Signatur
strip_tags(string $string, array|string|null $allowed_tags = null): string
Beschreibung
Achtung: Für sicheres Sanitizing von HTML-Input reicht das nicht. Nutze HTMLPurifier oder Symfony HtmlSanitizer für echten XSS-Schutz.
Parameter
| Name | Typ | Default | Beschreibung |
|---|---|---|---|
| $string Pflicht | string | — | Eingabe. |
| $allowed_tags | array|string|null | null | Erlaubte Tags. |
Rückgabewert
Typ
string
Beschreibung
Text ohne Tags.
Beispiele
Basis
<?php
echo strip_tags('<p>Hallo <b>Welt</b></p>'); // Hallo Welt
Whitelist
<?php
echo strip_tags($html, ['b', 'i', 'a']);
// Wichtig · Fallstricke
Nie für User-HTML-Input als einziger Schutz. Attribute wie onclick=... werden nicht entfernt.