Escape an attribute NAME: only allow safe attribute-name characters, drop the rest. Prevents attribute injection when a head entry is built from untrusted keys.
The raw attribute name.
The sanitized attribute name (may be empty).
Escape an attribute NAME: only allow safe attribute-name characters, drop the rest. Prevents attribute injection when a head entry is built from untrusted keys.