Escaping
Always escape output. Always.
One-liner helper
function h(string $s): string { return htmlspecialchars($s, ENT_QUOTES | ENT_SUBSTITUTE, 'UTF-8'); }Escaping helpers, slugify, CSRF tokens, and a renderer that is strict enough to be safe.
Always escape output. Always.
function h(string $s): string { return htmlspecialchars($s, ENT_QUOTES | ENT_SUBSTITUTE, 'UTF-8'); }