Defenses: <script> stripped, event handlers stripped, javascript: protocol blocked (case-insensitive check).
<script>
javascript:
Provide a URL to create a link. The server blocks <script>, event handlers, and the javascript: protocol.