Include funtion e. This will escape malicious js stuff.
function e($value)
{
return htmlspecialchars($value, ENT_QUOTES, 'UTF-8', false);
}
<input type="text" value="<?=e($_GET['q']??'')?>">
function e($value)
{
return htmlspecialchars($value, ENT_QUOTES, 'UTF-8', false);
}
<input type="text" value="<?=e($_GET['q']??'')?>">