This is because it replaces with HTML equivalents and causes problems Variable is only updateable if you're logged in, so has reasonable security Will create a better solution in the future