Ecosyste.ms: OpenCollective

An open API service for software projects hosted on Open Collective.

github.com/voku/anti-xss

㊙️ AntiXSS | Protection against Cross-site scripting (XSS) via PHP
https://github.com/voku/anti-xss

[-]: removed a unused parameter

75379c7f2cfb059b03678bb45a5169c9954e5966 authored over 9 years ago by Lars Moelleken <[email protected]>
[*]: added "https://www.xssposed.org/" as a xss-test-resource

8320c12e13586dae95dcadd2b0c030d3b68b4294 authored over 9 years ago by Lars Moelleken <[email protected]>
Merge remote-tracking branch 'origin/master'

* origin/master:
Update README.md

ce9a8b42bb07675ef885d5b2ec310bc130051df1 authored over 9 years ago by Lars Moelleken <[email protected]>
[!!!]: security update | use a new version of "portable-utf8"

315c66f8b3ed9fec35c9ed23750e084d8fef55b2 authored over 9 years ago by Lars Moelleken <[email protected]>
Update README.md

e4f4fc5509bf34b7110632fc4f507dc9bd0c81ff authored over 9 years ago by Lars Moelleken <[email protected]>
[+]: added tests from "https://www.davidsopas.com/win-50-amazon-gift-card-with-a-xss-challenge/"

f5bbbd0730312de2625d5c2fcad21647c1e7e1b6 authored over 9 years ago by Lars Moelleken <[email protected]>
Merge remote-tracking branch 'origin/master'

* origin/master:
Update README.md

de2aa0c9bee3c7058820d21c2b6b11ceb745ca19 authored over 9 years ago by Lars Moelleken <[email protected]>
[*]: only a small code-style change

fc12d5250c4529b8880b70dd96a1ecfecc8352f1 authored over 9 years ago by Lars Moelleken <[email protected]>
Update README.md

fa84b49696f3676785faad23d667bb580d0b0b4a authored over 9 years ago by Lars Moelleken <[email protected]>
[+]: add some more tests from -> https://html5sec.org/ v2.2

83c1b0c091e2dc16bfa98d9a6d5a86e3e130924b authored over 9 years ago by Lars Moelleken <[email protected]>
[+]: add some more tests from -> https://html5sec.org/ v2.1

2eb1694c193a4ef180bd0bcb9e53120363d8921d authored over 9 years ago by Lars Moelleken <[email protected]>
[+]: add some more tests from -> https://html5sec.org/ v2

229b3498419670e77e04a2b1ca2a49f0a0624cf9 authored over 9 years ago by Lars Moelleken <[email protected]>
Merge remote-tracking branch 'origin/master'

* origin/master:
Update circle.yml
Update .styleci.yml

573be2784b65cadb4208ce3f66d0aa28322f9856 authored over 9 years ago by Lars Moelleken <[email protected]>
[+]: add some more tests from -> https://html5sec.org/

78fdb9adc63c0a68cb823739c8a29e5acd54b699 authored over 9 years ago by Lars Moelleken <[email protected]>
Update circle.yml

f66f7b8299a51041bc26a7f4a909a1f85d87f308 authored over 9 years ago by Lars Moelleken <[email protected]>
Update .styleci.yml

3fcf65fcd622dd8f998f2fe24e77f637d1eafd74 authored over 9 years ago by Lars Moelleken <[email protected]>
[*]: fixed phpdoc

5ff402b82a5eed348263718e59768ffcc698602b authored over 9 years ago by Lars Moelleken <[email protected]>
[*]: fixed typo in ".gitattributes"

42a505f2462cd943b1d4f8b2b804154112d0d92d authored over 9 years ago by Lars Moelleken <[email protected]>
[+]: fixed tests for anti-xss -> it's save now, but with different output v2.1

5aae6471d0ea6ef7cd46accd31ff29e35b744164 authored over 9 years ago by Lars Moelleken <[email protected]>
[+]: fixed tests for anti-xss -> it's save now, but with different output v2

5ada07d2bc9c58e73003e140cbe3cab6ee95acc8 authored over 9 years ago by Lars Moelleken <[email protected]>
[+]: fixed tests for anti-xss -> it's save now, but with different output ...

8c65fdcf9b3aab4b13ca29df0c7b3e4904fd5f0e authored over 9 years ago by Lars Moelleken <[email protected]>
[!]: fixed anti-xss for PHP 5.4

0f148e8125a72d263a2edd9872ab9032f7ad0781 authored over 9 years ago by Lars Moelleken <[email protected]>
[!]: fixed anti-xss for PHP 5.3 v5

d042d7a30df82a4006db4c3b9c4de9f720a20ac5 authored over 9 years ago by Lars Moelleken <[email protected]>
[!]: fixed anti-xss for PHP 5.3 v4

6835931a95f2f10371e3d168883dc11436e8ac10 authored over 9 years ago by Lars Moelleken <[email protected]>
[!]: fixed anti-xss for PHP 5.3 v3

27ecd4a93f9cedbd0bcc62c0dffe81f8353c6cef authored over 9 years ago by Lars Moelleken <[email protected]>
[!]: fixed anti-xss for PHP 5.3 v2.3

06c608b34f0d8fcaebd9f844c9013e579fdb6979 authored over 9 years ago by Lars Moelleken <[email protected]>
[!]: fixed anti-xss for PHP 5.3 v2.2

82f6a6f1fe0fabe436b423288f181802273d3b34 authored over 9 years ago by Lars Moelleken <[email protected]>
[!]: fixed anti-xss for PHP 5.3 v2.1

d97bac5b7572a940d2319657cfb14d52db7ce573 authored over 9 years ago by Lars Moelleken <[email protected]>
[!]: fixed anti-xss for PHP 5.3 v2

ecae918ff2b058a54c66a7b9f09b1940c792067b authored over 9 years ago by Lars Moelleken <[email protected]>
[+]: added "circle.yml" v2

d462043fa9e8da506c6f6d6719fa410a136e5799 authored over 9 years ago by Lars Moelleken <[email protected]>
Merge remote-tracking branch 'origin/master'

* origin/master:
Scrutinizer Auto-Fixes

681d51e6b073c9795a304a157f85f37b8c1e9aec authored over 9 years ago by Lars Moelleken <[email protected]>
[+]: added "circle.yml"

c3ddbe95cf991a580ca24f024d94a1e4e6a232a2 authored over 9 years ago by Lars Moelleken <[email protected]>
Merge pull request #7 from voku/scrutinizer-patch-4

Scrutinizer Auto-Fixes

875b1329e5b8eab9bc4cbad21db83e49b3322c4d authored over 9 years ago by Lars Moelleken <[email protected]>
Scrutinizer Auto-Fixes

This commit consists of patches automatically generated for this project on https://scrutinizer-...

2d4ea96a2bb8242fb17b9302e2652b1993b63726 authored over 9 years ago by Scrutinizer Auto-Fixer <[email protected]>
[!]: fixed anti-xss for PHP 5.3

1b1b95e019b81b35fae5b0649d3c2a953a1bf2f3 authored over 9 years ago by Lars Moelleken <[email protected]>
[*]: edit phpdoc ...

e824b4b72f916b61b0bc22981692de7013dc50b8 authored over 9 years ago by Lars Moelleken <[email protected]>
Merge remote-tracking branch 'origin/master'

* origin/master:
Scrutinizer Auto-Fixes

39719a9f15d62ed3dbfc4e0437561ba665506c9b authored over 9 years ago by Lars Moelleken <[email protected]>
[+]: need more work for PHP 5.3 & HHVM v3.1

6be07258fa852a3d118454dc578d0358147f5ebf authored over 9 years ago by Lars Moelleken <[email protected]>
Merge pull request #6 from voku/scrutinizer-patch-3

Scrutinizer Auto-Fixes

a4afddcafb7927444bebd60aa9aa5d03a3ef3efa authored over 9 years ago by Lars Moelleken <[email protected]>
Scrutinizer Auto-Fixes

This commit consists of patches automatically generated for this project on https://scrutinizer-...

591050d8988e751d816a7ba8dab088dff663d00d authored over 9 years ago by Scrutinizer Auto-Fixer <[email protected]>
[+]: need more work for PHP 5.3 & HHVM v3

8871fcd43c117e469f3cec6d6b4883d101ecafb6 authored over 9 years ago by Lars Moelleken <[email protected]>
[+]: need more work for PHP 5.3 & HHVM v2

1533bcd5d67d8c5e113a824633fbe77895b33e72 authored over 9 years ago by Lars Moelleken <[email protected]>
[+]: need more work for PHP 5.3 & HHVM

024c494d6b18d771f5f81eab5eae2e69f0420cfa authored over 9 years ago by Lars Moelleken <[email protected]>
[*]: only auto code-re-range via PHPStorm

f5f079a1c98ef717cd89a91152ccce564d945979 authored over 9 years ago by Lars Moelleken <[email protected]>
[+]: some changes for HHVM (need testing)

98b5bedd1dc1412adf1e9f6d19fe871096895a96 authored over 9 years ago by Lars Moelleken <[email protected]>
[+]: add some more tests v2.1

437b212863804860c508a454e17296dd116e65fb authored over 9 years ago by Lars Moelleken <[email protected]>
[+]: try to fix for HHVM v2

183aa730a1997bf4cbf13f9d7f51532c73ab527d authored over 9 years ago by Lars Moelleken <[email protected]>
[+]: add some more tests v2

90b367ecf38bb65c980d05f585ee864702a72623 authored over 9 years ago by Lars Moelleken <[email protected]>
[+]: try to fix for HHVM

d69760b67c9684b887541babb9e0d3e5a0ff575c authored over 9 years ago by Lars Moelleken <[email protected]>
[*]: only code-style

b74fab00c26ba0fd7ee7a0c1871f27bec7d45d17 authored over 9 years ago by Lars Moelleken <[email protected]>
[+]: add some more tests | from https://raw.githubusercontent.com/GrahamCampbell/Laravel-Security/master/tests/SecurityTest.php

5540795c26aa9811eb80a1b60a032b29b8fc2d2f authored over 9 years ago by Lars Moelleken <[email protected]>
Merge remote-tracking branch 'origin/master'

* origin/master:
Update .travis.yml
Update .gitattributes
Applied fixes from StyleCI

94d359c0a715fd5706ef635a80b243bf6f2c9efe authored over 9 years ago by Lars Moelleken <[email protected]>
[+]: try to fix ant-xss for HHVM

9249e1c89e566763cafceadc7977ffb32f78c630 authored over 9 years ago by Lars Moelleken <[email protected]>
Update .travis.yml

961c2d8a2fa8a81af965ce36cbfa66985747fba0 authored over 9 years ago by Lars Moelleken <[email protected]>
Update .gitattributes

9b1dad918d6430a790f3a1c9540d51b0079600b3 authored over 9 years ago by Lars Moelleken <[email protected]>
Merge pull request #5 from voku/analysis-q2A7lX

Applied fixes from StyleCI

66b4582845067616431e2219de82960a8829abf6 authored over 9 years ago by Lars Moelleken <[email protected]>
Applied fixes from StyleCI

c6ffaa4c072adfad0f03400139fc47a33c4f800e authored over 9 years ago by Lars Moelleken <[email protected]>
[+]: add ".styleci.yml" v2.2

03de4190f8cb2a1c8c4d92908f72584723b3c8cd authored over 9 years ago by Lars Moelleken <[email protected]>
[+]: add ".styleci.yml" v2.1

328503c98adef58bc2a1bfe4da8399f78febc8d9 authored over 9 years ago by Lars Moelleken <[email protected]>
[+]: add ".styleci.yml" v2

0393f47701d3052bcc0175883ea9f7e98c16b0a3 authored over 9 years ago by Lars Moelleken <[email protected]>
Merge remote-tracking branch 'origin/master'

* origin/master:
Typo

6b62ea3e15a383740e9d7cbb5d65856f02d1cbab authored over 9 years ago by Lars Moelleken <[email protected]>
[+]: add ".styleci.yml"

a20ac9b496c88389686e7f403932cc8c17809706 authored over 9 years ago by Lars Moelleken <[email protected]>
Merge pull request #4 from tetreum/patch-1

Typo

df41684d33b5302bf42dd90a4496b9c2efd9e016 authored over 9 years ago by Lars Moelleken <[email protected]>
Typo

347cdfde86b20b65cfa7087d760204d8c2c1926c authored over 9 years ago by tetreum <[email protected]>
[!]: fixed PSR-4 auoload

badaf7be79da59f481faa35c32997456ee704210 authored over 9 years ago by Lars Moelleken <[email protected]>
[+]: added test via array

a0829cc007619a6687090eb66afd09057ad332ef authored over 9 years ago by Lars Moelleken <[email protected]>
[*]: only a code-comment

0ec5364e0ace5a6d80ee2f403bdd8a3073028201 authored over 9 years ago by Lars Moelleken <[email protected]>
[+]: added some more tests (from js-xss) v2.1 -> for old php

1ebf8cca9d0c5d5316bfa2df5d138e72da972110 authored over 9 years ago by Lars Moelleken <[email protected]>
[+]: added some more tests (from js-xss) v2 -> for old php

91bec6efaa181d9a1830142e61eeee5c8ae28025 authored over 9 years ago by Lars Moelleken <[email protected]>
[+]: added some more tests (from js-xss) v2

e35cd711ffc0ae50ef78b10e44028da2db3a51c7 authored over 9 years ago by Lars Moelleken <[email protected]>
Merge remote-tracking branch 'origin/master'

* origin/master:
Update README.md

9ed54d408d99498f6ac197e38686b9715b84193b authored over 9 years ago by Lars Moelleken <[email protected]>
[+]: added some more tests (from js-xss)

22cf623ec4a4fb7564e204a8ec5342eef864e1d7 authored over 9 years ago by Lars Moelleken <[email protected]>
Update README.md

3ec92898328e59beb9bdcb9fc10a233b5d5ffd6f authored over 9 years ago by Lars Moelleken <[email protected]>
[+]: try to fix XSS for PHP 5.3

642cd5a000f5a3c5240419a88b65236036f27f15 authored over 9 years ago by Lars Moelleken <[email protected]>
[+]: use xss-test from DOMPurify | https://github.com/cure53/DOMPurify/edit/master/test/expect.json

b124eb13f77962ecbca4f26f13004ad4e529e344 authored over 9 years ago by Lars Moelleken <[email protected]>
[+]: added"PDF-based polyglots through SVG images"-test

ed83744636d240e5d2fbd912d4591661ae01e11f authored over 9 years ago by Lars Moelleken <[email protected]>
[+]: added some more tests

037109f2840eee28ead17d9bf20b3fbe3e2208ac authored over 9 years ago by Lars Moelleken <[email protected]>
[+]: added some more tests

452c6e23a314c73387e9b28333fc5665b476650e authored over 9 years ago by Lars Moelleken <[email protected]>
[+]: added test with "Shift-JIS"-Encoding | https://en.wikipedia.org/wiki/Shift_JIS

b8bb72fb455af3305e9f8b4d3b472b8ac4cd1ccd authored over 9 years ago by Lars Moelleken <[email protected]>
[*]: no code-changes

6a884d8aa01d7d40079c04ace56140427ea11411 authored over 9 years ago by Lars Moelleken <[email protected]>
[+]: add some more tests

ab7ca65b0bf41b0e9313a296d6b5956cd312ac99 authored over 9 years ago by Lars Moelleken <[email protected]>
[+]: more performance for "_do_never_allowed()"

d95ca9e5407707a5b675e8c39395550659272a37 authored over 9 years ago by Lars Moelleken <[email protected]>
[+]: add a test for mutation XSS #mXSS

b09ac3b3001a706d0993113b1a7f14b52e599472 authored over 9 years ago by Lars Moelleken <[email protected]>
[+]: protect also against XXE (XML External Entity Injection) -> http://phpsecurity.readthedocs.org/en/latest/Injection-Attacks.html#xml-injection (need some real world-testing)

08de67e8bfb0faa4126e1d9212c7cf355d7abfbf authored over 9 years ago by Lars Moelleken <[email protected]>
[+]: added one more xss-test | NoScript XSS filter bypass

6f6a0538ddfdfacd161cf6f3e4b77625fb31c3d5 authored over 9 years ago by Lars Moelleken <[email protected]>
[+]: added one more xss-test

cd9b2af91640f0c9a338a17cf339985819904f67 authored over 9 years ago by Lars Moelleken <[email protected]>
Update README.md

cccbad2c6a4c7df2cc2cf4da7c9c716e916ec82e authored over 9 years ago by Lars Moelleken <[email protected]>
Merge remote-tracking branch 'origin/master'

* origin/master:
Update README.md

ee2d4636963b62fa012e6654f6b7c347a95c9251 authored over 9 years ago by Lars Moelleken <[email protected]>
[!]: protect against meta-tag hacks

[+]: optimized performance from "_js_removal()"
[+]: added some more tests

e52c9090e0804d0a1672beba862e72ea5e8c6633 authored over 9 years ago by Lars Moelleken <[email protected]>
Update README.md

ec8e5cb446e6d50a5c65d9b325879c4411eb6935 authored over 9 years ago by Lars Moelleken <[email protected]>
[+]: added "branch-alias"

f7cb7fa004d8c2530c331523c229c79e5584c014 authored over 9 years ago by Lars Moelleken <[email protected]>
[~]: use "psr-4"-autoload

fc97a4ae08671fc8251a107bc40e7165ef6fe3a3 authored over 9 years ago by Lars Moelleken <[email protected]>
[~]: optimized performance v2

033139c4ac5229aa9cdcedb0d0a09afa05a92192 authored over 9 years ago by Lars Moelleken <[email protected]>
[~]: optimized performance v1

7f616f89824d59291cdfdcd1ebc4962388688500 authored over 9 years ago by Lars Moelleken <[email protected]>
Merge remote-tracking branch 'origin/master'

* origin/master:
Update README.md

7181ba34a39b1da9ef2b00d42d09fac8242dfd76 authored over 9 years ago by Lars Moelleken <[email protected]>
[+]: fixed "license" v2

ae1cf2397ad74eadfa34c9708ce7b9fd9a46e0be authored over 9 years ago by Lars Moelleken <[email protected]>
Update README.md

759fe9482b7aca45f7a2ba70ae3665509143d460 authored over 9 years ago by Lars Moelleken <[email protected]>
[!]: fixed "license"

0c442bb68d4fd77c73d23b1292f5f0580dba065f authored over 9 years ago by Lars Moelleken <[email protected]>
[+]: added ".editorconfig"

41ed11a6fc25c765a45053dffd29faf9e0c4c476 authored over 9 years ago by Lars Moelleken <[email protected]>
[+]: fixed "xss_clean()" -> now we can also use it for encoded "JSON" strings

cae918b6bb7b3e13dfbbf36fa3fed728224e0e0b authored over 9 years ago by Lars Moelleken <[email protected]>