diff --git a/core/modules/rest/src/Plugin/views/display/RestExport.php b/core/modules/rest/src/Plugin/views/display/RestExport.php
index ae5ac7e..eefdf39 100644
--- a/core/modules/rest/src/Plugin/views/display/RestExport.php
+++ b/core/modules/rest/src/Plugin/views/display/RestExport.php
@@ -15,6 +15,7 @@
 use Drupal\Core\Routing\RouteProviderInterface;
 use Drupal\Core\State\StateInterface;
 use Drupal\views\Plugin\views\display\ResponseDisplayPluginInterface;
+use Drupal\views\Render\ViewsRenderPipelineSafeString;
 use Drupal\views\ViewExecutable;
 use Drupal\views\Plugin\views\display\PathPluginBase;
 use Symfony\Component\DependencyInjection\ContainerInterface;
@@ -311,7 +312,7 @@ public function execute() {
   public function render() {
     $build = array();
     $build['#markup'] = $this->renderer->executeInRenderContext(new RenderContext(), function() {
-      return $this->view->style_plugin->render();
+      return ViewsRenderPipelineSafeString::create($this->view->style_plugin->render());
     });
 
     $this->view->element['#content_type'] = $this->getMimeType();
@@ -323,19 +324,6 @@ public function render() {
       $build['#markup'] = SafeMarkup::checkPlain($build['#markup']);
       $build['#suffix'] = '</pre>';
     }
-    elseif ($this->view->getRequest()->getFormat($this->view->element['#content_type']) !== 'html') {
-      // This display plugin is primarily for returning non-HTML formats.
-      // However, we still invoke the renderer to collect cacheability metadata.
-      // Because the renderer is designed for HTML rendering, it filters
-      // #markup for XSS unless it is already known to be safe, but that filter
-      // only works for HTML. Therefore, we mark the contents as safe to bypass
-      // the filter. So long as we are returning this in a non-HTML response
-      // (checked above), this is safe, because an XSS attack only works when
-      // executed by an HTML agent.
-      // @todo Decide how to support non-HTML in the render API in
-      //   https://www.drupal.org/node/2501313.
-      $build['#markup'] = SafeMarkup::set($build['#markup']);
-    }
 
     parent::applyDisplayCachablityMetadata($build);
 
