To sanitize user content, use an HTML parser It is especially important, if you allow any HTML at all in user-submitted content, to sanitize that content by actually parsing the HTML and filtering it for any tags or attributes you wish to exclude.

A new string in which certain characters have been escaped. Description. The escape function is a property of the global object. The hexadecimal form for characters, whose code unit value is 0xFF or less, is a two-digit escape sequence: %xx.