Currently, HTML code in blog posts is not escaped but rendered. This could lead to XSS etc., but also makes the planet harder to read. Please escape the following characters: <, >, &, ", '
Issue is currently visible at Jonathan's Intent to Implement on July 29th:
