Since its inception, WordPress has relied on the KSES1 subsystem to sanitize HTML. Its purpose has grown and changed over time, but primarily serves two purposes: correct aesthetic defects that are likely the result of typos or pasting errors; and remove security risks that might appear in untrusted inputs. The original kses library was written before HTML5 fully-formalized HTML parsing and at a time when it was common to “hand type” HTML. Today, however, there is no such thing as “seriously malformed2” HTML and most people author content through rich editors, such as WordPress’ Block editor.

Click here to continue reading this article.