It's much better to either escape HTML so it's displayed in the browser or to detect if the content has HTML and display an error such as "HTML not allowed" instead of removing the HTML. By removing or replacing content, you can end up with a much bigger problem en.wikipedia.org/wiki/Scunthorpe_problem