# b-blocks/2.1.8/build/html/render.php

bBlocks – Essential Gutenberg Blocks &amp; Patterns Collection, version 2.1.8. 28 lines.

- Page: https://pluginprobe.com/plugins/b-blocks/2.1.8/code/build/html/render.php
- Raw: https://pluginprobe.com/plugins/b-blocks/2.1.8/raw/build/html/render.php
- Modified: 2026-09-27T04:52:46+00:00

Line numbers below start at 1. Link to a line or a range by appending a fragment to the
page URL, for example `https://pluginprobe.com/plugins/b-blocks/2.1.8/code/build/html/render.php#L10-L20`.

```php
<?php
/**
 * HTML block server-side render.
 *
 * `htmlCode` is raw author markup that view.js injects into the page and then
 * activates any <script> inside it. That is exactly the capability WordPress
 * gates behind unfiltered_html, so the attribute is filtered here against the
 * POST AUTHOR's capability before it is ever handed to the frontend. An author
 * who may not publish unfiltered HTML gets a wp_kses_post() copy, which has no
 * <script> and no event-handler attributes left in it - so the activation pass
 * in view.js finds nothing to run.
 *
 * @package bBlocks
 *
 * @var array $attributes Block attributes.
 */

$id = wp_unique_id( 'bBlocksHtml-' );

$attributes['htmlCode'] = BBlocks\Inc\Sanitize::userHtml( $attributes['htmlCode'] ?? '' );
?>
<div
	<?php // phpcs:ignore WordPress.Security.EscapeOutput.OutputNotEscaped -- get_block_wrapper_attributes() is properly escaped ?>
	<?php echo get_block_wrapper_attributes(); ?>
	id='<?php echo esc_attr( $id ); ?>'
	data-attributes='<?php echo esc_attr( wp_json_encode( $attributes ) ); ?>'
></div>

```
