You can't put user data in any "onwhatever" attributes, there is no way to sanitize it there. Use data attributes instead.