esc_html( string $text ): string
- Since
- 2.8.0
- Source
wp-includes/formatting.php:4680
Escape a string for HTML output with esc_html(), converting angle brackets, ampersands, and quotes to entities so untrusted text cannot inject markup. Available since WordPress 2.8.0, it validates the string as UTF-8 and passes the result through the esc_html filter before returning it.
Parameters
$textstring
Return
string- Escaped text.
Examples
Every example is editable and runs in a real WordPress booted in your browser by WordPress Playground. Press Run, then edit the code: clicking away re-runs it. Nothing is sent anywhere until you do.
Print an untrusted value inside an HTML element
Anything that came from a form, a URL or the database is untrusted at the point it is printed.
update_post_meta( 2, 'company_name', 'Acme <script>alert(1)</script> Ltd' );
$company = get_post_meta( 2, 'company_name', true );
echo "raw: ", $company, "\n";
echo "escaped: ", esc_html( $company );Escape at the point of output, not when saving, so the stored value stays intact.
Escape a translated string on output
Translations load from external files, so escape them like any other untrusted input (the esc_html__() shorthand combines both steps).
$heading = __( 'Recent projects', 'mytheme' );
echo '<h2>' . esc_html( $heading ) . '</h2>';
// Equivalent one-liner:
echo '<h2>' . esc_html__( 'Recent projects', 'mytheme' ) . '</h2>';esc_html() is for text between tags only; inside attribute values use esc_attr(), and for href/src values use esc_url().
Hooks fired · 1
One hook fires while esc_html() runs, in this order:
- apply_filters( esc_html )filterline 4694 (+14 into the body)
Filters a string cleaned and escaped for output in HTML.
Uses · 3
- wp_check_invalid_utf8()Checks for invalid UTF8 in a string.
- _wp_specialchars()Converts a number of special characters into their HTML entities.
- apply_filters()Calls the callback functions that have been added to a filter hook.
Used by · 50
- Bulk_Upgrader_Skin::error()Displays an error message about the update.
- Custom_Image_Header::step_1()Displays first step of custom header image page.
- Plugin_Installer_Skin::do_overwrite()Checks if the plugin can be overwritten and outputs the HTML for overwriting a plugin on upload.
- Theme_Installer_Skin::do_overwrite()Checks if the theme can be overwritten and outputs the HTML for overwriting a theme on upload.
- TwentyTwenty_Walker_Comment::html5_comment()Outputs a comment in the HTML5 format.
- Twenty_Fourteen_Ephemera_Widget::form()Displays the form for this widget on the Widgets page of the Admin area.
- Twenty_Fourteen_Ephemera_Widget::widget()Outputs the HTML for this widget.
- WP_AI_Client_Prompt_Builder::using_abilities()Registers WordPress abilities as function declarations for the AI model.
- WP_Abilities_Registry::get_registered()Retrieves a registered ability.
- WP_Abilities_Registry::register()Registers a new ability.
- WP_Abilities_Registry::unregister()Unregisters an ability.
- WP_Ability::__construct()Constructor.
Show all 50
- WP_Ability::check_permissions()Checks whether the ability has the necessary permissions.
- WP_Ability::do_execute()Executes the ability callback.
- WP_Ability::execute()Executes the ability after input validation and running a permission check.
- WP_Ability::invoke_callback()Invokes a callable, ensuring the input is passed through only if the input schema is defined.
- WP_Ability::validate_input()Validates input data against the input schema.
- WP_Ability::validate_output()Validates output data against the output schema.
- WP_Ability_Categories_Registry::get_registered()Retrieves a registered ability category.
- WP_Ability_Categories_Registry::register()Registers a new ability category.
- WP_Ability_Categories_Registry::unregister()Unregisters an ability category.
- WP_Ability_Category::__construct()Constructor.
- WP_Ajax_Upgrader_Skin::get_error_messages()Retrieves a string for error messages.
- WP_Application_Passwords_List_Table::column_name()Handles the name column output.
- WP_Block_Metadata_Registry::register_collection()Registers a block metadata collection.
- WP_Comments_List_Table::column_author()Outputs the author column.
- WP_Comments_List_Table::column_comment()Outputs the comment column.
- WP_Comments_List_Table::column_response()Outputs the response column.
- WP_Comments_List_Table::comment_type_dropdown()Displays a comment type drop-down for filtering on the Comments list table.
- WP_Comments_List_Table::handle_row_actions()Generates and displays row actions links.
- WP_Connector_Registry::get_registered()Retrieves a registered connector.
- WP_Connector_Registry::register()Registers a new connector.
- WP_Connector_Registry::unregister()Unregisters a connector.
- WP_Customize_Control::render_content()Renders the control's content.
- WP_Customize_Custom_CSS_Setting::validate()Validate a received value for being valid CSS.
- WP_Customize_Manager::render_control_templates()Renders JS templates for all registered control types.
- WP_Customize_Nav_Menu_Location_Control::render_content()Render content just like a normal select control.
- WP_Customize_Nav_Menu_Setting::sanitize()Sanitize an input.
- WP_Customize_Nav_Menus::available_items_template()Prints the HTML template used to render the add-menu-item frame.
- WP_Customize_Nav_Menus::enqueue_scripts()Enqueues scripts and styles for Customizer pane.
- WP_Customize_Nav_Menus::print_post_type_container()Prints the markup for new menu items.
- WP_Customize_New_Menu_Section::render()Render the section, and the controls that have been added to it.
- WP_Customize_Section::json()Gather the parameters passed to client JavaScript via JSON.
- WP_Customize_Themes_Section::filter_drawer_content_template()Renders the filter drawer portion of a themes section as a JS template.
- WP_Customize_Widgets::end_dynamic_sidebar()Finishes keeping track of the current sidebar being rendered.
- WP_Customize_Widgets::output_widget_control_templates()Renders the widget form control templates into the DOM.
- WP_Customize_Widgets::start_dynamic_sidebar()Begins keeping track of the current sidebar being rendered.
- WP_Date_Query::validate_date_values()Validates the given date_query values and triggers errors if something is not valid.
- WP_Embed::maybe_make_link()Conditionally makes a hyperlink based on an internal class variable.
- WP_Image_Editor_Imagick::write_image()Writes an image to a file or stream.
Source
function esc_html( $text ) { $safe_text = wp_check_invalid_utf8( $text ); $safe_text = _wp_specialchars( $safe_text, ENT_QUOTES ); /** * Filters a string cleaned and escaped for output in HTML. * * Text passed to esc_html() is stripped of invalid or special characters * before output. * * @since 2.8.0 * * @param string $safe_text The text after it has been escaped. * @param string $text The text prior to being escaped. */ return apply_filters( 'esc_html', $safe_text, $text );}History
Introduced in 2.8.0. Unchanged from 6.7.7 through 7.1.0.
Signature, return type and hooks compared across 5 parsed releases.
About this page
- Parsed data
- Generated from the wordpress-develop 7.0.4 tag, from
src/wp-includes/formatting.php, and regenerated for each WordPress release so it tracks the code rather than a snapshot of it. - Corrections
- Something wrong on this page? Report it and it gets fixed in the next regeneration.