In the description of the InjectHML.HTML parameter the description suggest the use EncodeHTML(). When applied the html will not render. Using the HtmlRenderer RemoveAllJavaScriptis perhaps a better way to protect the content.Please adjust the parameter description.