Automattic\WooCommerce\EmailEditor\Integrations\Core\Renderer\Blocks

Post_Template::strip_unsafe_markup │ private │ WC 1.0

Strip markup that has no place in an email from the preserved remainder: <script>/<style> elements and inline event-handler (on*) attributes.

The images beside this content are already sanitized when they're rebuilt, so this keeps the reconstructed cell internally consistent. It intentionally leaves style attributes and all structural markup in place, so legitimate card content (title/date/excerpt) renders unchanged — core never emits scripts or handlers there, making this a no-op for real content. Scoped to this renderer's grid path only; it operates on the local item DOM and touches no shared helper.

Method of the class: Post_Template{}

No Hooks.

Returns

null. Nothing (null).

Usage

// private - for code of main (parent) class only
$result = $this->strip_unsafe_markup( $item_dom ): void;
$item_dom(Dom_Document_Helper) (required)
The item DOM to clean in place.

Post_Template::strip_unsafe_markup() code WC 11.1.2

private function strip_unsafe_markup( Dom_Document_Helper $item_dom ): void {
	foreach ( array( 'script', 'style' ) as $tag_name ) {
		foreach ( $item_dom->find_elements( $tag_name ) as $element ) {
			$item_dom->remove_element( $element );
		}
	}

	foreach ( $item_dom->find_elements( '*' ) as $element ) {
		$attributes = $element->attributes;
		if ( null === $attributes ) {
			continue;
		}
		// Collect handler attribute names first, then remove — mutating the live attribute map
		// mid-iteration would skip entries.
		$handler_attributes = array();
		foreach ( $attributes as $attribute ) {
			if ( 0 === stripos( $attribute->name, 'on' ) ) {
				$handler_attributes[] = $attribute->name;
			}
		}
		foreach ( $handler_attributes as $attribute_name ) {
			$element->removeAttribute( $attribute_name );
		}
	}
}