text format - show breaks

simple_format

Will simple_format protect from embedded nasty html?

No, you need h() in addition to it: simple_format(h(text))