A template language that requires manually calling htmlspecialchars on every single value (or else you have an XSS vulnerability) seems like an enormous footgun. In Django this problem was corrected before the 1.0 release.
[0]: https://github.com/jbboehr/php-handlebars [1]: https://github.com/jbboehr/php-mustache [2]: https://www.smarty.net/ [3]: https://twig.symfony.com/
Escaping is typically handled in the framework.
You need to use a similar PHP framework, with one such framework you don't need to escape html or sql stuff.