“Constant FILTER_SANITIZE_STRING is deprecated” in WordPress: what to use instead

By CompatNav · Published · Last reviewed · 4 min read

Short answer

It’s a deprecation notice from PHP 8.1 and later: a plugin or theme cleans text with the FILTER_SANITIZE_STRING filter, which PHP has marked as outdated. The code keeps working. There is no exact replacement, because the old filter did several things at once: the right choice depends on what the text is used for, and the plugin’s developer makes it. A check that reads code finds it before you upgrade.

The message, exactly

A contact form plugin cleans what a visitor typed with the old filter. On PHP 8.0 it runs without a message; from PHP 8.1 on, PHP adds the notice, and PHP 8.5 names the replacement php.net suggests:

wp-content/plugins/contact-form-lite/includes/form.php

<?php
$input = '<b>Tom\'s "best" offer</b>'; // what a visitor typed

$name = filter_var($input, FILTER_SANITIZE_STRING);
echo $name, "\n";

Output on PHP 8.0.30

Tom&#39;s &#34;best&#34; offer

Output on PHP 8.1.34

Deprecated: Constant FILTER_SANITIZE_STRING is deprecated in /var/www/html/wp-content/plugins/contact-form-lite/includes/form.php on line 4
Tom&#39;s &#34;best&#34; offer

Output on PHP 8.5.11

Deprecated: Constant FILTER_SANITIZE_STRING is deprecated since 8.1, use htmlspecialchars() instead in /var/www/html/wp-content/plugins/contact-form-lite/includes/form.php on line 4
Tom&#39;s &#34;best&#34; offer

php.net: “The FILTER_SANITIZE_STRING and FILTER_SANITIZE_STRIPPED filters are deprecated.” (php.net) FILTER_SANITIZE_STRIPPED is another name for the same filter and gets the same notice.

Is it urgent?

No. The result is the same on every version, as the output shows; PHP only adds the notice. It still needs a fix at some point, because a future PHP version is expected to remove what is deprecated today. Update the plugin, or send the message to its developer.

What the old filter did

php.net describes it: “This filter strips tags and HTML-encodes double and single quotes.” (php.net) That is two jobs in one: removing HTML, and making quotes safe inside HTML. It also had a side effect worth knowing: it cut the text at a lone <, as if a tag started there.

PHP 8.0, where the filter runs without a notice: everything from the < on is gone.

wp-content/plugins/contact-form-lite/includes/form.php

<?php
$input = '5 < 6 and <b>bold</b>'; // what a visitor typed

echo 'the old filter: ', filter_var($input, FILTER_SANITIZE_STRING), "\n";
echo 'strip_tags():   ', strip_tags($input), "\n";

Output on PHP 8.0.30

the old filter: 5
strip_tags():   5 < 6 and bold

What to use instead

php.net’s note on the filter says: “Deprecated as of PHP 8.1.0, use htmlspecialchars() instead.” (php.net) But htmlspecialchars() does only the second job: it keeps the tags, as visible text. The same input with the plain PHP functions:

wp-content/plugins/contact-form-lite/includes/form.php

<?php
$input = '<b>Tom\'s "best" offer</b>'; // what a visitor typed

echo 'strip_tags():       ', strip_tags($input), "\n";
echo 'htmlspecialchars(): ', htmlspecialchars($input), "\n";
echo 'both:               ', htmlspecialchars(strip_tags($input)), "\n";

Output on PHP 8.0.30

strip_tags():       Tom's "best" offer
htmlspecialchars(): &lt;b&gt;Tom's &quot;best&quot; offer&lt;/b&gt;
both:               Tom's &quot;best&quot; offer

Output on PHP 8.5.11

strip_tags():       Tom's "best" offer
htmlspecialchars(): &lt;b&gt;Tom&#039;s &quot;best&quot; offer&lt;/b&gt;
both:               Tom&#039;s &quot;best&quot; offer
  • strip_tags() removes the tags and leaves the quotes as they are.
  • htmlspecialchars() keeps the tags as visible text and encodes quotes. On PHP 8.0 it leaves the single quote alone; since PHP 8.1: “This means that ' is escaped to &#039; while previously nothing was done.” (php.net)
  • Both together, on PHP 8.1 and later, give the same text as the old filter, with different but equivalent HTML codes for the quotes.

WordPress has its own function for this, sanitize_text_field(): it “Sanitizes a string from user input or from the database.” (developer.wordpress.org) We ran it on WordPress 7.1.2 with the same two inputs:

sanitize-text-field.php · run with WP-CLI’s eval-file on our test site (WordPress 7.1.2)

$input = '<b>Tom\'s "best" offer</b>';
echo sanitize_text_field( $input ), "\n";

$input = '5 < 6 and <b>bold</b>';
echo sanitize_text_field( $input ), "\n";

Output · the real output of the file above

Tom's "best" offer
5 &lt; 6 and bold

It removes the tags like strip_tags(), keeps the quotes, and keeps the text after a lone < (written as &lt;). Which one fits depends on where the text goes next, so this is the plugin developer’s decision.

Who fixes it

  1. Find the plugin or theme: the folder after wp-content/plugins/ or wp-content/themes/ in the message.
  2. Update it (Dashboard → Updates).
  3. Already on the latest version? Send the full message to its developer.
  4. Don’t edit the plugin’s files yourself: your changes are lost with its next update.

A check that reads code finds every use of the constant, while your site still runs an older PHP version:

CompatNav reports the constant wherever the code names it. It can’t judge which replacement suits the plugin; that stays with the developer. Other PHP 8.1 notices, such as passing null to a PHP function, depend on values while the site runs, and no code check can find them beforehand. How to keep notices off your pages: Deprecation notice vs fatal error.

Key takeaways

  • It’s a deprecation notice from PHP 8.1 and later; the code keeps working. On PHP 8.5 the message adds “use htmlspecialchars() instead”.
  • The old filter stripped HTML tags and encoded quotes, and it cut the text at a lone <.
  • No replacement behaves exactly the same: strip_tags(), htmlspecialchars() and WordPress’s sanitize_text_field() each keep or change different things.
  • The fix belongs in the plugin’s code: update the plugin, or send the message to its developer.
  • A check that reads code finds every use of the constant before you upgrade.

Frequently asked questions

Can I just replace it with htmlspecialchars()?

Not blindly. htmlspecialchars() doesn’t remove HTML tags; it turns them into visible text. If the old filter was used to remove tags, strip_tags() or, in WordPress, sanitize_text_field() is closer. The examples above show the differences.

Is sanitize_text_field() the same as the old filter?

No. In our test on WordPress 7.1.2 it removed the tags but kept the quotes as they were, and it kept the text after a lone < instead of cutting it off. For text going into a form field or the database, that is usually what you want; the plugin’s developer decides.

Why do I only see it on PHP 8.1 and later?

PHP 8.1 deprecated the constant. On PHP 8.0 and earlier the same code runs without a message.

Check your own site before you upgrade

CompatNav is a free WordPress plugin. It reads the code of your plugins and themes on your own server and tells you, in plain words, what will break and what will only show notices on the PHP version you choose. It never changes your code. It can’t see problems that only appear while code runs with real data, so a quick check of your site after the upgrade still matters.

Get CompatNav on wordpress.org How it works

Sources

About the code examples: each output is the real output of the code shown, run with the official PHP builds, without a php.ini, with all errors reported and displayed. Only the file path was replaced by a neutral server path.