The first one doesn't escape single quotes or slash, but I have no idea how to get any HTML parser to treat just those as anything but text. Underscore's implementation will be correct, I'm sure.
<img src="$url">
Exploit: foo.jpg" onload="alert('pwned')