Harden xss_clean() more

This time eliminate false positives for the
'naughty html' logic.
2 files changed