Escape user-controlled text at the output context: ~~~php $safeName = htmlentities( $userName, ENT_QUOTES | ENT_HTML5, 'UTF-8', ); echo $safeName; ~~~ Prefer Twig or Blade auto-escaping, use context-appropriate encoding, and never trust raw request values.
Installs into .claude/skills of the current project.
Are you the author of Php Security?
Add the live security badge to your README. It updates with every re-scan.
[](https://www.skillsdirectory.com/skills/hoangnguyen0403-php-security-f8bdfffc)
Escape user-controlled text at the output context:
~~~php
$safeName = htmlentities(
$userName,
ENT_QUOTES | ENT_HTML5,
'UTF-8',
);
echo $safeName;
~~~
Prefer Twig or Blade auto-escaping, use context-appropriate encoding, and never trust raw request values.