For those who think these are the only characters that need to be escaped in HTML.

If I had a dollar for every HTML escaper that only escapes &, <, >, and ", I'd have $0. Because my account would've been pwned via XSS.

