← Blocking `<script>` Won't Stop innerHTML XSS. `setHTML()` Will.Quiz
setHTML() and the HTML Sanitizer API
Test how well the innerHTML-to-setHTML switch landed: what setHTML() always strips, how elements, replaceWithChildrenElements and removeElements differ, why the 2022 config keys fail silently, and why setHTMLUnsafe() is named that way.
questions9
pass mark70%
resultsat the end
No account needed. Answer all 9 questions, then see your score with every answer explained and a reference to the spec or MDN — pass and you can claim a certificate.