Would encoding quotation marks and removing eventual javascript: prefixes be enough?
P.S. Safe enough to defeat XSS attacks that is.
you can use the php function to validate urls
$url = "http://google.com";
if (filter_var($url, FILTER_VALIDATE_URL)) {
echo "URL is valid";
}
else {
echo "URL is invalid";
}
If you love us? You can donate to us via Paypal or buy me a coffee so we can maintain and grow! Thank you!
Donate Us With