 deprecated in 0.6 are removed in 1.0, including the entire rails suite.)</p>
 <p><strong>Security update in version 1.2:</strong> addresses a potential XSS
-attack; all users are recommended to upgrade. More in
+attack. Users who use ' around HTML attributes (rather than ") are recommended
+to upgrade.  More in
 <a href="{{ pathto('whats_new') }}">What's New</a>.</p>
 <p>WebHelpers includes the widely-used HTML tag builder with smart escaping and