Sanitize better. "&" is handled before "<" and ">" so it doesn't sanitize the &gt...