{"id":375839,"date":"2026-10-06T07:43:48","date_gmt":"2026-10-06T07:43:48","guid":{"rendered":"https:\/\/cn.wordpress.org\/plugins\/lebase64url\/"},"modified":"2026-10-06T07:43:23","modified_gmt":"2026-10-06T07:43:23","slug":"lebase64url","status":"publish","type":"plugin","link":"https:\/\/as.wordpress.org\/plugins\/lebase64url\/","author":16982120,"comment_status":"closed","ping_status":"closed","template":"","meta":{"version":"1.5.1","stable_tag":"1.5.1","tested":"7.1.3","requires":"6.0","requires_php":"7.0","requires_plugins":null,"header_name":"LeBase64URL","header_author":"\u8001\u848b\u548c\u4ed6\u7684\u5c0f\u4f19\u4f34","header_description":"Convert post external links into signed redirect URLs (?goto=), with whitelist, nofollow, and intermediate page options.","assets_banners_color":"f7f9fb","last_updated":"2026-10-06 07:43:23","external_support_url":"","external_repository_url":"","donate_link":"https:\/\/www.lezaiyun.com\/Donate","header_plugin_uri":"https:\/\/www.lezaiyun.com\/lebase64url.html","header_author_uri":"https:\/\/www.laojiang.me","rating":0,"author_block_rating":0,"active_installs":0,"downloads":76,"num_ratings":0,"support_threads":0,"support_threads_resolved":0,"author_block_count":0,"sections":["description","installation","faq","changelog"],"tags":{"1.5.1":{"tag":"1.5.1","author":"laobuluo","date":"2026-10-06 07:43:23","revision":3730238}},"upgrade_notice":{"1.5.1":"<p>WordPress.org review alignment: enqueue CSS on wp_enqueue_scripts. Upload this build (not older zips).<\/p>","1.5.0":"<p>WordPress.org review fixes: CSS enqueue, remove go.php and root-file handling.<\/p>","1.4.2":"<p>Plugin Check compliance fixes. Please re-run Plugin Check after updating.<\/p>","1.4.1":"<p>Packaging and WordPress.org-oriented compliance updates. Refresh a post page after updating.<\/p>","1.4.0":"<p>Redirects now use <code>\/?goto=<\/code>. Legacy <code>go.php<\/code> prefixes migrate automatically.<\/p>"},"ratings":[],"assets_icons":{"icon-128x128.png":{"filename":"icon-128x128.png","revision":3730238,"resolution":"128x128","location":"assets","locale":"","width":128,"height":122},"icon-256x256.png":{"filename":"icon-256x256.png","revision":3730238,"resolution":"256x256","location":"assets","locale":"","width":256,"height":244}},"assets_banners":{"banner-772x250.png":{"filename":"banner-772x250.png","revision":3730238,"resolution":"772x250","location":"assets","locale":"","width":772,"height":250}},"assets_blueprints":{},"all_blocks":[],"tagged_versions":["1.5.1"],"block_files":[],"assets_screenshots":{"screenshot-1.png":{"filename":"screenshot-1.png","revision":3730238,"resolution":"1","location":"assets","locale":"","width":1852,"height":1354}},"screenshots":{"1":"Settings page under Settings \u2192 LeBase64URL\u8bbe\u7f6e","2":"Intermediate redirect warning page (optional)"}},"plugin_section":[],"plugin_tags":[369,9888,421,727,6147],"plugin_category":[35],"plugin_contributors":[169988],"plugin_business_model":[],"class_list":["post-375839","plugin","type-plugin","status-publish","hentry","plugin_tags-affiliate","plugin_tags-external-links","plugin_tags-nofollow","plugin_tags-redirect","plugin_tags-whitelist","plugin_category-advertising","plugin_contributors-laobuluo","plugin_committers-laobuluo"],"banners":{"banner":"https:\/\/ps.w.org\/lebase64url\/assets\/banner-772x250.png?rev=3730238","banner_2x":false,"banner_rtl":false,"banner_2x_rtl":false},"icons":{"svg":false,"icon":"https:\/\/ps.w.org\/lebase64url\/assets\/icon-128x128.png?rev=3730238","icon_2x":"https:\/\/ps.w.org\/lebase64url\/assets\/icon-256x256.png?rev=3730238","generated":false},"screenshots":[{"src":"https:\/\/ps.w.org\/lebase64url\/assets\/screenshot-1.png?rev=3730238","caption":"Settings page under Settings \u2192 LeBase64URL\u8bbe\u7f6e"}],"raw_content":"<!--section=description-->\n<p>LeBase64URL converts external links in WordPress post content into signed redirect URLs. Visitors leave your site through a controlled jump page (or a direct 302), which helps with link management and reduces open-redirect abuse.<\/p>\n\n<p><strong>Default redirect format<\/strong><\/p>\n\n<pre><code>https:\/\/example.com\/?goto=TOKEN\n<\/code><\/pre>\n\n<p>No files are written to the WordPress root directory. Tokens use Base64URL encoding plus an HMAC signature (Base64 is encoding, not encryption).<\/p>\n\n<p><strong>Features<\/strong><\/p>\n\n<ul>\n<li>Convert article external links to signed <code>?goto=<\/code> redirect URLs<\/li>\n<li>Optional intermediate warning page or direct redirect<\/li>\n<li>Domain whitelist (exact domain and subdomains)<\/li>\n<li>Optional <code>nofollow<\/code> and <code>target=\"_blank\"<\/code> (with <code>noopener noreferrer<\/code>)<\/li>\n<li>Optional: skip conversion for logged-in administrators<\/li>\n<li>Pretty permalink option: <code>\/go\/TOKEN<\/code><\/li>\n<\/ul>\n\n<p><strong>Privacy<\/strong><\/p>\n\n<p>This plugin does not phone home, does not load remote scripts, and does not collect personal data. Redirect tokens are generated and verified locally using WordPress salts.<\/p>\n\n<p><strong>Documentation<\/strong><\/p>\n\n<p>Plugin introduction: <a href=\"https:\/\/www.lezaiyun.com\/lebase64url.html\">https:\/\/www.lezaiyun.com\/lebase64url.html<\/a><\/p>\n\n<!--section=installation-->\n<ol>\n<li>Upload the <code>lebase64url<\/code> folder to the <code>\/wp-content\/plugins\/<\/code> directory, or install the ZIP via <strong>Plugins \u2192 Add New \u2192 Upload Plugin<\/strong>.<\/li>\n<li>Activate the plugin through the <strong>Plugins<\/strong> menu in WordPress.<\/li>\n<li>Go to <strong>Settings \u2192 LeBase64URL\u8bbe\u7f6e<\/strong> to configure options.<\/li>\n<li>Enable the plugin, then open any post with external links to verify redirects.<\/li>\n<li>If you use the <code>\/go\/<\/code> prefix, visit <strong>Settings \u2192 Permalinks<\/strong> and click <strong>Save Changes<\/strong> once.<\/li>\n<\/ol>\n\n<!--section=faq-->\n<dl>\n<dt id=\"what%20does%20a%20redirect%20link%20look%20like%3F\"><h3>What does a redirect link look like?<\/h3><\/dt>\n<dd><p>By default: <code>https:\/\/yoursite.com\/?goto=TOKEN<\/code>. You can also set the prefix to <code>go\/<\/code> for pretty URLs like <code>https:\/\/yoursite.com\/go\/TOKEN<\/code>.<\/p><\/dd>\n<dt id=\"is%20base64%20encryption%3F\"><h3>Is Base64 encryption?<\/h3><\/dt>\n<dd><p>No. Base64 is encoding only. This plugin adds an HMAC signature so forged tokens cannot redirect arbitrarily.<\/p><\/dd>\n<dt id=\"why%20do%20some%20links%20not%20convert%3F\"><h3>Why do some links not convert?<\/h3><\/dt>\n<dd><p>Internal links, relative links, <code>mailto:<\/code> \/ <code>tel:<\/code> \/ <code>#<\/code> anchors, and whitelisted domains are left unchanged. Only <code>http<\/code> \/ <code>https<\/code> external links are converted.<\/p><\/dd>\n<dt id=\"can%20administrators%20see%20original%20links%3F\"><h3>Can administrators see original links?<\/h3><\/dt>\n<dd><p>Yes. Enable <strong>\u7ba1\u7406\u5458\u8df3\u8fc7\u8f6c\u6362<\/strong> so users with <code>manage_options<\/code> see original external URLs while logged in.<\/p><\/dd>\n<dt id=\"do%20i%20need%20go.php%20in%20the%20site%20root%3F\"><h3>Do I need go.php in the site root?<\/h3><\/dt>\n<dd><p>No. The recommended method is <code>?goto=<\/code>. The plugin no longer writes <code>go.php<\/code> into the WordPress root.<\/p><\/dd>\n\n<\/dl>\n\n<!--section=changelog-->\n<h4>1.5.1<\/h4>\n\n<ul>\n<li>Redirect page CSS loads via wp_enqueue_scripts + wp_head() (no style\/script tags)<\/li>\n<li>Confirmed: no go.php bootstrap; no ABSPATH root file create\/delete<\/li>\n<\/ul>\n\n<h4>1.5.0<\/h4>\n\n<ul>\n<li>Enqueue redirect-page CSS via wp_register_style \/ wp_enqueue_style<\/li>\n<li>Remove legacy go.php bootstrap and all WordPress-root file create\/delete logic<\/li>\n<li>Use only plugin_dir_path \/ plugins_url for plugin file locations<\/li>\n<\/ul>\n\n<h4>1.4.2<\/h4>\n\n<ul>\n<li>Fix Plugin Check findings: prefixed globals, escaping, wp_safe_redirect, wp_parse_url, wp_delete_file, input sanitization<\/li>\n<li>Align Requires at least (6.0) between readme and plugin header<\/li>\n<li>Remove discouraged load_plugin_textdomain() call<\/li>\n<\/ul>\n\n<h4>1.4.1<\/h4>\n\n<ul>\n<li>Compliance and packaging: proper readme.txt, uninstall.php, directory index guards<\/li>\n<li>Remove HTML from plugin header description<\/li>\n<li>Prefer uninstall.php for cleanup<\/li>\n<\/ul>\n\n<h4>1.4.0<\/h4>\n\n<ul>\n<li>Default redirect format changed to <code>\/?goto=TOKEN<\/code> (WordPress query var), no root file write<\/li>\n<li>Removed automatic root <code>go.php<\/code> installation and cleaned legacy files<\/li>\n<\/ul>\n\n<h4>1.3.0<\/h4>\n\n<ul>\n<li>Used site-root <code>\/go.php?url=<\/code> links<\/li>\n<li>Auto-created root <code>go.php<\/code> on activation (removed in 1.4.0)<\/li>\n<\/ul>\n\n<h4>1.2.0<\/h4>\n\n<ul>\n<li>Fixed link regex so common <code>href=\"...\"<\/code> attributes are matched<\/li>\n<li>Improved internal\/external host detection (www \/ home_url \/ site_url)<\/li>\n<li>Added option to skip conversion for logged-in administrators<\/li>\n<li>Process content after shortcodes (priority 20)<\/li>\n<\/ul>\n\n<h4>1.1.0<\/h4>\n\n<ul>\n<li>Added HMAC-signed tokens to mitigate open redirects<\/li>\n<li>Fixed whitelist newline parsing<\/li>\n<li>Fixed protocol-relative URLs treated as internal<\/li>\n<li>Added redirect template; allow only http\/https targets<\/li>\n<\/ul>\n\n<h4>1.0.0<\/h4>\n\n<ul>\n<li>Initial release.<\/li>\n<\/ul>","raw_excerpt":"Convert post external links into signed redirect URLs (?goto=), with whitelist, nofollow, and intermediate page options.","jetpack_sharing_enabled":true,"_links":{"self":[{"href":"https:\/\/as.wordpress.org\/plugins\/wp-json\/wp\/v2\/plugin\/375839","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/as.wordpress.org\/plugins\/wp-json\/wp\/v2\/plugin"}],"about":[{"href":"https:\/\/as.wordpress.org\/plugins\/wp-json\/wp\/v2\/types\/plugin"}],"replies":[{"embeddable":true,"href":"https:\/\/as.wordpress.org\/plugins\/wp-json\/wp\/v2\/comments?post=375839"}],"author":[{"embeddable":true,"href":"https:\/\/as.wordpress.org\/plugins\/wp-json\/wporg\/v1\/users\/laobuluo"}],"wp:attachment":[{"href":"https:\/\/as.wordpress.org\/plugins\/wp-json\/wp\/v2\/media?parent=375839"}],"wp:term":[{"taxonomy":"plugin_section","embeddable":true,"href":"https:\/\/as.wordpress.org\/plugins\/wp-json\/wp\/v2\/plugin_section?post=375839"},{"taxonomy":"plugin_tags","embeddable":true,"href":"https:\/\/as.wordpress.org\/plugins\/wp-json\/wp\/v2\/plugin_tags?post=375839"},{"taxonomy":"plugin_category","embeddable":true,"href":"https:\/\/as.wordpress.org\/plugins\/wp-json\/wp\/v2\/plugin_category?post=375839"},{"taxonomy":"plugin_contributors","embeddable":true,"href":"https:\/\/as.wordpress.org\/plugins\/wp-json\/wp\/v2\/plugin_contributors?post=375839"},{"taxonomy":"plugin_business_model","embeddable":true,"href":"https:\/\/as.wordpress.org\/plugins\/wp-json\/wp\/v2\/plugin_business_model?post=375839"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}