Use autoescape to avoid html and js injection into document

Andrey Veltischev requested to merge andrey/autoescape into master

Mentions #44 (closed)

Merge request reports