Escape-on-input is a bad idea (2012)
lukeplant.me.uk
lukeplant.me.uk
Luckily, it's a Github Pages page (of the old kind, before the transition to .io domains) and is still on the user's GH Pages repo: https://github.com/nikic/nikic.github.com/blob/master/_posts...
For example, orgs with a large number of junior devs, using legacy template engines that don't escape by default (remember this is from 10 years ago) or, you know, when any of your data touches WordPress. The risk of occasional double-escaping might seem manageable compared to the risk of total compromise.
This might be because of really old data and old code that saved it. But changing this decision is very hard, so I imagine many systems that adopted escape-on-input once are stuck with it.
E.g., it will substitute emojis with their short-codes. (And this isn't a valid transformation, and changes some messages, as short codes are not processed inside teletype and code blocks.)
Links also get messed around with, often changing or corrupting the link. Code block begin/ends tend to get (annoyingly) merged with the first/lane lines, which makes editing more difficult.