Follow up
r65286. If we are going to support <img we should support width and height
attributes, too. Since there's a potential for creating webbugs of 1x1px we might want
to enforce a minimum size for them. But that has always existed when the attacker provides
the image.
The sanitizer isn't treating numeric-like arguments in a special way. That is something
to fix.