diff --git a/core/includes/theme.inc b/core/includes/theme.inc
index 7400017..4d441f2 100644
--- a/core/includes/theme.inc
+++ b/core/includes/theme.inc
@@ -1350,7 +1350,7 @@ function template_preprocess_page(&$variables) {
   $variables['language']          = $language_interface;
   $variables['logo']              = theme_get_setting('logo.url');
   $variables['site_name']         = (theme_get_setting('features.name') ? SafeMarkup::checkPlain($site_config->get('name')) : '');
-  $variables['site_slogan']       = (theme_get_setting('features.slogan') ? Xss::filterAdmin($site_config->get('slogan')) : '');
+  $variables['site_slogan']['#markup'] = (theme_get_setting('features.slogan') ? $site_config->get('slogan') : '');
 
   // An exception might be thrown.
   try {
diff --git a/core/lib/Drupal/Component/Utility/SafeMarkup.php b/core/lib/Drupal/Component/Utility/SafeMarkup.php
index d97dc2f..9352b38 100644
--- a/core/lib/Drupal/Component/Utility/SafeMarkup.php
+++ b/core/lib/Drupal/Component/Utility/SafeMarkup.php
@@ -15,9 +15,9 @@
  * provides a store for known safe strings and methods to manage them
  * throughout the page request.
  *
- * Strings sanitized by self::checkPlain() or Xss::filter() are automatically
- * marked safe, as are markup strings created from render arrays via
- * drupal_render().
+ * Strings sanitized by self::checkPlain(), self::xssFilter() or
+ * self::xssFilterAdmin() are automatically marked safe, as are markup strings
+ * created from render arrays via drupal_render().
  *
  * This class should be limited to internal use only. Module developers should
  * instead use the appropriate
@@ -139,19 +139,69 @@ public static function escape($string) {
   }
 
   /**
-   * Applies a very permissive XSS/HTML filter for admin-only use.
+   * Filters HTML intended for admin use for XSS and marks the result as safe.
+   *
+   * This method should be used instead of
+   * \Drupal\Component\Utility\Xss::filterAdmin() when the result is being added
+   * to a render array that is constructed before rendering begins. Calling this
+   * method unnecessarily will result in bloating the safe string list and
+   * increases the chance of unintended side-effects.
+   *
+   * If the caller does not want to filter strings that are marked safe already
+   * it needs to check \Drupal\Component\Utility\SafeMarkup::isSafe() itself.
    *
    * @param string $string
    *   A string.
    *
    * @return string
-   *   The escaped string. If $string was already set as safe with
-   *   self::set(), it won't be escaped again.
+   *   The filtered string. The string is marked as safe.
    *
    * @see \Drupal\Component\Utility\Xss::filterAdmin()
    */
+  public static function xssFilterAdmin($string) {
+    $string = Xss::filterAdmin($string);
+    return static::set($string);
+  }
+
+  /**
+   * Applies a very permissive XSS/HTML filter for admin-only use, if not safe.
+   *
+   * @deprecated as of Drupal 8.0.x, will be removed before Drupal 8.0.0. Use
+   *   \Drupal\Component\Utility\SafeMarkup::xssFilterAdmin() instead. If the
+   *   caller does not want to filter strings that are marked safe already it
+   *   needs to check \Drupal\Component\Utility\SafeMarkup::isSafe() itself.
+   *
+   * @see \Drupal\Component\Utility\SafeMarkup::xssFilterAdmin()
+   */
   public static function checkAdminXss($string) {
-    return static::isSafe($string) ? $string : Xss::filterAdmin($string);
+    return static::isSafe($string) ? $string : static::xssFilterAdmin($string);
+  }
+
+  /**
+   * Filters HTML for XSS vulnerabilities and marks the result as safe.
+   *
+   * This method should be used instead of
+   * \Drupal\Component\Utility\Xss::filter() when the result is being added to a
+   * render array that is construct before rendering begins. Calling this method
+   * unnecessarily will result in bloating the safe string list and increases
+   * the chance of unintended side-effects.
+   *
+   * @param $string
+   *   The string with raw HTML in it. It will be stripped of everything that
+   *   can cause an XSS attack. The string provided will always be escaped
+   *   regardless of whether the string is already marked as safe.
+   * @param array $html_tags
+   *   An array of HTML tags.
+   *
+   * @return string
+   *   An XSS safe version of $string, or an empty string if $string is not
+   *   valid UTF-8. The string is marked as safe.
+   *
+   * @see \Drupal\Component\Utility\Xss::filter()
+   */
+  public static function xssFilter($string, $html_tags = array('a', 'em', 'strong', 'cite', 'blockquote', 'code', 'ul', 'ol', 'li', 'dl', 'dt', 'dd')) {
+    $string = Xss::filter($string, $html_tags);
+    return static::set($string);
   }
 
   /**
diff --git a/core/lib/Drupal/Component/Utility/Xss.php b/core/lib/Drupal/Component/Utility/Xss.php
index f967ca6..a4efad1 100644
--- a/core/lib/Drupal/Component/Utility/Xss.php
+++ b/core/lib/Drupal/Component/Utility/Xss.php
@@ -29,14 +29,19 @@ class Xss {
    * Based on kses by Ulf Harnhammar, see http://sourceforge.net/projects/kses.
    * For examples of various XSS attacks, see: http://ha.ckers.org/xss.html.
    *
-   * This code does five things:
+   * This method is preferred to
+   * \Drupal\Component\Utility\SafeMarkup::xssFilter() when the result is
+   * not being used directly in the rendering system (for example, when its
+   * result is being combined with other strings before rendering). This avoids
+   * bloating the safe string list with partial strings if the whole result will
+   * be marked safe.
+   *
+   * This code does four things:
    * - Removes characters and constructs that can trick browsers.
    * - Makes sure all HTML entities are well-formed.
    * - Makes sure all HTML tags and attributes are well-formed.
    * - Makes sure no HTML tags contain URLs with a disallowed protocol (e.g.
    *   javascript:).
-   * - Marks the sanitized, XSS-safe version of $string as safe markup for
-   *   rendering.
    *
    * @param $string
    *   The string with raw HTML in it. It will be stripped of everything that
@@ -49,7 +54,7 @@ class Xss {
    *   valid UTF-8.
    *
    * @see \Drupal\Component\Utility\Unicode::validateUtf8()
-   * @see \Drupal\Component\Utility\SafeMarkup
+   * @see \Drupal\Component\Utility\SafeMarkup::xssFilter()
    *
    * @ingroup sanitization
    */
@@ -83,7 +88,7 @@ public static function filter($string, $html_tags = array('a', 'em', 'strong', '
     // for output. All other known XSS vectors have been filtered out by this
     // point and any HTML tags remaining will have been deliberately allowed, so
     // it is acceptable to call SafeMarkup::set() on the resultant string.
-    return SafeMarkup::set(preg_replace_callback('%
+    return preg_replace_callback('%
       (
       <(?=[^a-zA-Z!/])  # a lone <
       |                 # or
@@ -92,7 +97,7 @@ public static function filter($string, $html_tags = array('a', 'em', 'strong', '
       <[^>]*(>|$)       # a string that starts with a <, up until the > or the end of the string
       |                 # or
       >                 # just a >
-      )%x', $splitter, $string));
+      )%x', $splitter, $string);
   }
 
   /**
@@ -103,6 +108,13 @@ public static function filter($string, $html_tags = array('a', 'em', 'strong', '
    * is desired (so \Drupal\Component\Utility\SafeMarkup::checkPlain() is
    * not acceptable).
    *
+   * This method is preferred to
+   * \Drupal\Component\Utility\SafeMarkup::xssFilterAdmin() when the result is
+   * not being used directly in the rendering system (for example, when its
+   * result is being combined with other strings before rendering). This avoids
+   * bloating the safe string list with partial strings if the whole result will
+   * be marked safe.
+   *
    * Allows all tags that can be used inside an HTML body, save
    * for scripts and styles.
    *
@@ -111,6 +123,8 @@ public static function filter($string, $html_tags = array('a', 'em', 'strong', '
    *
    * @return string
    *   The filtered string.
+   *
+   * @see \Drupal\Component\Utility\SafeMarkup::xssFilterAdmin()
    */
   public static function filterAdmin($string) {
     return static::filter($string, static::$adminTags);
diff --git a/core/lib/Drupal/Core/Render/Element/HtmlTag.php b/core/lib/Drupal/Core/Render/Element/HtmlTag.php
index 5dc3afe..477f847 100644
--- a/core/lib/Drupal/Core/Render/Element/HtmlTag.php
+++ b/core/lib/Drupal/Core/Render/Element/HtmlTag.php
@@ -8,6 +8,7 @@
 namespace Drupal\Core\Render\Element;
 
 use Drupal\Component\Utility\SafeMarkup;
+use Drupal\Component\Utility\Xss;
 use Drupal\Core\Template\Attribute;
 
 /**
@@ -50,7 +51,7 @@ public function getInfo() {
    * pre-render callback being a #markup element, it is not passed through
    * \Drupal\Component\Utility\Xss::filterAdmin(). This is because it is marked
    * safe here, which causes
-   * \Drupal\Component\Utility\SafeMarkup::checkAdminXss() to regard it as safe
+   * \Drupal\Core\Render\Renderer::xssFilterAdminIfUnsafe() to regard it as safe
    * and bypass the call to \Drupal\Component\Utility\Xss::filterAdmin().
    *
    * @param array $element
@@ -161,7 +162,7 @@ public static function preRenderConditionalComments($element) {
     }
     else {
       // The IE expression might contain some user input data.
-      $expression = SafeMarkup::checkAdminXss($browsers['IE']);
+      $expression = Xss::filterAdmin($browsers['IE']);
     }
 
     // If the #prefix and #suffix properties are used, wrap them with
@@ -173,8 +174,8 @@ public static function preRenderConditionalComments($element) {
 
     // Ensure what we are dealing with is safe.
     // This would be done later anyway in drupal_render().
-    $prefix = isset($elements['#prefix']) ? SafeMarkup::checkAdminXss($elements['#prefix']) : '';
-    $suffix = isset($elements['#suffix']) ? SafeMarkup::checkAdminXss($elements['#suffix']) : '';
+    $prefix = isset($elements['#prefix']) ? Xss::FilterAdmin($elements['#prefix']) : '';
+    $suffix = isset($elements['#suffix']) ? Xss::FilterAdmin($elements['#suffix']) : '';
 
     // Now calling SafeMarkup::set is safe, because we ensured the
     // data coming in was at least admin escaped.
diff --git a/core/lib/Drupal/Core/Render/Renderer.php b/core/lib/Drupal/Core/Render/Renderer.php
index d98955d..f1e184a 100644
--- a/core/lib/Drupal/Core/Render/Renderer.php
+++ b/core/lib/Drupal/Core/Render/Renderer.php
@@ -393,7 +393,7 @@ protected function doRender(&$elements, $is_root_call = FALSE) {
     if (isset($elements['#markup'])) {
       // @todo Decide how to support non-HTML in the render API in
       //   https://www.drupal.org/node/2501313.
-      $elements['#markup'] = SafeMarkup::checkAdminXss($elements['#markup']);
+      $elements['#markup'] = $this->xssFilterAdminIfUnsafe($elements['#markup']);
     }
 
     // Assume that if #theme is set it represents an implemented hook.
@@ -407,7 +407,7 @@ protected function doRender(&$elements, $is_root_call = FALSE) {
       );
       foreach ($markup_keys as $key) {
         if (!empty($elements[$key]) && is_scalar($elements[$key])) {
-          $elements[$key] = SafeMarkup::checkAdminXss($elements[$key]);
+          $elements[$key] = $this->xssFilterAdminIfUnsafe($elements[$key]);
         }
       }
     }
@@ -493,8 +493,8 @@ protected function doRender(&$elements, $is_root_call = FALSE) {
     // with how render cached output gets stored. This ensures that placeholder
     // replacement logic gets the same data to work with, no matter if #cache is
     // disabled, #cache is enabled, there is a cache hit or miss.
-    $prefix = isset($elements['#prefix']) ? SafeMarkup::checkAdminXss($elements['#prefix']) : '';
-    $suffix = isset($elements['#suffix']) ? SafeMarkup::checkAdminXss($elements['#suffix']) : '';
+    $prefix = isset($elements['#prefix']) ? $this->xssFilterAdminIfUnsafe($elements['#prefix']) : '';
+    $suffix = isset($elements['#suffix']) ? $this->xssFilterAdminIfUnsafe($elements['#suffix']) : '';
 
     $elements['#markup'] = $prefix . $elements['#children'] . $suffix;
 
@@ -651,4 +651,23 @@ public function addCacheableDependency(array &$elements, $dependency) {
     $meta_a->merge($meta_b)->applyTo($elements);
   }
 
+  /**
+   * Applies a very permissive XSS/HTML filter for admin-only use, if not safe.
+   *
+   * We check if the string has been marked safe to ensure we do not filter
+   * strings intended for display.
+   *
+   * @param string $string
+   *   A string.
+   *
+   * @return string
+   *   The escaped string. If SafeMarkup::isSafe($string) returns TRUE, it won't
+   *   be escaped again.
+   */
+  protected function xssFilterAdminIfUnsafe($string) {
+    // @todo https://www.drupal.org/node/2506581 replace with
+    //   Xss::filterAdmin().
+    return SafeMarkup::isSafe($string) ? $string : SafeMarkup::xssFilterAdmin($string);
+  }
+
 }
diff --git a/core/modules/aggregator/src/Controller/AggregatorController.php b/core/modules/aggregator/src/Controller/AggregatorController.php
index eaa82e5..13ff3d9 100644
--- a/core/modules/aggregator/src/Controller/AggregatorController.php
+++ b/core/modules/aggregator/src/Controller/AggregatorController.php
@@ -7,7 +7,7 @@
 
 namespace Drupal\aggregator\Controller;
 
-use Drupal\Component\Utility\Xss;
+use Drupal\Component\Utility\SafeMarkup;
 use Drupal\Core\Controller\ControllerBase;
 use Drupal\Core\Datetime\DateFormatter;
 use Drupal\aggregator\FeedInterface;
@@ -187,7 +187,7 @@ public function pageLast() {
    *   The feed label.
    */
   public function feedTitle(FeedInterface $aggregator_feed) {
-    return Xss::filter($aggregator_feed->label());
+    return SafeMarkup::xssFilter($aggregator_feed->label());
   }
 
 }
diff --git a/core/modules/dblog/src/Controller/DbLogController.php b/core/modules/dblog/src/Controller/DbLogController.php
index 2e2eccf..b6d8326 100644
--- a/core/modules/dblog/src/Controller/DbLogController.php
+++ b/core/modules/dblog/src/Controller/DbLogController.php
@@ -207,7 +207,7 @@ public function overview() {
           $this->dateFormatter->format($dblog->timestamp, 'short'),
           $message,
           array('data' => $username),
-          Xss::filter($dblog->link),
+          SafeMarkup::xssFilter($dblog->link),
         ),
         // Attributes for table row.
         'class' => array(Html::getClass('dblog-' . $dblog->type), $classes[$dblog->severity]),
@@ -285,7 +285,7 @@ public function eventDetails($event_id) {
         ),
         array(
           array('data' => $this->t('Operations'), 'header' => TRUE),
-          SafeMarkup::checkAdminXss($dblog->link),
+          SafeMarkup::xssFilterAdmin($dblog->link),
         ),
       );
       $build['dblog_table'] = array(
diff --git a/core/modules/filter/filter.module b/core/modules/filter/filter.module
index 400d6cc..d28b841 100644
--- a/core/modules/filter/filter.module
+++ b/core/modules/filter/filter.module
@@ -430,7 +430,7 @@ function template_preprocess_filter_tips(&$variables) {
   foreach ($variables['tips'] as $name => $tiplist) {
     foreach ($tiplist as $tip_key => $tip) {
       $tiplist[$tip_key]['attributes'] = new Attribute();
-      $tiplist[$tip_key]['tip'] = Xss::filterAdmin($tiplist[$tip_key]['tip']);
+      $tiplist[$tip_key]['tip'] = SafeMarkup::xssFilterAdmin($tiplist[$tip_key]['tip']);
     }
 
     $variables['tips'][$name] = array(
diff --git a/core/modules/filter/src/Plugin/Filter/FilterCaption.php b/core/modules/filter/src/Plugin/Filter/FilterCaption.php
index 6f90565..ed241d8 100644
--- a/core/modules/filter/src/Plugin/Filter/FilterCaption.php
+++ b/core/modules/filter/src/Plugin/Filter/FilterCaption.php
@@ -45,7 +45,7 @@ public function process($text, $langcode) {
         // Sanitize caption: decode HTML encoding, limit allowed HTML tags; only
         // allow inline tags that are allowed by default, plus <br>.
         $caption = Html::decodeEntities($caption);
-        $caption = Xss::filter($caption, array('a', 'em', 'strong', 'cite', 'code', 'br'));
+        $caption = SafeMarkup::xssFilter($caption, array('a', 'em', 'strong', 'cite', 'code', 'br'));
 
         // The caption must be non-empty.
         if (Unicode::strlen($caption) === 0) {
diff --git a/core/modules/menu_ui/src/Controller/MenuController.php b/core/modules/menu_ui/src/Controller/MenuController.php
index 7287054..560bb18 100644
--- a/core/modules/menu_ui/src/Controller/MenuController.php
+++ b/core/modules/menu_ui/src/Controller/MenuController.php
@@ -7,7 +7,7 @@
 
 namespace Drupal\menu_ui\Controller;
 
-use Drupal\Component\Utility\Xss;
+use Drupal\Component\Utility\SafeMarkup;
 use Drupal\Core\Controller\ControllerBase;
 use Drupal\Core\Menu\MenuParentFormSelectorInterface;
 use Drupal\system\MenuInterface;
@@ -77,7 +77,7 @@ public function getParentOptions(Request $request) {
    *   The menu label.
    */
   public function menuTitle(MenuInterface $menu) {
-    return Xss::filter($menu->label());
+    return SafeMarkup::xssFilter($menu->label());
   }
 
 }
diff --git a/core/modules/node/node.module b/core/modules/node/node.module
index f7374da..f422c4e 100644
--- a/core/modules/node/node.module
+++ b/core/modules/node/node.module
@@ -9,6 +9,7 @@
  */
 
 use Drupal\Component\Utility\Html;
+use Drupal\Component\Utility\SafeMarkup;
 use Drupal\Component\Utility\Xss;
 use Drupal\Core\Access\AccessResult;
 use Drupal\Core\Cache\Cache;
@@ -491,30 +492,6 @@ function node_is_page(NodeInterface $node) {
 }
 
 /**
- * Prepares variables for list of available node type templates.
- *
- * Default template: node-add-list.html.twig.
- *
- * @param array $variables
- *   An associative array containing:
- *   - content: An array of content types.
- *
- * @see node_add_page()
- */
-function template_preprocess_node_add_list(&$variables) {
-  $variables['types'] = array();
-  if (!empty($variables['content'])) {
-    foreach ($variables['content'] as $type) {
-      $variables['types'][$type->id()] = array(
-        'type' => $type->id(),
-        'add_link' => \Drupal::l($type->label(), new Url('node.add', array('node_type' => $type->id()))),
-        'description' => Xss::filterAdmin($type->getDescription()),
-      );
-    }
-  }
-}
-
-/**
  * Implements hook_preprocess_HOOK() for HTML document templates.
  */
 function node_preprocess_html(&$variables) {
diff --git a/core/modules/node/src/Controller/NodeController.php b/core/modules/node/src/Controller/NodeController.php
index b8e4918..3291f33 100644
--- a/core/modules/node/src/Controller/NodeController.php
+++ b/core/modules/node/src/Controller/NodeController.php
@@ -8,7 +8,6 @@
 namespace Drupal\node\Controller;
 
 use Drupal\Component\Utility\SafeMarkup;
-use Drupal\Component\Utility\Xss;
 use Drupal\Core\Controller\ControllerBase;
 use Drupal\Core\Datetime\DateFormatter;
 use Drupal\Core\DependencyInjection\ContainerInjectionInterface;
@@ -195,7 +194,7 @@ public function revisionOverview(NodeInterface $node) {
           '#context' => [
             'date' => $link,
             'username' => $this->renderer->renderPlain($username),
-            'message' => Xss::filter($revision->revision_log->value),
+            'message' => SafeMarkup::xssFilter($revision->revision_log->value),
           ],
         ],
       ];
diff --git a/core/modules/node/src/NodeTypeListBuilder.php b/core/modules/node/src/NodeTypeListBuilder.php
index 46bec74..2e4b442 100644
--- a/core/modules/node/src/NodeTypeListBuilder.php
+++ b/core/modules/node/src/NodeTypeListBuilder.php
@@ -7,10 +7,10 @@
 
 namespace Drupal\node;
 
+use Drupal\Component\Utility\SafeMarkup;
 use Drupal\Core\Config\Entity\ConfigEntityListBuilder;
 use Drupal\Core\Url;
 use Drupal\Core\Entity\EntityInterface;
-use Drupal\Component\Utility\Xss;
 
 /**
  * Defines a class to build a listing of node type entities.
@@ -39,7 +39,7 @@ public function buildRow(EntityInterface $entity) {
       'data' => $this->getLabel($entity),
       'class' => array('menu-label'),
     );
-    $row['description'] = Xss::filterAdmin($entity->getDescription());
+    $row['description'] = SafeMarkup::xssFilterAdmin($entity->getDescription());
     return $row + parent::buildRow($entity);
   }
 
diff --git a/core/modules/node/templates/node-add-list.html.twig b/core/modules/node/templates/node-add-list.html.twig
index c64751b..c878b45 100644
--- a/core/modules/node/templates/node-add-list.html.twig
+++ b/core/modules/node/templates/node-add-list.html.twig
@@ -10,8 +10,6 @@
  *   - add_link: Link to create a piece of content of this type.
  *   - description: Description of this type of content.
  *
- * @see template_preprocess_node_add_list()
- *
  * @ingroup themeable
  */
 #}
diff --git a/core/modules/search/search.module b/core/modules/search/search.module
index b4c4126..25d52b5 100644
--- a/core/modules/search/search.module
+++ b/core/modules/search/search.module
@@ -8,7 +8,6 @@
 use Drupal\Component\Utility\SafeMarkup;
 use Drupal\Component\Utility\Html;
 use Drupal\Component\Utility\Unicode;
-use Drupal\Component\Utility\Xss;
 use Drupal\Core\Cache\Cache;
 use Drupal\Core\Form\FormStateInterface;
 use Drupal\Core\Routing\RouteMatchInterface;
@@ -768,7 +767,7 @@ function search_excerpt($keys, $text, $langcode = NULL) {
   // Highlight keywords. Must be done at once to prevent conflicts ('strong'
   // and '<strong>').
   $text = trim(preg_replace('/' . $boundary . '(?:' . implode('|', $keys) . ')' . $boundary . '/iu', '<strong>\0</strong>', ' ' . $text . ' '));
-  return Xss::filter($text, ['strong']);
+  return SafeMarkup::xssFilter($text, ['strong']);
 }
 
 /**
diff --git a/core/modules/simpletest/src/Form/SimpletestResultsForm.php b/core/modules/simpletest/src/Form/SimpletestResultsForm.php
index ea3447e..63dea75 100644
--- a/core/modules/simpletest/src/Form/SimpletestResultsForm.php
+++ b/core/modules/simpletest/src/Form/SimpletestResultsForm.php
@@ -313,7 +313,7 @@ public static function addResultForm(array &$form, array $results) {
       $rows = array();
       foreach ($assertions as $assertion) {
         $row = array();
-        $row[] = SafeMarkup::checkAdminXss($assertion->message);
+        $row[] = SafeMarkup::xssFilterAdmin($assertion->message);
         $row[] = $assertion->message_group;
         $row[] = \Drupal::service('file_system')->basename(($assertion->file));
         $row[] = $assertion->line;
diff --git a/core/modules/system/src/Plugin/Block/SystemBrandingBlock.php b/core/modules/system/src/Plugin/Block/SystemBrandingBlock.php
index c5ebaa5..16b0368 100644
--- a/core/modules/system/src/Plugin/Block/SystemBrandingBlock.php
+++ b/core/modules/system/src/Plugin/Block/SystemBrandingBlock.php
@@ -7,6 +7,7 @@
 
 namespace Drupal\system\Plugin\Block;
 
+use Drupal\Component\Utility\SafeMarkup;
 use Drupal\Core\Block\BlockBase;
 use Drupal\Core\Cache\Cache;
 use Drupal\Core\Config\ConfigFactoryInterface;
@@ -173,7 +174,7 @@ public function build() {
     );
 
     $build['site_slogan'] = array(
-      '#markup' => Xss::filterAdmin($site_config->get('slogan')),
+      '#markup' => $site_config->get('slogan'),
       '#access' => $this->configuration['use_site_slogan'],
     );
 
diff --git a/core/modules/taxonomy/src/Controller/TaxonomyController.php b/core/modules/taxonomy/src/Controller/TaxonomyController.php
index e24eb6f..2e35678 100644
--- a/core/modules/taxonomy/src/Controller/TaxonomyController.php
+++ b/core/modules/taxonomy/src/Controller/TaxonomyController.php
@@ -7,6 +7,7 @@
 
 namespace Drupal\taxonomy\Controller;
 
+use Drupal\Component\Utility\SafeMarkup;
 use Drupal\Component\Utility\Xss;
 use Drupal\Core\Controller\ControllerBase;
 use Drupal\taxonomy\TermInterface;
@@ -54,7 +55,7 @@ public function addForm(VocabularyInterface $taxonomy_vocabulary) {
    *   The term label.
    */
   public function vocabularyTitle(VocabularyInterface $taxonomy_vocabulary) {
-    return Xss::filter($taxonomy_vocabulary->label());
+    return SafeMarkup::xssFilter($taxonomy_vocabulary->label());
   }
 
   /**
@@ -67,7 +68,7 @@ public function vocabularyTitle(VocabularyInterface $taxonomy_vocabulary) {
    *   The term label.
    */
   public function termTitle(TermInterface $taxonomy_term) {
-    return Xss::filter($taxonomy_term->getName());
+    return SafeMarkup::xssFilter($taxonomy_term->getName());
   }
 
 }
diff --git a/core/modules/user/src/Controller/UserController.php b/core/modules/user/src/Controller/UserController.php
index 03dcb10..a52372d 100644
--- a/core/modules/user/src/Controller/UserController.php
+++ b/core/modules/user/src/Controller/UserController.php
@@ -7,6 +7,7 @@
 
 namespace Drupal\user\Controller;
 
+use Drupal\Component\Utility\SafeMarkup;
 use Drupal\Component\Utility\Xss;
 use Drupal\Core\Controller\ControllerBase;
 use Drupal\Core\Datetime\DateFormatter;
@@ -161,7 +162,7 @@ public function userPage() {
    *   The user account name.
    */
   public function userTitle(UserInterface $user = NULL) {
-    return $user ? Xss::filter($user->getUsername()) : '';
+    return $user ? SafeMarkup::xssFilter($user->getUsername()) : '';
   }
 
   /**
diff --git a/core/modules/views/src/Plugin/views/field/Field.php b/core/modules/views/src/Plugin/views/field/Field.php
index 386456c..455f48e 100644
--- a/core/modules/views/src/Plugin/views/field/Field.php
+++ b/core/modules/views/src/Plugin/views/field/Field.php
@@ -671,7 +671,7 @@ public function renderItems($items) {
     if (!empty($items)) {
       $items = $this->prepareItemsByDelta($items);
       if ($this->options['multi_type'] == 'separator' || !$this->options['group_rows']) {
-        $separator = $this->options['multi_type'] == 'separator' ? SafeMarkup::checkAdminXss($this->options['separator']) : '';
+        $separator = $this->options['multi_type'] == 'separator' ? SafeMarkup::xssFilterAdmin($this->options['separator']) : '';
         $build = [
           '#type' => 'inline_template',
           '#template' => '{{ items | safe_join(separator) }}',
diff --git a/core/tests/Drupal/Tests/Component/Utility/SafeMarkupTest.php b/core/tests/Drupal/Tests/Component/Utility/SafeMarkupTest.php
index 1776e75..ff09bc5 100644
--- a/core/tests/Drupal/Tests/Component/Utility/SafeMarkupTest.php
+++ b/core/tests/Drupal/Tests/Component/Utility/SafeMarkupTest.php
@@ -213,6 +213,30 @@ public function testReplace($search, $replace, $subject, $expected, $is_safe) {
   }
 
   /**
+   * Tests the interaction between the safe list and XSS filtering.
+   *
+   * @covers ::xssFilter
+   * @covers ::xssFilterAdmin
+   * @covers ::escape
+   */
+  public function testAdminXss() {
+    // This will strip the <marquee> tags.
+    $this->assertEquals('text', SafeMarkup::xssFilterAdmin('<marquee>text</marquee>'));
+
+    // This won't strip the <marquee> tags and the string with html will be
+    // marked as safe.
+    $filtered = SafeMarkup::xssFilter('<marquee>text</marquee>', array('marquee'));
+    $this->assertEquals('<marquee>text</marquee>', $filtered);
+
+    // This will strip the <marquee> tags.
+    $this->assertEquals('text', SafeMarkup::xssFilterAdmin($filtered));
+    $this->assertEquals('text', SafeMarkup::xssFilter($filtered));
+
+    // This won't escape the <marquee> tags.
+    $this->assertEquals('<marquee>text</marquee>', SafeMarkup::escape($filtered));
+  }
+
+  /**
    * Data provider for testReplace().
    *
    * @see testReplace()
