I also don't see how PHP goes 'out of its way'. It doesn't do anything, neither do most other web languages, you build or use existing frameworks and libraries to help with such tasks.
I also don't see how PHP goes 'out of its way'. It doesn't do anything, neither do most other web languages, you build or use existing frameworks and libraries to help with such tasks.
<?php echo htmlspecialchars($name); ?>
Here's how to do the same thing in Django:
{{ name }}
That's the thing that bugs me most about PHP: it's not even a productive templating language!
<%= h(@var) %>
In any case, my intent wasn't to compare Django to PHP, it was to point out that PHP's default way of outputting things really does make it inconvenient to write secure code - hence answering the parent post that argued that poor security had nothing to do with the language used.
I realize I'm playing devil's advocate because I love Python, but you shouldn't put blame nor give credit where it isn't due.
function o($name) { echo htmlspecialchars($name); }
o($name);
<?php o($name); ?>
I've used this exact function in my own code, though I call it "h". Really sucks that we have to do this - not to mention that PHP's global namespace for functions means it's better to have long names that are more likely not to clash with third party code.
function o($name) { return(htmlspecialchars($name));}
<?=o($name)?>
which lo, and behold, looks a lot like the rails candidate below.