Ryan Grove@yaypieIf I had a dollar for every HTML escaper that only escapes &, <, >, and ", I'd have $0. Because my account would've been pwned via XSS.8:49 PM · Apr 19, 2011129 Retweets35 Likes
Ryan Grove@yaypie·Aug 14, 2016[ and ] don’t have special meaning in HTML. They do in JS. Depends on the context.