It's open source now:
https://github.com/ikkez/CryptDown
feel free to add your own ideas and improvements.
I might work on this if I get a little time later today, but in case I don't, here are a few resources for you:
http://stackoverflow.com/questions/3129899/what-are-the-comm...
https://www.owasp.org/index.php/XSS_%28Cross_Site_Scripting%...
The good news is that PHP is so widespread that there are really great tutorials and libraries for sanitizing user input and preventing cross-site scripting.
Good luck!