SECURITY: Always expand xml entities when checking SVG's