What are the common pitfalls to avoid when including text in a PHP file for display in an HTML page?

One common pitfall to avoid when including text in a PHP file for display in an HTML page is not properly escaping the text to prevent HTML injection attacks. To solve this issue, you can use the `htmlspecialchars()` function in PHP to escape the text before outputting it to the HTML page.

<?php
$text = "<script>alert('Hello, world!');</script>";
echo htmlspecialchars($text);
?>