Free tools Windows power users keep installed

One-click scans. No signup required.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

iTechGuides is reader-supported. When you buy through links on our site, we may earn an affiliate commission. As an Amazon Associate I earn from qualifying purchases. Learn more

No: Trusted Types blocking does not, by itself, stop every innerHTML XSS risk. It can make supported browsers reject plain strings at protected DOM injection sinks, but the policy must still transform input safely. Where available, Element.setHTML() is designed to sanitize untrusted HTML before insertion. Its browser support is limited, so check compatibility before relying on it.

Does Trusted Types stop innerHTML XSS?

Not on its own. Assigning attacker-controlled markup to innerHTML is risky because the browser parses the string as HTML. Trusted Types adds enforcement: with an applicable Content Security Policy, protected sinks can reject plain strings unless they arrive through an approved Trusted Types policy. OWASP describes the require-trusted-types-for 'script' directive as enforcing this protection in Chromium-based browsers (OWASP Cross Site Scripting Prevention Cheat Sheet).

A policy is not automatically a sanitizer. If the application’s policy simply blesses an unsafe string, Trusted Types enforcement does not make that markup safe. The policy must apply a vetted transformation, and the application must use it consistently. MDN also identifies innerHTML as an injection sink and discusses its TrustedHTML handling (MDN: Element: innerHTML property).

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

Is setHTML() safer than innerHTML?

For inserting untrusted HTML in a browser that supports it, Element.setHTML() is designed to parse and sanitize the input before insertion. Its default sanitizer removes XSS-unsafe elements and attributes. MDN examples include script, frame, iframe, embed, object, use, and event-handler attributes. Even a custom sanitizer cannot use this safe method to preserve items classified as XSS-unsafe. MDN recommends setHTML() for untrusted strings when it is available (MDN: Element: setHTML() method).

Choose the insertion method according to the content:

  • Plain text: insert it as text rather than parsing it as HTML.
  • Untrusted HTML: use setHTML() where supported, or a vetted sanitizer and an appropriately protected insertion path.
  • Trusted Types enforcement: use a policy that performs a safe transformation; enforcement controls what reaches protected sinks, not what the policy considers safe.

How do the approaches differ?

Approach Sanitizes untrusted HTML? Controls use of injection sinks? Availability or key caution
innerHTML No. It parses the assigned string as markup. No, not by itself. Do not treat a string that merely looks sanitized as safe.
Trusted Types with CSP enforcement Only if the application’s policy performs a safe transformation. Yes, for covered sinks in supported browsers when enforcement is configured. Requires a sound policy and applicable browser support; it is not a sanitizer by itself.
Element.setHTML() Yes. It parses and sanitizes before insertion. It provides a sanitizing insertion method rather than general sink enforcement. Limited availability; verify support for the browsers your users rely on.

These measures address different parts of the problem. Sanitization removes unsafe markup; Trusted Types enforcement helps prevent strings from reaching covered sinks without passing through an application policy. Neither eliminates the need to consider the destination context and the application’s handling of the content. MDN explains the Sanitizer API’s safe and unsafe methods (MDN: HTML Sanitizer API), while its XSS guidance explains why sanitization depends on context (MDN: Cross-site scripting (XSS)).

Rank #2
Sale
HTML and CSS: Design and Build Websites
  • HTML CSS Design and Build Web Sites
  • Comes with secure packaging
  • It can be a gift option

Can you use setHTML() in every browser?

No. MDN marks setHTML() as having limited availability and not Baseline because it is missing in some widely used browsers. The available compatibility information does not establish a complete browser-by-browser matrix here, so check the current compatibility data for your target browsers rather than assuming universal support. If a target browser lacks the method, use a vetted sanitizer and a safe insertion approach appropriate to that environment.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

Why is serializing sanitized markup risky?

Sanitization is context-sensitive. A fragment made safe for one destination does not necessarily remain safe if the application serializes it with innerHTML and reparses that string elsewhere. MDN warns that taking the result of div.setHTML(untrusted) through serialization and assigning it to another element’s innerHTML can reintroduce risk, including mutation XSS.

Avoid the serialize-and-reparse step. If the content must be inserted at another destination, sanitize it for that destination with setHTML() where available, or use an appropriate vetted sanitizer there.

Independent reader supportYour contribution helps us test, update, and keep practical guides available for everyone.Support on Ko-Fi

When should you avoid setHTMLUnsafe()?

setHTMLUnsafe() is not interchangeable with the safe sanitizing method. It exists for cases where applications need markup that safe methods strip, but it requires careful sanitizer configuration and policy review when input is untrusted. MDN says it should almost never be used when setHTML() is available, unless there is a specific need to allow unsafe elements and attributes.

Rank #4
Sale
Web Design with HTML, CSS, JavaScript and jQuery Set
  • Brand: Wiley
  • Set of 2 Volumes
  • A handy two-book set that uniquely combines related technologies Highly visual format and accessible language makes these books highly effective learning tools Perfect for beginning web designers and front-end developers

Product prices and availability are accurate as of the date/time indicated and are subject to change. Any price and availability information displayed on Amazon at the time of purchase will apply.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.