Escaping is about context: HTML entities, JSON strings, and where XSS comes from
There is no such thing as 'escaped text' — only text escaped for a specific place. Here's what each context needs, the bugs that come from mixing them, and why you escape on output.