Coding tips
PHP htmlspecialchars to Prevent XSS (Tested Examples)
Prevent XSS in PHP by escaping output with htmlspecialchars(ENT_QUOTES, UTF-8): reflected XSS demo, sticky forms, attributes, and the cases it does not cover.