We should be careful about what we allow into the database, and especially careful about what we allow to be rendered. Things to look at: Django's html cleaning, beautifulsoup