new-tab

Installation
SKILL.md

External Link Security

A malicious site opened via target='_blank' can use window.opener.location to silently redirect your original tab to a phishing page — the user switches back and sees a fake login screen on what appears to be your domain.

Quick Reference

  • Always add rel="noopener noreferrer" to any <a target="_blank"> link
  • noopener prevents the new tab from accessing window.opener and redirecting your page
  • noreferrer additionally suppresses the Referer header sent to the destination site
  • Modern browsers (Chrome 88+, Firefox 79+) implicitly add noopener for cross-origin _blank links, but explicit markup is required for older browsers and same-origin links
  • ESLint rule jsx-a11y/anchor-is-valid and eslint-plugin-security can enforce this automatically

Check

Find all anchor elements with target='_blank' in the HTML and JSX source. Verify each one includes rel='noopener noreferrer' (or at minimum rel='noopener'). Flag any external links opening in a new tab that are missing this attribute.

Fix

Add rel='noopener noreferrer' to all elements. In React/JSX this is rel="noopener noreferrer". Configure an ESLint rule to prevent this from recurring.

Installs
4
GitHub Stars
73.9K
First Seen
Aug 11, 2026
new-tab — thedaviddias/front-end-checklist