Prevent XSS attacks using htmlspecialchars and htmlentities. Full video tutorial here:
function _e($string) {
echo htmlspecialchars($string, ENT_QUOTES, 'UTF-8');
//echo htmlentities($string, ENT_QUOTES, 'UTF-8');
<!DOCTYPE html>
<meta charset="UTF-8">
<title>Escape Output</title>
<?php _e('This is a problem: <script>alert("Yikes");</script>'); ?>
