Strip out HTML tags from user profiles
Hi - is there any way to strip out all HTML from the user profile fields? If a user updates their profile I would prefer it to strip out all HTML which is currently does not seem to be doing, I can even enter HTML tags on "real name" field, which render on the user profile page post update.
http://i.imgur.com/ldaFTQV.png (Example that renders)
Comments
That's a good catch. This would be a nice feature. It can be added as a enable/disable option in conf file. So that if admin wants to disable it he can, and switch back if he changes his mind.
I think of another feature where you can "nofollow" all external links, it will save from spam and link-juice.