Str2html was abused a lot. So use a proper name for it: SanitizeHTML And add some tests to show its behavior.