Make compose.php XSS-safe by encoding all untrusted data. I'm using the new