diff --git a/src/Rules/XssRule.php b/src/Rules/XssRule.php index 1c3cfb2..66dc3ca 100644 --- a/src/Rules/XssRule.php +++ b/src/Rules/XssRule.php @@ -484,6 +484,15 @@ class XssRule extends BaseRule '/\bcsrf_token\s*\(/', // CSRF token helper '/\btrans\s*\(/', // Laravel translation (usually safe) '/\b__\s*\(/', // Laravel translation helper + // URL helpers - generate URLs, not HTML, so safe for raw output + '/^\s*route\s*\(/', // route() helper + '/^\s*url\s*\(/', // url() helper + '/^\s*asset\s*\(/', // asset() helper + '/^\s*secure_url\s*\(/', // secure_url() helper + '/^\s*secure_asset\s*\(/', // secure_asset() helper + '/^\s*action\s*\(/', // action() helper + '/^\s*mix\s*\(/', // mix() helper (Laravel Mix) + '/^\s*vite\s*\(/', // vite() helper (Vite) ]; foreach ($safePatterns as $pattern) {