/** * Return a sanitized string that is going to be rendered in the browser to prevent XSS attacks. * Note that sanitized tags will be removed, such as "