Verhindern Sie Cross Site Scripting PHP

<div id="profile"><?php echo $user['profile']; ?></div>
Drab Dove