Instead we html_escape the externalized string, consistent with the HTML section in this doc
Attach a file by drag & drop or click to upload