escape incoming strings (cannot contain HTML any more)