In more detail
&, < and > must be written as &, < and > in text. Escaping user input this way is the main defence against cross-site scripting. See the HTML Entities Cheat Sheet.
An HTML entity is a code such as `&` or `©` that stands for a character that is reserved in HTML or hard to type.
Last reviewed:
&, < and > must be written as &, < and > in text. Escaping user input this way is the main defence against cross-site scripting. See the HTML Entities Cheat Sheet.