Hi Mike,
Doing "cleanup" for other fields shouldn't be needed, because the values of those fields are not rendered as HTML. That is, it is perfectly safe to allow a user to enter HTML+JavaScript in a text field when that value is then rendered by that text field: it will be just be shown as-is. Or do you maybe have some other use case in mind?
Alex
--
Follow Orbeon on Twitter: @orbeon
Follow me on Twitter: @avernet