WordPress Plugin Security: Sanitizing Output

Sanitizing output for plugin security is the process of stripping unwanted data which will be rendered to users. The unwanted data can be incorrect HTML or script tags. This process usually called escaping data. Escaping data can help in preventing Cross-Site Scripting.

For the most common scenarios, these functions can be help securing WordPress:

  • esc\_html()
  • esc\_url()
  • esc\_js()
  • esc\_attr()


WordPress Plugin Handbook: Securing Output