LeBase64URL

Description

LeBase64URL converts external links in WordPress post content into signed redirect URLs. Visitors leave your site through a controlled jump page (or a direct 302), which helps with link management and reduces open-redirect abuse.

Default redirect format

https://example.com/?goto=TOKEN

No files are written to the WordPress root directory. Tokens use Base64URL encoding plus an HMAC signature (Base64 is encoding, not encryption).

Features

  • Convert article external links to signed ?goto= redirect URLs
  • Optional intermediate warning page or direct redirect
  • Domain whitelist (exact domain and subdomains)
  • Optional nofollow and target="_blank" (with noopener noreferrer)
  • Optional: skip conversion for logged-in administrators
  • Pretty permalink option: /go/TOKEN

Privacy

This plugin does not phone home, does not load remote scripts, and does not collect personal data. Redirect tokens are generated and verified locally using WordPress salts.

Documentation

Plugin introduction: https://www.lezaiyun.com/lebase64url.html

Screenshots

Installation

  1. Upload the lebase64url folder to the /wp-content/plugins/ directory, or install the ZIP via Plugins Add New Upload Plugin.
  2. Activate the plugin through the Plugins menu in WordPress.
  3. Go to Settings LeBase64URL设置 to configure options.
  4. Enable the plugin, then open any post with external links to verify redirects.
  5. If you use the /go/ prefix, visit Settings Permalinks and click Save Changes once.

FAQ

What does a redirect link look like?

By default: https://yoursite.com/?goto=TOKEN. You can also set the prefix to go/ for pretty URLs like https://yoursite.com/go/TOKEN.

Is Base64 encryption?

No. Base64 is encoding only. This plugin adds an HMAC signature so forged tokens cannot redirect arbitrarily.

Why do some links not convert?

Internal links, relative links, mailto: / tel: / # anchors, and whitelisted domains are left unchanged. Only http / https external links are converted.

Can administrators see original links?

Yes. Enable 管理员跳过转换 so users with manage_options see original external URLs while logged in.

Do I need go.php in the site root?

No. The recommended method is ?goto=. The plugin no longer writes go.php into the WordPress root.

Reviews

There are no reviews for this plugin.

Contributors & Developers

“LeBase64URL” is open source software. The following people have contributed to this plugin.

Contributors

Translate “LeBase64URL” into your language.

Interested in development?

Browse the code, check out the SVN repository, or subscribe to the development log by RSS.

Changelog

1.5.1

  • Redirect page CSS loads via wp_enqueue_scripts + wp_head() (no style/script tags)
  • Confirmed: no go.php bootstrap; no ABSPATH root file create/delete

1.5.0

  • Enqueue redirect-page CSS via wp_register_style / wp_enqueue_style
  • Remove legacy go.php bootstrap and all WordPress-root file create/delete logic
  • Use only plugin_dir_path / plugins_url for plugin file locations

1.4.2

  • Fix Plugin Check findings: prefixed globals, escaping, wp_safe_redirect, wp_parse_url, wp_delete_file, input sanitization
  • Align Requires at least (6.0) between readme and plugin header
  • Remove discouraged load_plugin_textdomain() call

1.4.1

  • Compliance and packaging: proper readme.txt, uninstall.php, directory index guards
  • Remove HTML from plugin header description
  • Prefer uninstall.php for cleanup

1.4.0

  • Default redirect format changed to /?goto=TOKEN (WordPress query var), no root file write
  • Removed automatic root go.php installation and cleaned legacy files

1.3.0

  • Used site-root /go.php?url= links
  • Auto-created root go.php on activation (removed in 1.4.0)

1.2.0

  • Fixed link regex so common href="..." attributes are matched
  • Improved internal/external host detection (www / home_url / site_url)
  • Added option to skip conversion for logged-in administrators
  • Process content after shortcodes (priority 20)

1.1.0

  • Added HMAC-signed tokens to mitigate open redirects
  • Fixed whitelist newline parsing
  • Fixed protocol-relative URLs treated as internal
  • Added redirect template; allow only http/https targets

1.0.0

  • Initial release.