Fixed unsecure code.
When dumping the object, use '%s' and pass the string, don't use it as a format element.