Plugin info

Total downloads: 17,484
Active installs: 60
Total reviews: 0
Average rating: 0
Support threads opened: 0
Support threads resolved: 0 (0%)
Available in: 1 language(s)
Contributors: 2
Last updated: 5/5/2012 (4988 days ago)
Added to WordPress: 8/17/2007 (18 years old)
Minimum WordPress version: 2.9
Tested up to WordPress version: 3.3.2
Minimum PHP version: f

Maintenance & Compatibility

Maintenance score

Possibly abandoned • Last updated 4988 days ago

20/100

Is HTML Purified abandoned?

Possibly abandoned (last update 4988 days ago).

Compatibility

Requires WordPress: 2.9
Tested up to: 3.3.2
Requires PHP: f

Similar & Alternatives

Explore plugins with similar tags, and compare key metrics like downloads, ratings, updates, support, and WP/PHP compatibility.

Prevent XSS Vulnerability
Rating 5.0/5 (7 reviews)Active installs 7,000
Content Security Policy Manager
Rating 4.3/5 (6 reviews)Active installs 2,000
Pareto Security
Rating 4.8/5 (20 reviews)Active installs 400
Basic Security: Prevent Cross Site Scripting
Rating 5.0/5 (1 reviews)Active installs 200
Shieldfy Security Firewall and Anti Virus
Rating 5.0/5 (3 reviews)Active installs 40
MJP Security Plugin
Rating 0.0/5 (0 reviews)Active installs 10

Description

HTML Purified replaces the default WordPress comments filters with HTML Purifier, a super HTML filtering
library.

HTML Purifier is a standards-compliant HTML filter library written in PHP. HTML Purifier will
not only remove all malicious code (better known as XSS) with a thoroughly audited, secure yet
permissive whitelist, it will also make sure your documents are standards compliant, something
only achievable with a comprehensive knowledge of W3C’s specifications.

An additional feature of HTML Purifier is that it will produce valid well-formed XHTML code, something
which KSES does not do.

Features:

  • Configurable KSES or HTML Purifier
  • Configurable list of HTML elements and attributes for both KSES and HTML purifier
  • Additionally process comments with HTML Tidy
  • URL blacklist
  • Fully localized (and awaiting translations)
  • Automatically escape PHP or anything inside backticks

HTML Purifier is available in:

  • English
  • Spanish, thanks to José Cuesta
  • Belorussian, thanks to Marcis Gasuns
  • Russian, thanks to Ilyuha
  • Uzbekistan, thanks to Alexandra Bolshova
  • Dutch, thanks to Pieter
  • German, thanks to Andreas Beraz
  • Polish, thanks to Kasia Ciszewski & Dawid Śpiechowicz
  • Romanian, thanks to Alina @ InboxTranslations.com
  • Lithuanian, thanks to Nata Strazda
  • Ukranian, thanks to Iflexion Design

Documentation

Full documentation can be found on the HTML Purified page.

Installation

The plugin is simple to install:

  1. Download html-purified.zip
  2. Unzip
  3. Upload html-purified directory to your /wp-content/plugins directory
  4. Go to the plugin management page and enable the plugin
  5. Configure the options from the Options/HTML Purified page

You can find full details of installing a plugin on the plugin installation page.

Frequently Asked Questions

Why would I want to replace the default WordPress filter?

There is nothing fundamentally wrong with the way WordPress filters comments, and in fact there has been no security alert related to this. However, this doesn’t detract from the desire to make things better, and the fact that HTML Purifier is much more thorough and exhaustive.

Does this plugin also protect posts?

Not currently, no, but it is planned for a future version

Review feed

No reviews available

Screenshots

  1. Main options page allowing specific HTML tags

    Main options page allowing specific HTML tags

  2. Specific configuration options for HTML Purifier

    Specific configuration options for HTML Purifier

Changelog

0.2

  • Initial released version

0.2.1

  • Change cache directory
  • Allow no tag
  • Update HTML purifier to 2.0.1

0.2.2

  • Update HTML purifier to 2.1.1

0.2.4

  • Fix cache directory write error

0.2.5

  • Add Spanish localization

0.2.6

  • Add auto-escape PHP option
  • Update to HTML purifier 2.1.2

0.2.7

  • Add option for bbcode-style tags
  • Update to HTML Purifier 2.1.3

0.2.8

  • Now works in bbPress!

0.2.9

  • Update plugin library

0.3.0

  • HTML Purifier PHP4 2.1.5, PHP5 3.1.1 – WP 2.5.1

0.3.1

  • WP 2.6

0.3.2

  • Update base library

0.3.3

  • bbPress working again
  • Clean up code

0.3.4

  • WP 2.8
  • Support for syntaxhighlighter
  • Fixes to backticks

0.3.5

  • Add Uzbekistan
  • Add Russian

0.4

  • PHP5 only
  • Update to HTML Purifier 4.2.0
  • Add German
  • Add Dutch

0.5

  • Add Polish translation, thanks to Kasia Ciszewski & Dawid Śpiechowicz

0.6

  • Add Lithuanian
  • Add Ukranian

0.7

  • Code cleanup