wp_kses_allowed_html │ filter-hook │ WP 3.5.0

Allows you to change the array of permitted HTML tags and attributes used when content is sanitized by functions in the wp_kses() family.

Tags and attributes must be lowercase; otherwise, KSES will not recognize them.

Usage

add_filter( 'wp_kses_allowed_html', 'wp_kama_kses_allowed_html_filter', 10, 2 );

/**
 * Function for `wp_kses_allowed_html` filter-hook.
 * 
 * @param array[] $html    Allowed HTML tags.
 * @param string  $context Context name.
 *
 * @return array[]
 */
function wp_kama_kses_allowed_html_filter( $html, $context ){
	// filter...
	return $html;
}
$html(array)
Permitted HTML tags. An array of tag ⇒ attributes entries that the filter can add to or remove from.
$context(string)
The context in which sanitization runs. For example: post, data, strip, entities, pre_user_description, and so on.

Examples

#1 Demonstration

add_filter( 'wp_kses_allowed_html', 'add_additional_allowed_html', 10, 2 );
function add_additional_allowed_html( $allowed, $context ) {
	// Change the rules only for the 'post' context.
	if ( 'post' !== $context ) {
		return $allowed;
	}

	// Allow SVG.
	$allowed['svg']  = array(
		'xmlns'   => true,
		'viewbox' => true,
		'width'   => true,
		'height'  => true,
		'fill'    => true,
	);

	$allowed['path'] = array(
		'd'    => true,
		'fill' => true,
	);

	return $allowed;
}

#2 Allow iframe in the visual editor

See: https://gist.github.com/bueltge/4511711

// Allow script and iframe tags within posts.
add_filter( 'wp_kses_allowed_html','allow_post_tags', 1 );
function allow_post_tags( $allowedposttags ){
	$allowedposttags['script'] = array(
		'type'   => true,
		'src'    => true,
		'height' => true,
		'width'  => true,
	);

	$allowedposttags['iframe'] = array(
		'src' => true,
		'width' => true,
		'height' => true,
		'class' => true,
		'frameborder' => true,
		'webkitAllowFullScreen' => true,
		'mozallowfullscreen' => true,
		'allowFullScreen' => true
	);

	return $allowedposttags;
}

Changelog

Since 3.5.0 Introduced.

Where the hook is called

wp_kses_allowed_html()
wp_kses_allowed_html
wp-includes/kses.php 1083
return apply_filters( 'wp_kses_allowed_html', $html, $context );
wp-includes/kses.php 1089
$tags = apply_filters( 'wp_kses_allowed_html', $allowedposttags, $context );
wp-includes/kses.php 1106
$tags = apply_filters( 'wp_kses_allowed_html', $tags, $context );
wp-includes/kses.php 1118
return apply_filters( 'wp_kses_allowed_html', $tags, $context );
wp-includes/kses.php 1122
return apply_filters( 'wp_kses_allowed_html', array(), $context );
wp-includes/kses.php 1126
return apply_filters( 'wp_kses_allowed_html', $allowedentitynames, $context );
wp-includes/kses.php 1131
return apply_filters( 'wp_kses_allowed_html', $allowedtags, $context );

Where the hook is used in WordPress

wp-includes/class-wp-customize-widgets.php 1801
add_filter( 'wp_kses_allowed_html', array( $this, 'filter_wp_kses_allowed_data_attributes' ) );
wp-includes/default-filters.php 316
add_filter( 'wp_kses_allowed_html', '_wp_kses_allow_note_mention_span', 10, 2 );