Decide whether you want to keep only selected tags or remove a few named tags while preserving other markup. Those are different operations. For untrusted HTML, use a sanitizer with explicit rules for allowed tags, attributes, and URL protocols; a tag-stripping function alone may leave risky attributes behind.
Choose the behavior you need
- Keep only certain tags: set an allowlist of permitted tags, then separately specify permitted attributes and URL protocols.
- Remove only certain tags: use an HTML parser or sanitizer API that directly supports removing those elements while leaving other markup intact. An allowlist is not equivalent: it removes or neutralizes everything outside the allowed set.
For either task, avoid treating regular-expression replacements as a general solution for arbitrary or malformed HTML. Use a tool that parses HTML according to HTML rules.
| # | Preview | Product | Price | |
|---|---|---|---|---|
| 1 |
|
Editors Keys Dedicated Keyboard for Photoshop | PC Shortcut Keyboard | $99.99 | Buy on Amazon |
| 2 |
|
Online-Welcome Vi and Vim Editor Keyboard Shortcut (11.5 x 13 mm) | $11.97 | Buy on Amazon |
PHP: keep selected tags with strip_tags()
PHP’s strip_tags() accepts an optional allowed-tags argument. This example keeps <b> while stripping other tags:
$html = '<p>Hello <b>world</b> <script>alert(1)</script></p>';
echo strip_tags($html, '<b>');
The PHP Manual notes that HTML comments and PHP tags are stripped regardless of the allowed-tags argument. More importantly, strip_tags() does not modify attributes on tags it retains. An allowed tag could therefore keep attributes such as style or onmouseover. Do not use this example as a complete sanitizer for untrusted HTML. See the PHP Manual for strip_tags().
Recommended Free Tools
Python: configure an HTML allowlist with Bleach
Bleach’s documented clean() API lets you specify allowed tags, per-tag attributes, URL protocols, and what to do with disallowed tags. This example permits a small set of tags and link attributes, allows only the listed protocols, and strips disallowed tag markup while retaining its text:
import bleach
clean_html = bleach.clean(
untrusted_html,
tags={"b", "i", "a"},
attributes={"a": ["href", "title"]},
protocols={"http", "https", "mailto"},
strip=True,
)
The tag set is the element allowlist; the attribute map is a separate policy. If links are permitted, the protocol set limits which schemes are accepted. Bleach documents http, https, and mailto as its default protocols, but this example states them explicitly. Its documentation identifies release 6.4.0 and describes parsing according to the HTML5 parsing algorithm. See Bleach’s cleaning documentation.
Rank #2
- vi and vim keyboard sticker
- VI VIM EDITOR KEYBOARD SHORTCUT
- vi and vim editor
- vi/vim editor
- vi vim mgedit software
Strip or escape disallowed tags
Bleach escapes disallowed tags by default. Set strip=True when you want the disallowed tag markup removed while leaving the text between those tags. Choose deliberately: escaping displays markup as text; stripping removes the markup itself.
Match sanitization to where the result will be used
Sanitized HTML is not automatically safe in every output context. Bleach says its cleaner is intended for HTML fragments, not for direct use in contexts such as HTML attributes, CSS, JavaScript, JSON, XHTML, or SVG without appropriate context-specific handling. OWASP likewise distinguishes defenses by output context and recommends DOMPurify for HTML sanitization. See the OWASP Cross Site Scripting Prevention Cheat Sheet.
Quick Recap
- For HTML fragments, define the tags and attributes the content needs, and restrict URI protocols where links or other URI-bearing attributes are allowed.
- For a different destination, use output handling appropriate to that context rather than assuming HTML sanitization is sufficient.
- If your requirement is to remove just a few elements while preserving all other markup, select a parser or API for your language that expresses that exact removal policy.
Quick decision guide
| Goal | Approach | Important distinction |
|---|---|---|
| Keep a small set of tags in untrusted HTML | Use an allowlist sanitizer, such as Bleach’s documented cleaner | Set tag, attribute, and protocol rules separately; choose whether disallowed markup is escaped or stripped. |
| Keep selected tags in simple PHP input | Use strip_tags($html, '<b>') with the desired allowed tags |
Retained tags’ attributes are not modified, so this alone is not safe sanitization for untrusted markup. |
| Remove only named elements and preserve other markup | Use an HTML parser or sanitizer API with a removal policy | This is not the same as allowing only a chosen set of tags. |
Product prices and availability are accurate as of the date/time indicated and are subject to change. Any price and availability information displayed on Amazon at the time of purchase will apply.




