3v4l.org

run code in 500+ PHP versions simultaneously
<?php $_GET['search'] = "' onclick='alert(1337)"; ?> <input name=search value='<?= htmlspecialchars($_GET['search']); ?>'>

preferences:
97.45 ms | 1244 KiB | 5 Q