Removing HTML tags by using strip_tag function

Remove HTML and PHP tags from a string

strip_tags() is useful when the goal is to remove markup, but it is not an XSS-prevention function and it does not make allowed tag attributes safe. For plain text rendered into HTML, use context-appropriate escaping such as htmlspecialchars().

$html = '<p>Hello <strong>PHP</strong></p>';
$plain = strip_tags($html);
echo $plain; // Hello PHP

Start with this current pattern. The examples below are retained, corrected where necessary, and expanded for additional variations and output.

$str="Welcome <b>to</b> <i>plus2net</i>";
echo strip_tags($str);
Output
Welcome to plus2net
We can remove all html tags from the content by using strip_tags string function in PHP. This function can be used to collect only the content part without reading the html formatting of the page. Here is the syntax
 strip_tags (input string [, string allowable_tags])
This function also allows one optional string where we can keep the tags which are not to be removed. Say we don't want the hyper links to be removed. So we will allow the linking tag <a href to be kept as it is. Here is the syntax for this.
strip_tags($string_str, '<a>');
In the above code $string_str is the input string.

Using strip_tags function we can collect content from different pages of a directory. Now let us try to collect the content of a sample page test.php. You can read the tutorial on how to collect content of a page here.

Here is the code to collect the content of the page and then we will apply strip_tags to remove all tags and display only the text content without any HML formatting.

$path="test.php";
$contents="";
$fd = fopen ($path, "r"); // opening the file in read mode
while($buffer = fread ($fd,1024)){
$contents .=$buffer;
}
fclose ($fd); 

$contents=strip_tags($contents,'<a>');
echo $contents;

Example: Allowing Specific Tags

$text = '<b>Bold</b> and <i>Italic</i>';
echo strip_tags($text, '<i>');  // Output: Bold and <i>Italic</i>

Example: Why strip_tags() Is Not an XSS Defense

strip_tags() removes markup, but it does not make untrusted HTML safe. Script text can remain, and attributes on allowed tags are not sanitized. Use context-appropriate escaping or a dedicated HTML sanitizer when security is the goal.

$input = '<script>alert("XSS")</script>Text';
echo strip_tags($input);  // Output: alert("XSS")Text

String Functions nl2br() To add Line break


Subscribe to our YouTube Channel here



plus2net.com







Malik

18-07-2009

Thanx dude its worked for me




PHP video Tutorials
✖
We use cookies to improve your browsing experience. . Learn more
HTML MySQL PHP JavaScript ASP Photoshop Articles Contact us
© 2000-2026 plus2net.com All rights reserved worldwide Privacy Policy Disclaimer