Paul Reinheimer, one of two behind the
funcaday website (providing details on one PHP function each day and special content on the weekends) has
posted a supplement to this weekend's posting
covering escaping.
The disadvantage with the escape for now, not for later approach is simple. If you save a user's post to the database, then that user's post is displayed 2,000 times there will be some serious differences. [...] You will need to balance your security concerns with performance needs.
The
comments on his post back up his suggestions (and include other tips like a recommendation to cache on an even higher level - page blocks).
Paul Reinheimer's Blog: Today's Funcaday (Escaping) - Read More...