how to prevent this in codeigniter. The user may still wish to type this in so xss filtering is not an option

Thanks my issue was that htmlentitites wasn't properly escaping the £ sign.

I thought it was a real ballache to write


in all my views. So I have created my own helper function which wraps it up.

OK solved?

