Message sanitization

WIP! HTML characters are escaped by default when using .toHTML(). For now, if you need something more advanced refer to DOMPurify.

Last updated