Nice job though. The code is clean.
Thus CL-WHO is vulnerable to XSS attack by default.
Just bringing up some history. I don't know the age profile of the developers or readers anymore.
Just trying to look smart.
Thus CL-WHO is vulnerable to XSS attack by default.