Escape HTML special characters to prevent XSS injection.
Escapes & < > " ' — including the apostrophe (') for
defense-in-depth against single-quoted attribute contexts. Callers
embedding into either attribute style (double- or single-quoted)
are safe.
Escape HTML special characters to prevent XSS injection.
Escapes
& < > " '— including the apostrophe (') for defense-in-depth against single-quoted attribute contexts. Callers embedding into either attribute style (double- or single-quoted) are safe.