Sanitize on input, escape on output: the WordPress rule behind XSSTwo WordPress functions people constantly mix up, and the XSS hole that opens when they do.Jun 27, 2026·5 min read·23