diff --git a/test/index.php b/test/index.php index 824e08c..0a56b64 100644 --- a/test/index.php +++ b/test/index.php @@ -6,7 +6,7 @@ die('Invalid input'); } -// Convert to string and sanitize +// Convert to string and apply strict XSS protection $input = (string)$_GET['test']; echo htmlspecialchars($input, ENT_QUOTES | ENT_HTML5, 'UTF-8', true);