Skip to content

KSES: Deprecate wp_kses_html_error(). - #13821

Open
dmsnell wants to merge 1 commit into
WordPress:trunkfrom
dmsnell:kses/deprecate-wp-kses-html-error
Open

dmsnell wants to merge 1 commit into
WordPress:trunkfrom
dmsnell:kses/deprecate-wp-kses-html-error

Conversation

@dmsnell

@dmsnell dmsnell commented Sep 29, 2026

Copy link
Copy Markdown
Member

Trac ticket: Core-63724.

Follow-up to r61467 (#9248)

As wp_kses_hair() was the only place in Core calling wp_kses_html_error(), this change deprecates the leftover function.

@github-actions

github-actions Bot commented Sep 29, 2026 •

Copy link
Copy Markdown

The following accounts have interacted with this PR and/or linked issues. I will continue to update these lists as activity occurs. You can also manually ask me to refresh this list by adding the props-bot label.

Core Committers: Use this line as a base for the props when committing in SVN:

Props dmsnell, westonruter.

To understand the WordPress project's expectations around crediting contributors, please review the Contributor Attribution page in the Core Handbook.

@github-actions

Copy link
Copy Markdown

Test using WordPress Playground

The changes in this pull request can previewed and tested using a WordPress Playground instance.

WordPress Playground is an experimental project that creates a full WordPress instance entirely within the browser.

Some things to be aware of

  • All changes will be lost when closing a tab with a Playground instance.
  • All changes will be lost when refreshing the page.
  • A fresh instance is created each time the link below is clicked.
  • Every time this pull request is updated, a new ZIP file containing all changes is created. If changes are not reflected in the Playground instance,
    it's possible that the most recent build failed, or has not completed. Check the list of workflow runs to be sure.

For more details about these limitations and more, check out the Limitations page in the WordPress Playground documentation.

Test this pull request with WordPress Playground.

@westonruter

Copy link
Copy Markdown
Member

Should this be moved to deprecated.php? Another such Kses function was moved there:

/**
* Removes the HTML JavaScript entities found in early versions of Netscape 4.
*
* Previously, this function was pulled in from the original
* import of kses and removed a specific vulnerability only
* existent in early version of Netscape 4. However, this
* vulnerability never affected any other browsers and can
* be considered safe for the modern web.
*
* The regular expression which sanitized this vulnerability
* has been removed in consideration of the performance and
* energy demands it placed, now merely passing through its
* input to the return.
*
* @since 1.0.0
* @deprecated 4.7.0 Officially dropped security support for Netscape 4.
*
* @param string $content
* @return string
*/
function wp_kses_js_entities( $content ) {
_deprecated_function( __FUNCTION__, '4.7.0' );
return preg_replace( '%&\s*\{[^}]*(\}\s*;?|$)%', '', $content );
}

Comment thread src/wp-includes/kses.php Outdated
* but it deals with quotes and apostrophes as well.
*
* @since 1.0.0
* @deprecated 7.2.0

Copy link
Copy Markdown
Member

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Often a description is included explaining why it was deprecated.

Copy link
Copy Markdown
Member Author

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Initially I refrained, because there is no alternative recommendation, but I see that a number of existing functions and methods list why. Thanks for pointing that out!

Copy link
Copy Markdown
Member Author

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Another such Kses function was moved there:

ha! one of my first contributions…

Copy link
Copy Markdown
Member Author

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

moved and described in 614d6b7

@westonruter

Copy link
Copy Markdown
Member

FYI: Instances of this function being used by plugins: https://veloria.dev/search/6467e2b9-c246-44ea-a4fd-618cf475fb9f

@dmsnell

dmsnell commented Sep 29, 2026

Copy link
Copy Markdown
Member Author

Instances of this function being used by plugins

@westonruter I think the linked search examines instances of plugins calling wp_kses_hair(), not wp_kses_html_error(). There were only three matches that I saw in the directory for wp_kses_html_error(), two of which were from internal vendored copies of Core (thus, not affected by this change). The third case was using this function in a way that seemed clearly incongruous with its intention and behavior, and was installed in only a small set of active installs, so I believe this change should be safe from the ecosystem standpoint.

Originally I had drafted notes about the plugin search, but then it felt less appropriate in the PR description given the results I found, and given that the only call to the function is likely using it inappropriately.

@dmsnell
dmsnell force-pushed the kses/deprecate-wp-kses-html-error branch from 1cb8c8a to 614d6b7 Compare September 29, 2026 17:51
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants