Progress Report: wp_kses()

Since its inception, WordPress has relied on the KSES1 subsystem to sanitize HTMLHTML HyperText Markup Language. The semantic scripting language primarily used for outputting content in web browsers.. Its purpose has grown and changed over time, but primarily serves two purposes: correct aesthetic defects that are likely the result of typos or pasting errors; and remove security risks that might appear in untrusted inputs. The original kses library was written before HTML5 fully-formalized HTML parsing and at a time when it was common to “hand type” HTML. Today, however, there is no such thing as “seriously malformed2” HTML and most people author content through rich editors, such as WordPress’ BlockBlock Block is the abstract term used to describe units of markup that, composed together, form the content or layout of a webpage using the WordPress editor. The idea combines concepts of what in the past may have achieved with shortcodes, custom HTML, and embed discovery into a single consistent API and user experience. editor. This means that today, the primary purpose of wp_kses() is to prune out risks from untrusted inputs, and it’s time for it to get an overhaul.

As part of #66208, PR#13271 replaced the implementation of wp_kses() with a new one based on the HTML API. This update replaces a complicated chain of functions, string processing, PCRE regular expressions, and outdated logic to ensure that WordPress can perform its sanitization role reliably and comprehensibly.

Continue reading →

#html-api, #html-api-progress-report, #progress-report