标签: xss
这足以避免XSS攻击
substr($_GET['code'], 0, 20)
谢谢
测试用例: / test?code = 1234%3Cimg + src = xyz + onerror = alert(150)%3E%3Cxss_44b3c79656b91c5a7918b8b047f506fb /%3E
<div><?= $_GET['code'] ?></div>