Text, not HTML
value always writes plain text, any markup in the data shows up escaped, as literal
characters, not rendered. That's deliberate, not a limitation, if the data ever comes from anywhere
outside your own code, rendering it as HTML unescaped is how you get an XSS hole. If you genuinely need
to render HTML from a data-key, that's a separate, explicit attribute,
html, with its own trust rules, not something value
does by accident.
To output text without wrapping it in an element at all, see
text content.