diff --git a/src/Html/Sanitisation/Escaper.php b/src/Html/Sanitisation/Escaper.php index 0ee611f..be975d4 100644 --- a/src/Html/Sanitisation/Escaper.php +++ b/src/Html/Sanitisation/Escaper.php @@ -29,7 +29,7 @@ final class Escaper */ private static function escape($text, $allowQuotes = false) { - return \htmlentities( + return \htmlspecialchars( $text, $allowQuotes ? \ENT_NOQUOTES : \ENT_QUOTES, 'UTF-8'