Following best practices helps avoid security issues.

Handle user input with care

Input, whether it comes from visitors or servers, should be handled with care.

Why does Drupal filter on output?

Some web applications process/filter the user input in the name of security before storing it in the database. Historically, Drupal has

