SkillAgentSearch skills...

HTMLawed

a highly customizable PHP script to sanitize / make (X)HTML secure against XSS attacks, so users can edit HTML without risk of your site getting compromised by evildoers.

Install / Use

/learn @kesar/HTMLawed
About this skill

Quality Score

0/100

Supported Platforms

Universal

README

HTMLawed is ...

... a single-file, 45 kb PHP script that makes input text more secure, HTML standards-compliant, and suitable in general from the viewpoint of a web-page administrator, for use in the body of HTML, XHTML or XML documents. A simple HTMLTidy alternative, the htmLawed filter, processor, purifier, sanitizer, beautifier, etc., is highly customizable.

It ensures that HTML tags are balanced and properly nested tags, neutralizes code that may be used for cross-site scripting (XSS) attacks, limits allowed HTML elements, attributes, or URL protocols, tidies the code, and so forth.

As such is may serve as an alternative to HTMLtidy in a sanitation context.

This repository is ...

... a derivative, which closely tracks the original

Links

  • The Original: http://www.bioinformatics.org/phplabware/internal_utilities/htmLawed/
  • The SF site where the official Original Releases are available (no cvs/svn/... repository there, though, just releases): http://sourceforge.net/projects/htmlawed/
  • HTMLawed against RSnake's XSS attack vectors: http://www.bioinformatics.org/phplabware/internal_utilities/htmLawed/rsnake/RSnakeXSSTest.htm

Related Skills

View on GitHub
GitHub Stars40
CategoryDevelopment
Updated5mo ago
Forks17

Languages

HTML

Security Score

87/100

Audited on Oct 30, 2025

No findings