Sanitizer: removeAttribute() method

Limited availability

This feature is not Baseline because it does not work in some of the most widely-used browsers.

The removeAttribute() method of the Sanitizer interface sets an attribute to be removed from all elements when the sanitizer is used.

The method can be used with either an allow configuration or a remove configuration. If used with a remove configuration, the specified attribute is added to the removeAttributes array. If used with an allow configuration, the attribute is removed from the attributes array (if present).

Note that to allow/disallow attributes only on specific elements use Sanitizer.allowElement().

Syntax

js
removeAttribute(attribute)

Parameters

attribute

A string indicating the name of the attribute to be disallowed globally on elements, or an object with the following properties:

name

A string containing the name of the attribute.

namespace Optional

A string containing the namespace of the attribute, which defaults to null.

Return value

true if the operation changed the configuration to disallow the attribute, and false if the attribute was already disallowed.

Note that false might be returned if the internal configuration:

  • defines a removeAttributes array that already contains the specified attribute (and is hence already filtered)
  • instead defines an attributes array that already omits the attribute (and is hence already disallowed)

Examples

How to disallow specific attributes

This example shows how removeAttribute() is used to specify that an attribute is should be removed from elements.

JavaScript

The code first creates a new Sanitizer object that initially specifies no attributes or elements. We then call removeAttribute() with the attributes title and mathcolor.

js
// Create sanitizer that allows
const sanitizer = new Sanitizer({
  removeAttributes: [],
});

// Remove the title attribute
sanitizer.removeAttribute("title");
// Remove the mathcolor attribute
sanitizer.removeAttribute("mathcolor");

// Log the sanitizer configuration
let sanitizerConfig = sanitizer.get();
log(JSON.stringify(sanitizerConfig, null, 2));

Results

The final configuration is logged below. Note how both attributes are now added to the removeAttributes list (these attributes will removed if present on elements when the sanitizer is used).

Specifications

Specification
HTML Sanitizer API
# dom-sanitizer-removeattribute

Browser compatibility

desktop mobile
Chrome
Edge
Firefox
Opera
Safari
Chrome Android
Firefox for Android
Opera Android
Safari on iOS
Samsung Internet
WebView Android
WebView on iOS
removeAttribute
Chrome – Full support
Chrome 146 (Release date: 2026-03-10)
footnote Full support
Edge – Full support
Edge 146 (Release date: 2026-03-13)
footnote Full support
Firefox – Full support
Firefox 148 (Release date: 2026-02-24)
footnote Full support
Opera – Full support
Opera 130 (Release date: 2026-04-08)
footnote Full support
Safari – No support
Safari
footnote No support
Chrome Android – Full support
Chrome Android 146 (Release date: 2026-03-10)
footnote Full support
Firefox for Android – Full support
Firefox for Android 148 (Release date: 2026-02-24)
footnote Full support
Opera Android – Full support
Opera Android 97 (Release date: 2026-04-16)
footnote Full support
Safari on iOS – No support
Safari on iOS
footnote No support
Samsung Internet – No support
Samsung Internet
footnote No support
WebView Android – Full support
WebView Android 146 (Release date: 2026-03-10)
footnote Full support
WebView on iOS – No support
WebView on iOS
footnote No support

Legend

Tip: you can click/tap on a cell for more information.

Full support
Full support
No support
No support