xml-html-qq is currently using textSetting from heterocephalus, which makes the xml, xmlUnsafe, and html function NOT escape template variables.
It would be nice to provide different versions of the xml, xmlUnsafe, and html functions (using htmlSetting) which DO escape template variables.