">: company_name and
description are merchant-supplied, and strip_tags returns an html_safe
buffer that will NOT escape — so a name or description containing a
double quote would break out of the attribute. The tag helper escapes
attribute values regardless of html_safe status. %>