PHP Classes

allowHTML: Filter insecure HTML following OWASP AntiSamy

Recommend this page to a friend!
  Info   View files View files (3)   DownloadInstall with Composer Download .zip   Reputation   Support forum   Blog    
Last Updated Ratings Unique User Downloads Download Rankings
2010-11-28 (5 years ago) RSS 2.0 feedStarStarStarStar 64%Total: 721 This week: 3All time: 4,399 This week: 384Up
Version License PHP version Categories
allowhtml 1.0.0BSD License5HTML, Validation, Security
Description Author

This class can be used to filter insecure HTML following OWASP AntiSamy rules.

It can parse HTML documents using DOM document objects and then remove unsafe tags, attributes and CSS parameters.

It uses a configurable whitelist to determine which tags, attributes and CSS style parameters are allowed.

The class may also apply filtering rules defined in a separate AntiSamy XML rules file.

Innovation Award
PHP Programming Innovation award nominee
December 2010
Number 9
AntiSamy is a project of OWASP to define rules that secure applications must apply to HTML in order to filter insecure tags.

This class is secure HTML filter that can apply OWASP AntiSamy rules.

Manuel Lemos
Picture of Simon Emery
Name: Simon Emery <contact>
Classes: 1 package by
Country: United Kingdom United Kingdom
Age: ???
All time rank: 2632116 in United Kingdom United Kingdom
Week rank: 395 Up12 in United Kingdom United Kingdom Up
Innovation award
Innovation award
Nominee: 1x

  Files folder image Files  
File Role Description
Files folder imageexample (1 file)
Files folder imagexml (1 file)
Plain text file allowHTML.php Class Main class

  Files folder image Files  /  example  
File Role Description
  Accessible without login Plain text file example.php Example Example of class usage

  Files folder image Files  /  xml  
File Role Description
  Plain text file antisamy.xml Aux. Anti-Samy XML policy file

 Version Control Unique User Downloads Download Rankings  
This week:3
All time:4,399
This week:384Up
 User Ratings  
 All time