<?php // escape code $bad = array('<?', '<%', '<script', '<applet', '<object', '<embed', '<iframe', '</script', '</applet', '</object', '</embed', '</iframe'); $good = array('<?', '<%', '<script', '<applet', '<object', '<embed', '<iframe', '</script', '</applet', '</object', '</object', '</embed', '</iframe'); $str = str_replace($bad, $good, $str); // xss filter $str = htmLawed($str, array('safe' => 1, 'balanced' => 0));