I've noticed that HTML tags are removed instead of being encoded. For example, the Signer opted out with a message:
Can't sign as there is a