For Model Objects containing free form user input, it is highly recommended that you use , not <tt>String</tt></span>. Free form user inputis open to malicious use, such as Cross Site Scripting attacks..