Skip to content
CAI
Software that uses CAICheck a score

rrrene/html_sanitize_ex

72.5

Strong · 18 September 2026

3.1k

lines of production code

Elixir

primary language

1

measurement over time

CAI band scale
CAI lens gauges

What this system is

This system is an Elixir library for sanitizing HTML and CSS content to prevent cross-site scripting (XSS) vulnerabilities. It provides a DSL-based API for defining custom scrubbers and includes built-in modes for basic HTML, HTML5, and Markdown-flavored HTML. The library also features a dedicated CSS scrubber to strip dangerous inline styles and ensures parser stability by preserving whitespace and handling malformed input.

Features

Introduces custom scrubber DSL and new sanitization modes

HtmlSanitizeEx now supports creating and extending custom scrubbers via a new DSL (macros) using \use HtmlSanitizeEx\, allowing users to define specific allowed tags and attributes or extend existing modes like \:basic\_html\ and \:html5\. The library also adds a new \html5/1\ function for full HTML5 sanitization and a \markdown\_html/1\ function for Markdown-compatible HTML, replacing the previous \markdown/1\ shortcut. Existing convenience functions (\noscrub\, \basic\_html\, \strip\_tags\) remain available but now delegate to their respective scrubber modules directly.

lib · high confidence

New HTML5 and Markdown scrubbers with a DSL-based configuration API

The library now includes dedicated scrubbers for HTML5 (\HtmlSanitizeEx.Scrubber.HTML5\) and Markdown-flavored HTML (\HtmlSanitizeEx.Scrubber.MarkdownHTML\), providing pre-configured whitelists for modern tags and attributes. The \BasicHTML\ scrubber has been updated to support \mailto:\ links and the \h6\ tag. A new CSS scrubber (\HtmlSanitizeEx.Scrubber.CSS\) is introduced to sanitize inline styles and \\<style\>\ blocks, removing dangerous constructs like \@import\. Additionally, the meta-programming API (\HtmlSanitizeEx.Scrubber.Meta\) has been extended with new macros like \allow\_tag\_with\_any\_attributes\ and \allow\_tag\_with\_this\_attribute\_values\, allowing users to define custom scrubbers with a more concise and flexible DSL.

_lib/html\_sanitize\ex/scrubber · high confidence

New custom scrubber API and Elixir 1.20 support

Users can now define custom HTML scrubbers using a simplified \use HtmlSanitizeEx\ macro that automatically generates a \sanitize/1\ function, replacing the previous requirement to import \HtmlSanitizeEx.Scrubber.Meta\. This new API also supports extending built-in scrubbers (like \:basic\_html\ or \:html5\) or other custom scrubbers via the \extend:\ option. Additionally, the library has been updated to support Elixir 1.20.3 and includes security fixes for XSS vulnerabilities.

(repo-wide) · high confidence

Behavioural changes

Improved whitespace preservation and parser stability in HTML sanitization

The HTML sanitizer now better preserves meaningful whitespace (line breaks, spaces, and tabs) between nodes by using internal replacement markers during parsing and post-processing, preventing the loss of formatting that previously occurred. Additionally, the parser now escapes dangling processing instruction markers (e.g., \\<?\) to avoid crashes, and the traversal logic has been refactored to handle sibling nodes more robustly, fixing issues where traversal could exhaust or incorrectly flatten results.

_lib/html\_sanitize\ex · high confidence

Removal of legacy config/config.exs file

The legacy config/config.exs file has been removed from the project. This file previously contained default configuration settings and comments regarding Mix.Config usage, including examples for logger configuration and environment-specific imports. Its removal indicates a shift away from this specific configuration pattern, likely consolidating configuration management elsewhere in the application.

config · high confidence

Test coverage

Added comprehensive test coverage for HTML sanitization scrubbers; Added test infrastructure and XSS regression fixtures.

Dependencies

Update dependencies and add development tooling

The project updates the mochiweb dependency to support versions 2.15 and 3.1 (locking at 3.2.2) and adds ex\_doc and mix\_test\_watch as development dependencies. It also registers mochiweb as an extra application in the OTP release configuration.

(dependencies) · high confidence

Written by watchdog.canine.dev from the codebase's own history, inside the signed delivery this page is composed from.

How this codebase got here

Baseline

  • First survey — no prior run to compare against. CAI 73.

Lenses

  • Code Health 100
  • Architecture 100
  • Maturity 61
  • Readiness 67
  • Security 99

Changes since last survey

  • 230 commits — 200 feature/other, 30 fixes

By area

  • (root) — 101 commits
  • lib/html_sanitize_ex — 68 commits
  • (repo) — 32 commits
  • .github/workflows — 12 commits
  • test/html_sanitize_ex — 7 commits
  • test/basic_html_test.exs — 3 commits
  • test/html5_test.exs — 3 commits
  • config/config.exs — 1 commit
  • test/check_formatted.sh — 1 commit
  • test/css_test.exs — 1 commit
  • test/strip_tags_test.exs — 1 commit

Notable commits

  • fix: Add fix for missing white-space between nodes
  • fix: Fix <meta> vulns
  • fix: Fix GitHub Actions
  • fix: Fix PCRE exhaustion
  • fix: Fix bad @import sanitizing
  • fix: Fix bad data on <object>
  • fix: Fix bug
  • fix: Fix compiler warning
  • fix: Fix compiler warning for CSS test
  • fix: Fix compiler warnings
  • fix: Fix compiler warnings for Elixir 1.3
  • fix: Fix compiler warnings on Elixir < 1.18
  • fix: Fix css scubber for input that is not a property: value declaration
  • fix: Fix custom scrubber test
  • fix: Fix different @import vectors
  • fix: Fix last commit
  • fix: Fix messed up commits
  • fix: Fix missing s
  • fix: Fix parser bug for nested tags in <style>
  • fix: Fix redundant scrub_attributes/2 clauses on Elixir 1.20
  • …and 210 more

Written by watchdog.canine.dev from the codebase's own history, inside the signed delivery this page is composed from.

Survey your own repository

rrrene/html_sanitize_ex was measured the same way every project in this corpus was: the same rubric, at a pinned commit, with the result published in full. Point a surveyor at a repository you know and see whether you agree with it.

About this page

  • The score is its most recent published measurement, taken on 18 September 2026 at a pinned commit. It is not a live figure and does not change until the project is measured again.
  • Measured at commit d5aaa4dc94695779353094018ad56c7718145006 — the exact code this score is about.
  • Scored under rubric-2026.09.15 — the same rubric and the same method as every other entry in this index.
  • Measured by watchdog.canine.dev using codehealth-analyzer preprod-5d04157a340d.