Comment Output encoding (Score 3, Informative) 107
It's not fragile. This was a non-problem over 25-years ago when almost everyone coded CGI scripts in Perl using CGI.pm, and it has not changed with new techniques. People just need an hour security education before starting to write web applications.