Echoing Data and HTML Escaping

{{ $x }} prints through htmlspecialchars; {!! $x !!} prints raw, which is safe only for HTML you produced. Here an attacker wrote the review and the shop's editors wrote the blurb:

resources/views/reviews/show.blade.phpPHP
{{-- A Blade comment never reaches the browser --}}
<p>{{ $review->author }} wrote: {{ $review->body }}</p>
<p>{!! $blurbHtml !!}</p>
<p>{{ 'Tom &amp; Jerry' }}</p>
<p>Vue sees: @{{ cartCount }}</p>
Output
<p>Mallory wrote: &lt;script&gt;steal(document.cookie)&lt;/script&gt;</p>
<p>A <em>classic</em> on software craft.</p>
<p>Tom &amp;amp; Jerry</p>
<p>Vue sees: {{ cartCount }}</p>

The script is defused. Blade double-encodes existing entities unless you call Blade::withoutDoubleEncoding(). @{{ }} (or a @verbatim block) leaves braces for Vue 5,482 or Alpine, and {{ Js::from($data) }} writes JSON that is safe inside <script> (Contextual Escaping).

Where compiled views live. Each template compiles to PHP in storage/framework/views, named by an xxh128 hash of its path, and recompiles when the template is newer than that file:

storage/framework/views/3a80907fe690f08b63a2a3115c16ed24.phpPHP
<p><?php echo e($review->author); ?> wrote: <?php echo e($review->body); ?></p>
<p><?php echo $blurbHtml; ?></p>
<p><?php echo e('Tom &amp; Jerry'); ?></p>
<p>Vue sees: {{ cartCount }}</p>
<?php /**PATH /var/www/bookshop/resources/views/reviews/show.blade.php ENDPATH**/ ?>

{{ }} became e(), {!! !!} a bare echo, and the comment a blank line; the PATH trailer lets error pages name the template. Deployments run php artisan view:cache (Production Deployment), which here reported "Blade templates cached successfully" and wrote 76 files; view:clear empties the folder.