  1. In my own project I've begun to subclass certain Ext components into a new namespace Ext.sec. For example I have subclassed Ext.tree.TreeNode to override the unsafe text parameter.

  2. I don't think your doing justice to developers making this mistake appealing to bad planning. I think this is something you would reasonably expect a framework to take care of for you.

  3. I'd just like to weigh in on this (old) discussion. Ext JS really should escape all input.

    The problem

