HTML Purified replaces the default comments filters with the more secure HTML Purifier.
As of April 2026, HTML Purified is a WordPress xss plugin with 50 active installations and a 0/5 rating0. It has been downloaded 17K+ times in total. Requires WordPress 2.9+ and PHP false+. Available on WordPress.org since 2007. Last updated 13 years ago — may have compatibility concerns. Top alternative: Prevent XSS Vulnerability.
HTML Purified replaces the default WordPress comments filters with HTML Purifier, a super HTML filtering
library.
HTML Purifier is a standards-compliant HTML filter library written in PHP. HTML Purifier will
not only remove all malicious code (better known as XSS) with a thoroughly audited, secure yet
permissive whitelist, it will also make sure your documents are standards compliant, something
only achievable with a comprehensive knowledge of W3C’s specifications.
An additional feature of HTML Purifier is that it will produce valid well-formed XHTML code, something
which KSES does not do.
Features:
| WordPress | 2.9+ requiredTested up to 3.3.2 |
| PHP | false+ required |
Plugin data sourced from WordPress.org. Analysis and metrics by PluginSift.