prevent script tag injection … how google do it … stackoverflow.com/questions/2669…