2

These image tags, aren't they already added by the extensions from the textsanitiser as defined in /class/textsanitizer/image/image.php?
I believe there is somewhere also a configuration option or preference to allow images in DHTML or not.
But you are right, you can
do a lot with this kind of replacements.
PS: Check your code. The code window may be unable to display some sequences properly (as eg \.). Use the quote window instead.