Defend against potential XSS attacks.

fixes #506

Merge request reports

Loading