Escape exception messages?

If checked, the plug-in escapes the test method's exception messages.

If unchecked, this allows you to use HTML tags to format the exception message e.g. embed links in the text. (Enabled by default)

However, if this field is unchecked, you are vulnerable to a cross-site scripting attack through an HTML exception message.