Free tools Windows power users keep installed
One-click scans. No signup required.
iTechGuides is reader-supported. When you buy through links on our site, we may earn an affiliate commission. As an Amazon Associate I earn from qualifying purchases. Learn more
wp_kses() removes markup that is not permitted by the rules you pass to it. To keep a tag, check the function’s second argument, then allow the lowercase tag and only the attributes your output needs. An allowed element does not automatically make every attribute or value acceptable.
What wp_kses filters
wp_kses() returns HTML filtered against an allow-list: it checks elements, attributes, attribute values, and entities. It does not guess which markup you intended to preserve. The second argument can be an explicit array of allowed HTML or a named context such as post. WordPress’s function reference documents both forms.
Start with the string immediately before the call and the returned string immediately after it. Then inspect the actual call site and identify which rules are being supplied. A tag disappearing usually means the active rules do not allow it; an attribute disappearing can mean the element is allowed but that attribute or its value is not.
The Tool Desk
Outbyte PC Repair FREERepair Windows errors before they cause bigger problemsFix Now →Outbyte Driver Updater FREEFix the driver behind crashes, sound loss and screen glitchesFind Drivers →Check whether you passed an allow-list or a context
Explicit allow-list
With an array, the array itself defines the permitted elements and attributes. Add the needed tag and its required attributes, using lowercase names. Keep the list narrow rather than allowing attributes you do not use.
#1 Best Overall
$allowed_html = array(
'a' => array(
'href' => true,
),
);
$clean_html = wp_kses( $html, $allowed_html );
This example permits the a element and its href attribute. It is not a universal policy: include only the markup appropriate for your content and application. WordPress’s escaping handbook shows the selected-tags approach for HTML that should remain in output.
Named context
If the second argument is a context name, inspect the rules for that context rather than assuming your custom tag is included. wp_kses_allowed_html() returns the rules for a context, and the wp_kses_allowed_html filter is the documented way to customize them. See the context function reference for details.
Context rules can also be affected by a plugin or theme. If the rules differ from what you expect, check the site’s code for callbacks that modify wp_kses_allowed_html.
Recommended Free Tools
Allow the tag, attributes, and values you actually need
Use lowercase tag and attribute names in an explicit allow-list; WordPress does not recognize mixed-case or uppercase entries as permitted. Then check each layer independently:
- Element: Is the tag present in the rules?
- Attribute: Is the specific attribute listed for that tag?
- Value: Do the rules permit the attribute’s actual value?
These are separate checks. Adding a tag alone does not permit all its attributes, and allowing an attribute does not necessarily accept every value. The WordPress handbook example demonstrates an allow-list that retains only selected tags and attributes.
Choose the post wrapper only when its context fits
wp_kses_post() filters content using the post context; its function reference describes it as a call to wp_kses( $data, 'post' ). Use it when the post context matches the HTML you intend to preserve. If the output needs a narrower or different set of tags, use wp_kses() with rules chosen for that purpose. WordPress documents the wrapper here.
Rank #4
Both wp_kses() and wp_kses_post() expect unslashed data. Do not assume the slashed-input contract of wp_filter_post_kses() applies to direct calls: that separate function strips and restores slashes around its filtering operation. Its reference describes that behavior.
Quick wins for a faster PC:
Clear out junk files and repair common Windows errorsFree Scan →Fix the driver behind crashes, sound loss and screen glitchesFind Drivers →Escape when you output the value
Sanitizing HTML for an allow-list and escaping output address related but distinct concerns. Use KSES when permitted HTML should remain; use plain-text escaping when the output is not supposed to contain HTML. Choose the escaping function for the output context, and escape when rendering rather than treating an earlier sanitization step as a substitute. As the WordPress escaping handbook puts it: “You always want to escape when you echo, not before.”
Quick Recap
Best Value
Product prices and availability are accurate as of the date/time indicated and are subject to change. Any price and availability information displayed on Amazon at the time of purchase will apply.

