, you must test and adjust the details on multiple clients.

Using HTML sums allows for intuitive and semantic clarity to add caption text to images or media. 1. Used to wrap independent media content, such as pictures, videos or code blocks; 2. It is placed as its explanatory text, and can be located above or below the media; 3. They not only improve the clarity of the page structure, but also enhance accessibility and SEO effect; 4. When using it, you should pay attention to avoid abuse, and apply to content that needs to be emphasized and accompanied by description, rather than ordinary decorative pictures; 5. The alt attribute that cannot be ignored, which is different from figcaption; 6. The figcaption is flexible and can be placed at the top or bottom of the figure as needed. Using these two tags correctly helps to build semantic and easy to understand web content.

class, id, style, data-, and title are the most commonly used global attributes in HTML. class is used to specify one or more class names to facilitate style setting and JavaScript operations; id provides unique identifiers for elements, suitable for anchor jumps and JavaScript control; style allows for inline styles to be added, suitable for temporary debugging but not recommended for large-scale use; data-properties are used to store custom data, which is convenient for front-end and back-end interaction; title is used to add mouseover prompts, but its style and behavior are limited by the browser. Reasonable selection of these attributes can improve development efficiency and user experience.

When there is no backend server, HTML form submission can still be processed through front-end technology or third-party services. Specific methods include: 1. Use JavaScript to intercept form submissions to achieve input verification and user feedback, but the data will not be persisted; 2. Use third-party serverless form services such as Formspree to collect data and provide email notification and redirection functions; 3. Use localStorage to store temporary client data, which is suitable for saving user preferences or managing single-page application status, but is not suitable for long-term storage of sensitive information.
