scriptygoddess

03 Oct, 2002

sanitize plugin

Posted by: kristine In: MT hacks

Worried about people posting malicious code in your comments, but still want the functionality of HTML enabled comments?? You might want to check out the MT Sanitize Plugin. It "allows you to clean HTML and other markup that might exist in an comment entry." It will let you list the acceptable HTML that you allow in your comments, and then it filters out the rest. Smart!
To run MT Plugins, you need to be using MT2.21 or higher.

4 Responses to "sanitize plugin"

1 | robyn

October 4th, 2002 at 3:56 am

Avatar

Hey thanks — very easy to install!

2 | Mariann

October 4th, 2002 at 7:06 am

Avatar

I added that plug-in yesterday after I saw it on your LoveLinks blog… I never thought about malicious code in the comments, but I do recall some experiences where code had been added and never showed up the email notification so I didn't realize there was code in the comments until I saw it on the actual comment page. I'm very grateful for this plug-in, even if my comment scale is fairly low — better to be prepared than regretful later on!

3 | Jennifer

October 4th, 2002 at 8:58 am

Avatar

Very neat! EXTREMELY easy install!!

One of the things I like about it – is it doesn't actually remove those tags from the comment itself – it just won't write it to your page. So, in the examle that's often seen here – people putting PHP code in and forgetting to "ascii-ize" it – it just makes it so the pages doesn't break – but I can still go on change the appropriate characters to ascii and make it so the code shows…

4 | Quadsk8

October 4th, 2002 at 1:05 pm

Avatar

Just to let you know about an alternative, at the same time Brad Chaote wrote this plugin L.M.Orchard had the same idea and wrote this 0decafbad MTCleanHTMLPlugin.

I only installed the last one and thinks it works good!

Featured Sponsors

Genesis Framework for WordPress

Advertise Here


  • Scott: Just moved changed the site URL as WP's installed in a subfolder. Cookie clearance worked for me. Thanks!
  • Stephen Lareau: Hi great blog thanks. Just thought I would add that it helps to put target = like this:1-800-555-1212 and
  • Cord Blomquist: Jennifer, you may want to check out tp2wp.com, a new service my company just launched that converts TypePad and Movable Type export files into WordPre

About


Advertisements