If you need a nice class that will clean pretty much anything for your PHP app, grab this class. Here’s the summary from the developer:

This class can filter input of stray or malicious PHP, Javascript or HTML tags and to prevent cross-site scripting (XSS) attacks. It should be used to filter input supplied by the user, such as an HTML code entered in form fields.

I have tried to make this class as easy as possible to use. You have control over the filter process unlike other alternatives, and can input a string or an entire array to be cleaned (such as $_POST).

** SQL Injection feature has been added.

I’ve used this in several sites. Mostly I pass all of POSTS, GET and REQUEST through this class before working with the content.