function check_url

8.x check_url($uri)

Strips dangerous protocols from a URI and encodes it for output to HTML.


$uri: A plain-text URI that might contain dangerous protocols.

Return value

A URI stripped of dangerous protocols and encoded for output to an HTML attribute value. Because it is already encoded, it should not be set as a value within a $attributes array passed to Drupal\Core\Template\Attribute, because Drupal\Core\Template\Attribute expects those values to be plain-text strings. To pass a filtered URI to Drupal\Core\Template\Attribute, call drupal_strip_dangerous_protocols() instead.

See also



Related topics

9 calls to check_url()
comment_tokens in drupal/core/modules/comment/
Implements hook_tokens().
format_rss_channel in drupal/core/includes/
Formats an RSS channel.
format_rss_item in drupal/core/includes/
Formats a single RSS item.
install_check_translations in drupal/core/includes/
Checks installation requirements and reports any errors.
install_display_requirements in drupal/core/includes/
Displays installation requirements.

... See full list


drupal/core/includes/, line 904
Common functions that many Drupal modules will need to reference.


function check_url($uri) {
  return String::checkPlain(UrlValidator::stripDangerousProtocols($uri));