Download the PHP package phlib/xss-sanitizer without Composer
On this page you can find all versions of the php package phlib/xss-sanitizer. It is possible to download/install these versions without Composer. Possible dependencies are resolved automatically.
Download phlib/xss-sanitizer
More information about phlib/xss-sanitizer
Files in phlib/xss-sanitizer
Package xss-sanitizer
Short Description PHP XSS sanitizer tool for HTML
License LGPL-3.0
Informations about the package xss-sanitizer
phlib/xss-sanitizer
PHP XSS sanitizer tool for HTML
Disclaimer
Use HTML Purifier.
This library was created to try to solve the problem of XSS sanitization without using a permissive list, since the HTML which is being sanitized may contain non-standard or unusual syntax (e.g. HTML for emails).
This library is also intended for a limited use case whereby it is assumed that the sanitized HTML is only going to be displayed in a limited set of supported browsers (e.g. no need to strip 'vbscript:' code).
Install
Via Composer
Usage
Create a sanitizer and sanitize some input:
Optionally, extra tags and/or attributes can be specified to be removed, in addition to the defaults:
Supported Browsers
This library is intended to prevent XSS vulnerabilities when the resulting HTML is rendered by any of the following browsers:
- Chrome (40+)
- Firefox (40+)
- Safari (8+)
- IE (10, 11)
- Edge
License
This package is free software: you can redistribute it and/or modify it under the terms of the GNU Lesser General Public License as published by the Free Software Foundation, either version 3 of the License, or (at your option) any later version.
This program is distributed in the hope that it will be useful, but WITHOUT ANY WARRANTY; without even the implied warranty of MERCHANTABILITY or FITNESS FOR A PARTICULAR PURPOSE. See the GNU Lesser General Public License for more details.
You should have received a copy of the GNU Lesser General Public License along with this program. If not, see http://www.gnu.org/licenses/.
All versions of xss-sanitizer with dependencies
ext-mbstring Version *