0
0
mirror of https://github.com/ezyang/htmlpurifier.git synced 2024-11-08 06:48:42 +00:00
Standards compliant HTML filter written in PHP. http://htmlpurifier.org
Go to file
semantic-release-bot cb56001e54 chore(release): 4.18.0 [skip ci]
# [4.18.0](https://github.com/ezyang/htmlpurifier/compare/v4.17.0...v4.18.0) (2024-11-01)

### Bug Fixes

* Adjust Core.AllowHostnameUnderscore to consider that "_" is defined as Unreserved Characters in RFC 3986 ([#406](https://github.com/ezyang/htmlpurifier/issues/406)) ([d9fbef8](d9fbef8e27))
* Avoid a deprecated error when the attribute name is numeric and DirectLex is used ([#412](https://github.com/ezyang/htmlpurifier/issues/412)) ([f0fbf51](f0fbf51098))
* checking that node has property name ([#399](https://github.com/ezyang/htmlpurifier/issues/399)) ([9ca5a36](9ca5a3687b))
* Ignore conditional comments ([#401](https://github.com/ezyang/htmlpurifier/issues/401)) ([4828fdf](4828fdf45a))
* Support PHP 8.4 ([#396](https://github.com/ezyang/htmlpurifier/issues/396)) ([92da247](92da2473ff))
* undefined array key warning ([#419](https://github.com/ezyang/htmlpurifier/issues/419)) ([01be377](01be377f93))

### Features

* Add allowfullscreen attr for iframe ([#411](https://github.com/ezyang/htmlpurifier/issues/411)) ([70754a2](70754a2533))
* add directive for removing blank nodes ([#404](https://github.com/ezyang/htmlpurifier/issues/404)) ([c9d60c9](c9d60c96d7))
* Add support for CSS aspect-ratio ([#408](https://github.com/ezyang/htmlpurifier/issues/408)) ([93bee73](93bee73349))
* Allow universal CSS values for all properties ([#410](https://github.com/ezyang/htmlpurifier/issues/410)) ([9723267](972326785d))
2024-11-01 03:51:45 +00:00
.github/workflows fix: Support PHP 8.4 (#396) 2024-02-22 00:05:10 -05:00
art [2.0.1] Implement haphazard error collection for AttrValidator. 2007-06-27 02:03:15 +00:00
benchmarks .htaccess support apache 2.4+ (#190) 2018-11-11 14:55:13 -05:00
configdoc chore(release): 4.18.0 [skip ci] 2024-11-01 03:51:45 +00:00
docs Supported hundreds of nested HTML (#202) 2019-07-14 13:15:31 -04:00
extras PHP 8.1: fix various deprecations/errors in newest version of PHP (#310) 2022-04-08 13:48:12 -04:00
library chore(release): 4.18.0 [skip ci] 2024-11-01 03:51:45 +00:00
maintenance feat: add semantic release (#307) 2022-09-18 02:44:00 -04:00
plugins feat: add directive for removing blank nodes (#404) 2024-04-11 20:52:45 -04:00
smoketests Run CSSTidy tests on CI (#338) 2022-09-14 20:55:41 -07:00
tests fix: Avoid a deprecated error when the attribute name is numeric and DirectLex is used (#412) 2024-07-30 22:06:23 -04:00
.gitattributes feat: add semantic release (#307) 2022-09-18 02:44:00 -04:00
.gitignore Improve gitignore. 2013-10-13 00:18:11 -07:00
composer.json fix: Support PHP 8.4 (#396) 2024-02-22 00:05:10 -05:00
CREDITS Add vim modelines to all files. 2008-12-06 04:24:59 -05:00
Doxyfile chore(release): 4.18.0 [skip ci] 2024-11-01 03:51:45 +00:00
INSTALL Delete references to PHP 5.1 in INSTALL. 2018-11-11 16:56:06 -05:00
INSTALL.fr.utf8 Update PHP version in INSTALL (#195) 2018-10-23 20:03:41 -04:00
LICENSE Add vim modelines to all files. 2008-12-06 04:24:59 -05:00
NEWS chore(release): 4.18.0 [skip ci] 2024-11-01 03:51:45 +00:00
package.php feat: add semantic release (#307) 2022-09-18 02:44:00 -04:00
phpdoc.ini Add vim modelines to all files. 2008-12-06 04:24:59 -05:00
README.md PHP 8 Support (#297) 2021-07-20 09:40:50 -04:00
release.config.js fix: semantic release (#341) 2022-09-20 12:45:11 -04:00
test-settings.sample.php Run CSSTidy tests on CI (#338) 2022-09-14 20:55:41 -07:00
TODO Release 4.8.0 2016-07-16 05:58:58 -07:00
update-for-release feat: add semantic release (#307) 2022-09-18 02:44:00 -04:00
VERSION chore(release): 4.18.0 [skip ci] 2024-11-01 03:51:45 +00:00
WYSIWYG Add vim modelines to all files. 2008-12-06 04:24:59 -05:00

HTML Purifier Build Status

HTML Purifier is an HTML filtering solution that uses a unique combination of robust whitelists and aggressive parsing to ensure that not only are XSS attacks thwarted, but the resulting HTML is standards compliant.

HTML Purifier is oriented towards richly formatted documents from untrusted sources that require CSS and a full tag-set. This library can be configured to accept a more restrictive set of tags, but it won't be as efficient as more bare-bones parsers. It will, however, do the job right, which may be more important.

Places to go:

  • See INSTALL for a quick installation guide
  • See docs/ for developer-oriented documentation, code examples and an in-depth installation guide.
  • See WYSIWYG for information on editors like TinyMCE and FCKeditor

HTML Purifier can be found on the web at: http://htmlpurifier.org/

Installation

Package available on Composer.

If you're using Composer to manage dependencies, you can use

$ composer require ezyang/htmlpurifier