What potential pitfalls should be considered when writing HTML content to a PHP file?

One potential pitfall when writing HTML content to a PHP file is the risk of introducing cross-site scripting (XSS) vulnerabilities if the HTML content includes user input that is not properly sanitized. To mitigate this risk, always sanitize any user input before outputting it to the browser. This can be done using functions like htmlspecialchars() in PHP to escape special characters.

<?php
// Sanitize user input before outputting to the browser
$user_input = "<script>alert('XSS attack!');</script>";
$sanitized_input = htmlspecialchars($user_input, ENT_QUOTES, 'UTF-8');
echo $sanitized_input;
?>