esc_html( string $text ): string
- Since
- 2.8.0
- Source
wp-includes/formatting.php:4673
Escape a string for HTML output with esc_html(), converting angle brackets, ampersands, and quotes to entities so untrusted text cannot inject markup. Available since WordPress 2.8.0, it validates the string as UTF-8 and passes the result through the esc_html filter before returning it.
Parameters
$textstring
Return
string
Examples
Every example is editable and runs in a real WordPress booted in your browser by WordPress Playground. Press Run, then edit the code: clicking away re-runs it. Nothing is sent anywhere until you do.
Print an untrusted value inside an HTML element
Anything that came from a form, a URL or the database is untrusted at the point it is printed.
update_post_meta( 2, 'company_name', 'Acme <script>alert(1)</script> Ltd' );
$company = get_post_meta( 2, 'company_name', true );
echo "raw: ", $company, "\n";
echo "escaped: ", esc_html( $company );Escape at the point of output, not when saving, so the stored value stays intact.
Escape a translated string on output
Translations load from external files, so escape them like any other untrusted input (the esc_html__() shorthand combines both steps).
$heading = __( 'Recent projects', 'mytheme' );
echo '<h2>' . esc_html( $heading ) . '</h2>';
// Equivalent one-liner:
echo '<h2>' . esc_html__( 'Recent projects', 'mytheme' ) . '</h2>';esc_html() is for text between tags only; inside attribute values use esc_attr(), and for href/src values use esc_url().
Hooks fired · 1
One hook fires while esc_html() runs, in this order:
- apply_filters( esc_html )filterline 4687 (+14 into the body)
Filters a string cleaned and escaped for output in HTML.
Uses · 3
- wp_check_invalid_utf8()Checks for invalid UTF8 in a string.
- _wp_specialchars()Converts a number of special characters into their HTML entities.
- apply_filters()Calls the callback functions that have been added to a filter hook.
Used by · 50
- Bulk_Upgrader_Skin::error()Displays an error message about the update.
- Custom_Image_Header::step_1()Displays first step of custom header image page.
- Plugin_Installer_Skin::do_overwrite()Checks if the plugin can be overwritten and outputs the HTML for overwriting a plugin on upload.
- Theme_Installer_Skin::do_overwrite()Checks if the theme can be overwritten and outputs the HTML for overwriting a theme on upload.
- TwentyTwenty_Walker_Comment::html5_comment()Outputs a comment in the HTML5 format.
- Twenty_Fourteen_Ephemera_Widget::form()Display the form for this widget on the Widgets page of the Admin area.
- Twenty_Fourteen_Ephemera_Widget::widget()Output the HTML for this widget.
- WP_Ajax_Upgrader_Skin::get_error_messages()Retrieves a string for error messages.
- WP_Application_Passwords_List_Table::column_name()Handles the name column output.
- WP_Block_Metadata_Registry::register_collection()Registers a block metadata collection.
- WP_Comments_List_Table::column_author()
- WP_Comments_List_Table::column_comment()
Show all 50
- WP_Comments_List_Table::column_response()
- WP_Comments_List_Table::comment_type_dropdown()Displays a comment type drop-down for filtering on the Comments list table.
- WP_Comments_List_Table::handle_row_actions()Generates and displays row actions links.
- WP_Customize_Control::render_content()Renders the control's content.
- WP_Customize_Manager::render_control_templates()Renders JS templates for all registered control types.
- WP_Customize_Nav_Menu_Location_Control::render_content()Render content just like a normal select control.
- WP_Customize_Nav_Menu_Setting::sanitize()Sanitize an input.
- WP_Customize_Nav_Menus::available_items_template()Prints the HTML template used to render the add-menu-item frame.
- WP_Customize_Nav_Menus::enqueue_scripts()Enqueues scripts and styles for Customizer pane.
- WP_Customize_Nav_Menus::print_post_type_container()Prints the markup for new menu items.
- WP_Customize_New_Menu_Section::render()Render the section, and the controls that have been added to it.
- WP_Customize_Section::json()Gather the parameters passed to client JavaScript via JSON.
- WP_Customize_Themes_Section::filter_drawer_content_template()Renders the filter drawer portion of a themes section as a JS template.
- WP_Customize_Widgets::end_dynamic_sidebar()Finishes keeping track of the current sidebar being rendered.
- WP_Customize_Widgets::output_widget_control_templates()Renders the widget form control templates into the DOM.
- WP_Customize_Widgets::start_dynamic_sidebar()Begins keeping track of the current sidebar being rendered.
- WP_Date_Query::validate_date_values()Validates the given date_query values and triggers errors if something is not valid.
- WP_Embed::maybe_make_link()Conditionally makes a hyperlink based on an internal class variable.
- WP_Image_Editor_Imagick::write_image()Writes an image to a file or stream.
- WP_Interactivity_API::data_wp_text_processor()Processes the `data-wp-text` directive.
- WP_Interactivity_API_Directives_Processor::set_content_between_balanced_tags()Sets the content between two balanced tags.
- WP_List_Table::get_views_links()Generates views links.
- WP_List_Table::months_dropdown()Displays a dropdown for filtering items in the list table by month.
- WP_Media_List_Table::column_author()Handles the author column output.
- WP_Media_List_Table::column_default()Handles output for the default column.
- WP_Media_List_Table::column_title()Handles the title column output.
- WP_Nav_Menu_Widget::form()Outputs the settings form for the Navigation Menu widget.
- WP_Object_Cache::stats()Echoes the stats of the caching.
- WP_Plugin_Dependencies::display_admin_notice_for_circular_dependencies()Displays an admin notice if circular dependencies are installed.
- WP_Plugin_Install_List_Table::display_rows()Generates the list table rows.
- WP_Plugin_Install_List_Table::get_dependencies_notice()Returns a notice containing a list of dependencies required by the plugin.
- WP_Plugin_Install_List_Table::get_more_details_link()Creates a 'More details' link for the plugin.
- WP_Plugins_List_Table::get_view_details_link()Returns a 'View details' link for the plugin.
- WP_Plugins_List_Table::no_items()
- WP_Posts_List_Table::column_author()Handles the post author column output.
- WP_Posts_List_Table::column_default()Handles the default column output.
- WP_Posts_List_Table::column_title()Handles the title column output.
- WP_Posts_List_Table::formats_dropdown()Displays a formats drop-down for filtering items.
Source
function esc_html( $text ) { $safe_text = wp_check_invalid_utf8( $text ); $safe_text = _wp_specialchars( $safe_text, ENT_QUOTES ); /** * Filters a string cleaned and escaped for output in HTML. * * Text passed to esc_html() is stripped of invalid or special characters * before output. * * @since 2.8.0 * * @param string $safe_text The text after it has been escaped. * @param string $text The text prior to being escaped. */ return apply_filters( 'esc_html', $safe_text, $text );}History
Introduced in 2.8.0. Unchanged from 6.7.7 through 7.1.0.
Signature, return type and hooks compared across 5 parsed releases.
About this page
- Parsed data
- Generated from the wordpress-develop 6.8.8 tag, from
src/wp-includes/formatting.php, and regenerated for each WordPress release so it tracks the code rather than a snapshot of it. - Corrections
- Something wrong on this page? Report it and it gets fixed in the next regeneration.