Problem/Motivation

Xss::attributes() contains a list of dangerous attributes or prefixes:

              in_array($attribute_name, ['style', 'srcdoc']) ||
              str_starts_with($attribute_name, 'on') ||
              str_starts_with($attribute_name, 'data-hx') ||
              str_starts_with($attribute_name, 'hx') ||
              str_starts_with($attribute_name, '-') ||

Contrib modules sometimes have their own logic for detecting dangerous attributes and they have to duplicate these rules.
This means that if we had a new dangerous attribute (this was done for SA-CORE-2026-011 for example), they won't automatically benefit from it.

Steps to reproduce

Proposed resolution

Maybe move this logic to a method like this:

Xss::isAttributeDangerous($attribute_name)

Remaining tasks

User interface changes

Introduced terminology

API changes

Data model changes

Release notes snippet

Comments

prudloff created an issue.