Download the PHP package wackowiki/safehtml without Composer

On this page you can find all versions of the php package wackowiki/safehtml. It is possible to download/install these versions without Composer. Possible dependencies are resolved automatically.

FAQ

After the download, you have to make one include require_once('vendor/autoload.php');. After that you have to import the classes with use statements.

Example:
If you use only one package a project is not needed. But if you use more then one package, without a project it is not possible to import the classes with use statements.

In general, it is recommended to use always a project to download your libraries. In an application normally there is more than one library needed.
Some PHP packages are not free to download and because of that hosted in private repositories. In this case some credentials are needed to access such packages. Please use the auth.json textarea to insert credentials, if a package is coming from a private repository. You can look here for more information.

  • Some hosting areas are not accessible by a terminal or SSH. Then it is not possible to use Composer.
  • To use Composer is sometimes complicated. Especially for beginners.
  • Composer needs much resources. Sometimes they are not available on a simple webspace.
  • If you are using private repositories you don't need to share your credentials. You can set up everything on our site and then you provide a simple download link to your team member.
  • Simplify your Composer build process. Use our own command line tool to download the vendor folder as binary. This makes your build process faster and you don't need to expose your credentials for private repositories.
Please rate this library. Is it a good library?

Informations about the package safehtml

SafeHTML

SafeHTML is a defensive HTML filter for PHP that strips down all potentially dangerous content within HTML to protect against XSS (Cross-Site Scripting) and other code-injection attacks.

It is a continuation of the original HTML_Safe parser by Roman Ivanov, maintained by the WackoWiki project.


Features


Requirements


Installation


Quick Start


Configuration

All filtering behaviour is controlled by public properties on the SafeHTML class. Override only what you need:

Protocol filtering modes

Mode Description
WHITELIST (default) Allow only listed whiteProtocols.
BLACKLIST Allow everything except blackProtocols.

Built-in whitelisted protocols

ed2k, file, ftp, gopher, http, https, irc, mailto, news, nntp, telnet, webcal, xmpp, callto

Built-in blacklisted protocols

about, chrome, data, disk, hcp, help, javascript, livescript, lynxcgi, lynxexec, ms-help, ms-its, mhtml, mocha, opera, res, resource, shell, vbscript, view-source, vnd.ms.radio, wysiwyg


API

SafeHTML::parse(string $doc): string

Main entry point. Parses $doc and returns the sanitised XHTML.

SafeHTML::setAllowTags(array $tags): void

Whitelist a set of otherwise-forbidden tags.

SafeHTML::getAllowTags(): array

Returns the currently allowed tags.

SafeHTML::resetAllowTags(): void

Clears the allowed-tags list.

SafeHTML::getXHTML(): string

Returns the accumulated output and closes any remaining open tags.

SafeHTML::clear(): void

Resets internal state so the parser instance can be reused.

ProtocolFilterMode (enum)

Constant Value
BLACKLIST 'black'
WHITELIST 'white'

Running Tests

Static analysis:


Security Notes

SafeHTML is a defence-in-depth layer. It is not a substitute for context-aware output encoding (htmlspecialchars(), etc.). For modern PHP applications, prefer using a dedicated HTML sanitiser like HTML Purifier or DOMDocument-based solutions when you need full HTML5 support.

SafeHTML still excels in legacy code-bases and as a fast, dependency-light first-pass filter where you control the input format.


License

This project is licensed under the BSD 3-Clause License — see the LICENSE file for details.


Credits


All versions of safehtml with dependencies

PHP Build Version
Package Version
Requires php Version ^8.1
wackowiki/htmlsax3 Version ^4.1
Composer command for our command line client (download client) This client runs in each environment. You don't need a specific PHP version etc. The first 20 API calls are free. Standard composer command

The package wackowiki/safehtml contains the following files

Loading the files please wait ...