<?php
//inseguro
$input = 'alert("ola")';
echo $input;
//seguro
$input_filter = filter_var($input, FILTER_SANITIZE_STRING
); echo "<br>". $input_filter;
PD9waHAKCi8vaW5zZWd1cm8KJGlucHV0ID0gJ2FsZXJ0KCJvbGEiKSc7CmVjaG8gJGlucHV0OwoKLy9zZWd1cm8KJGlucHV0X2ZpbHRlciA9IGZpbHRlcl92YXIoJGlucHV0LCBGSUxURVJfU0FOSVRJWkVfU1RSSU5HKTsKZWNobyAiPGJyPiIuICRpbnB1dF9maWx0ZXI7