Skip to content

Commit 654c05f

Browse files
committed
doc: add warning based on wkhtmltopdf recommendations
1 parent 3dd138e commit 654c05f

File tree

1 file changed

+10
-0
lines changed

1 file changed

+10
-0
lines changed

README.md

Lines changed: 10 additions & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -25,6 +25,16 @@ composer require knplabs/knp-snappy
2525

2626
## Usage
2727

28+
> ⚠️ **Security Warning: Do NOT use `wkhtmltopdf` with untrusted HTML!**
29+
>
30+
> Never process user-supplied HTML/JS without **thorough sanitization**.
31+
> Failing to do so can result in a **complete takeover of the server** running `wkhtmltopdf`.
32+
>
33+
> To mitigate risks, it is strongly recommended to use a Mandatory Access Control system like **AppArmor** or **SELinux**.
34+
>
35+
> 🔗 [See the official recommendations](https://wkhtmltopdf.org/status.html#recommendations)
36+
37+
2838
### Initialization
2939
```php
3040
<?php

0 commit comments

Comments
 (0)