escape only entities which are dangerous to html