setHTML() sanitizes untrusted HTML before inserting it, where the browser supports the API. Trusted Types enforcement can block plain strings from reaching covered DOM injection sinks such as innerHTML, but Trusted Types does not sanitize markup by itself: the application’s policy must perform a safe transformation. Neither approach removes the need to handle data according to its context.
Does Trusted Types stop innerHTML XSS?
It can stop a plain string from being assigned to covered injection sinks when the site enforces Trusted Types through Content Security Policy (CSP) and the browser supports that enforcement. OWASP describes require-trusted-types-for 'script' as making relevant DOM XSS sinks reject plain strings in Chromium-based browsers. That is a guardrail against unsafe assignments, not a built-in HTML sanitizer.
As an Amazon Associate I earn from qualifying purchases.
A Trusted Types policy defines how input is transformed into a trusted value. If the policy passes attacker-controlled markup through unchanged, enforcement has not made that markup safe. The application must choose and correctly configure a safe transformation for its intended content.
PC Slower Than It Used to Be?
A free scan shows the junk files, broken settings and background clutter dragging Windows down - then fixes them in one click.Free scan · Windows 10 & 11Outdated Drivers Are Slowing You Down
One free scan finds every outdated or missing driver and matches the right update for your exact hardware.Free scan · exact hardware matchSee the OWASP Cross Site Scripting Prevention Cheat Sheet for the CSP enforcement model and MDN’s innerHTML reference for its injection-sink behavior.
#1 Best Overall
- POWERFUL SECURITY KEY: The Security Key C NFC is the essential physical passkey for protecting your digital life from phishing attacks. It ensures only you can access your accounts.
- WORKS WITH 1000+ ACCOUNTS: Compatible with Google, Microsoft, and Apple. A single Security Key C NFC secures 100 of your favorite accounts, including email, password managers, and more.
- FAST & CONVENIENT LOGIN: Plug in your Security Key C NFC via USB-C and tap it, or tap it against your phone (NFC) to authenticate. No batteries, no internet connection, and no extra fees required.
- TRUSTED PASSKEY TECHNOLOGY: Uses the latest passkey standards (FIDO2/WebAuthn & FIDO U2F) but does not support One-Time Passwords. For complex needs, check out the YubiKey 5 Series.
- BUILT TO LAST: Made from tough, waterproof, and crush-resistant materials. Manufactured in Sweden and programmed in the USA with the highest security standards.
Is setHTML() safer than innerHTML?
For inserting untrusted HTML, yes: Element.setHTML() parses and sanitizes the input before insertion. MDN recommends it over innerHTML when the API is available. Its default sanitizer removes XSS-unsafe markup, including examples such as script, frame, iframe, embed, object, use, and event-handler attributes. A custom sanitizer cannot use this safe insertion method to preserve elements or attributes classified as XSS-unsafe.
By contrast, innerHTML parses a string as markup and is an injection sink. A string does not become safe merely because it appears sanitized; safety depends on how it was transformed and the context where it is inserted. For ordinary text, insert text rather than HTML. If an interface needs a restricted subset of markup, use setHTML() where supported or a vetted sanitizer appropriate to the application.
Rank #2
- POWERFUL SECURITY KEY: The YubiKey 5 NFC is the most versatile physical passkey, protecting your digital life from phishing attacks. It ensures only you can access your accounts
- WORKS WITH 1000+ ACCOUNTS: Compatible with popular accounts like Google, Microsoft, and Apple. A single YubiKey 5 NFC secures 100+ of your favorite accounts, including email, password managers, and more
- FAST & CONVENIENT LOGIN: Plug in your YubiKey 5 NFC via USB and tap it, or tap it against your phone (NFC), to authenticate. No batteries, no internet connection, and no extra fees required
- MOST SECURE PASSKEY: Supports FIDO2/WebAuthn, FIDO U2F, Yubico OTP, OATH-TOTP/HOTP, Smart card (PIV), and OpenPGP. That means it’s versatile, working almost anywhere you need it
- PRIMARY & SPARE KEYS: Just like having a spare house key, we recommend buying two YubiKeys - one for daily use and one as a spare. That way you’ll never get locked out of your accounts
MDN’s references explain the APIs and context-sensitive risks: Element: setHTML() method, HTML Sanitizer API, and Cross-site scripting (XSS).
How the approaches differ
| Approach | Sanitizes untrusted HTML? | Controls use of covered sinks? | Availability and main caution |
|---|---|---|---|
innerHTML |
No. It parses the supplied string as markup. | No, not by itself. | Do not assign attacker-controlled strings as HTML. |
| Trusted Types with CSP enforcement | Not by itself; the application policy must transform input safely. | Yes, it can reject plain strings at covered sinks in supporting browsers when enforced. | Enforcement and browser support matter; a policy that does not sanitize is not a security fix. |
setHTML() |
Yes. It sanitizes before insertion using the safe insertion behavior. | It provides a sanitizing insertion method rather than general sink enforcement. | Limited availability; check support for the browsers your users need. |
Can you use setHTML() in all browsers?
No. MDN marks setHTML() as having limited availability and not Baseline because some widely used browsers do not support it. Check the current compatibility information against your actual browser and device targets before relying on it. A fallback must preserve the security property: use a vetted sanitizer for the required HTML subset, or insert plain text if markup is unnecessary. Do not silently fall back to assigning untrusted input to innerHTML.
Rank #3
- POWERFUL SECURITY KEY: The YubiKey 5C NFC is the most versatile physical passkey, protecting your digital life from phishing attacks. It ensures only you can access your accounts
- WORKS WITH 1000+ ACCOUNTS: Compatible with popular accounts like Google, Microsoft, and Apple. A single YubiKey 5C NFC secures 100+ of your favorite accounts, including email, password managers, and more
- FAST & CONVENIENT LOGIN: Plug in your YubiKey 5C NFC via USB and tap it, or tap it against your phone (NFC), to authenticate. No batteries, no internet connection, and no extra fees required
- MOST SECURE PASSKEY: Supports FIDO2/WebAuthn, FIDO U2F, Yubico OTP, OATH-TOTP/HOTP, Smart card (PIV), and OpenPGP. That means it’s versatile, working almost anywhere you need it
- PRIMARY & SPARE KEYS: Just like having a spare house key, we recommend buying two YubiKeys - one for daily use and one as a spare. That way you’ll never get locked out of your accounts
What can make sanitized markup unsafe again?
Do not serialize sanitized markup and then reparse it through innerHTML. Sanitization is context-sensitive: content safe in one insertion context may not remain safe after serialization and insertion elsewhere, a class of issue associated with mutation XSS. MDN specifically warns that taking a result from setHTML(), reading its innerHTML, and assigning that string to another element’s innerHTML is unsafe.
- Insert the original untrusted HTML at its destination with
setHTML()when supported. - If content must be transformed or moved, sanitize it again for the destination context.
- Prefer keeping content as text or structured data instead of serializing and reparsing HTML.
Why not use setHTMLUnsafe()?
The Sanitizer API also exposes unsafe insertion methods for cases where an application needs markup that safe methods strip. They are not interchangeable with setHTML(). MDN says setHTMLUnsafe() should almost never be used when setHTML() is available; accepting untrusted input with an unsafe method requires careful sanitizer configuration and policy review. If the content does not require elements or attributes that the safe method removes, use the safe method instead.
Quick Recap
Rank #4
- POWERFUL SECURITY KEY: The Security Key NFC is the essential physical passkey for protecting your digital life from phishing attacks. It ensures only you can access your accounts.
- WORKS WITH 1000+ ACCOUNTS: Compatible with Google, Microsoft, and Apple. A single Security Key NFC secures 100 of your favorite accounts, including email, password managers, and more.
- FAST & CONVENIENT LOGIN: Plug in your Security Key NFC via USB-A and tap it, or tap it against your phone (NFC) to authenticate. No batteries, no internet connection, and no extra fees required.
- TRUSTED PASSKEY TECHNOLOGY: Uses the latest passkey standards (FIDO2/WebAuthn & FIDO U2F) but does not support One-Time Passwords. For complex needs, check out the YubiKey 5 Series.
- BUILT TO LAST: Made from tough, waterproof, and crush-resistant materials. Manufactured in Sweden and programmed in the USA with the highest security standards.
Product prices and availability are accurate as of the date/time indicated and are subject to change. Any price and availability information displayed on Amazon at the time of purchase will apply.
What’s actually slowing this PC down?
Pick the symptom - the matching free tool is one click away.




