Is it common practice to restrict the use of HTML in newsletters sent through PHP, and if so, what are the reasons behind it?

It is common practice to restrict the use of HTML in newsletters sent through PHP to prevent potential security vulnerabilities such as cross-site scripting attacks. By sanitizing and filtering the HTML content before sending it out, you can ensure that only safe and valid HTML is included in the newsletter.

<?php
// Sanitize and filter HTML content before sending it in a newsletter
$newsletter_content = "<p>This is some <script>alert('malicious code')</script> HTML content</p>";
$filtered_content = strip_tags($newsletter_content, '<p><a><strong><em><ul><ol><li>'); // Allow only specified HTML tags
$filtered_content = htmlspecialchars($filtered_content); // Encode special characters

// Send the newsletter with the filtered HTML content
// mail($recipient, $subject, $filtered_content, $headers);
?>