htmLawed is a new GPL'ed PHP script to filter text to make it secure, and standard-compliant. The easily-customized script can also remove admin-specified HTML attributes and elements, control spam, and so on. You can read the documentation and test the script at the htmLawed website.