Driver FixRecommendedSound, Wi-Fi or graphics acting up? Check drivers firstFind missing or outdated drivers fast.Check DriversOctober DealsAmazon USOctober deal check: compare before you payAmazon US: current deals, useful picks and tech finds.Check DealsWindows FixRecommendedWindows errors stealing your time? Find the fix fastScan stability, cleanup and performance issues.Fix Now×
Skip to content
World desk3 min

Trusted Types vs. `setHTML()`: What Actually Stops `innerHTML` XSS

Trusted Types enforcement can block unsafe strings from covered sinks, while setHTML() sanitizes untrusted HTML where supported. Learn the difference and avoid unsafe fallbacks or reparsing.
Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

setHTML() sanitizes untrusted HTML before inserting it, where the browser supports the API. Trusted Types enforcement can block plain strings from reaching covered DOM injection sinks such as innerHTML, but Trusted Types does not sanitize markup by itself: the application’s policy must perform a safe transformation. Neither approach removes the need to handle data according to its context.

Does Trusted Types stop innerHTML XSS?

It can stop a plain string from being assigned to covered injection sinks when the site enforces Trusted Types through Content Security Policy (CSP) and the browser supports that enforcement. OWASP describes require-trusted-types-for 'script' as making relevant DOM XSS sinks reject plain strings in Chromium-based browsers. That is a guardrail against unsafe assignments, not a built-in HTML sanitizer.

As an Amazon Associate I earn from qualifying purchases.

A Trusted Types policy defines how input is transformed into a trusted value. If the policy passes attacker-controlled markup through unchanged, enforcement has not made that markup safe. The application must choose and correctly configure a safe transformation for its intended content.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

See the OWASP Cross Site Scripting Prevention Cheat Sheet for the CSP enforcement model and MDN’s innerHTML reference for its injection-sink behavior.

#1 Best Overall
Yubico - Security Key C NFC - Basic Compatibility - Multi-Factor authentication (MFA) Security Key and passkey, Connect via USB-C or NFC, FIDO Certified
  • POWERFUL SECURITY KEY: The Security Key C NFC is the essential physical passkey for protecting your digital life from phishing attacks. It ensures only you can access your accounts.
  • WORKS WITH 1000+ ACCOUNTS: Compatible with Google, Microsoft, and Apple. A single Security Key C NFC secures 100 of your favorite accounts, including email, password managers, and more.
  • FAST & CONVENIENT LOGIN: Plug in your Security Key C NFC via USB-C and tap it, or tap it against your phone (NFC) to authenticate. No batteries, no internet connection, and no extra fees required.
  • TRUSTED PASSKEY TECHNOLOGY: Uses the latest passkey standards (FIDO2/WebAuthn & FIDO U2F) but does not support One-Time Passwords. For complex needs, check out the YubiKey 5 Series.
  • BUILT TO LAST: Made from tough, waterproof, and crush-resistant materials. Manufactured in Sweden and programmed in the USA with the highest security standards.

Is setHTML() safer than innerHTML?

For inserting untrusted HTML, yes: Element.setHTML() parses and sanitizes the input before insertion. MDN recommends it over innerHTML when the API is available. Its default sanitizer removes XSS-unsafe markup, including examples such as script, frame, iframe, embed, object, use, and event-handler attributes. A custom sanitizer cannot use this safe insertion method to preserve elements or attributes classified as XSS-unsafe.

By contrast, innerHTML parses a string as markup and is an injection sink. A string does not become safe merely because it appears sanitized; safety depends on how it was transformed and the context where it is inserted. For ordinary text, insert text rather than HTML. If an interface needs a restricted subset of markup, use setHTML() where supported or a vetted sanitizer appropriate to the application.

Rank #2
Yubico - YubiKey 5 NFC - Multi-Factor authentication (MFA) Security Key and passkey, Connect via USB-A or NFC, FIDO Certified - Protect Your Online Accounts
  • POWERFUL SECURITY KEY: The YubiKey 5 NFC is the most versatile physical passkey, protecting your digital life from phishing attacks. It ensures only you can access your accounts
  • WORKS WITH 1000+ ACCOUNTS: Compatible with popular accounts like Google, Microsoft, and Apple. A single YubiKey 5 NFC secures 100+ of your favorite accounts, including email, password managers, and more
  • FAST & CONVENIENT LOGIN: Plug in your YubiKey 5 NFC via USB and tap it, or tap it against your phone (NFC), to authenticate. No batteries, no internet connection, and no extra fees required
  • MOST SECURE PASSKEY: Supports FIDO2/WebAuthn, FIDO U2F, Yubico OTP, OATH-TOTP/HOTP, Smart card (PIV), and OpenPGP. That means it’s versatile, working almost anywhere you need it
  • PRIMARY & SPARE KEYS: Just like having a spare house key, we recommend buying two YubiKeys - one for daily use and one as a spare. That way you’ll never get locked out of your accounts

MDN’s references explain the APIs and context-sensitive risks: Element: setHTML() method, HTML Sanitizer API, and Cross-site scripting (XSS).

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

How the approaches differ

Approach Sanitizes untrusted HTML? Controls use of covered sinks? Availability and main caution
innerHTML No. It parses the supplied string as markup. No, not by itself. Do not assign attacker-controlled strings as HTML.
Trusted Types with CSP enforcement Not by itself; the application policy must transform input safely. Yes, it can reject plain strings at covered sinks in supporting browsers when enforced. Enforcement and browser support matter; a policy that does not sanitize is not a security fix.
setHTML() Yes. It sanitizes before insertion using the safe insertion behavior. It provides a sanitizing insertion method rather than general sink enforcement. Limited availability; check support for the browsers your users need.

Can you use setHTML() in all browsers?

No. MDN marks setHTML() as having limited availability and not Baseline because some widely used browsers do not support it. Check the current compatibility information against your actual browser and device targets before relying on it. A fallback must preserve the security property: use a vetted sanitizer for the required HTML subset, or insert plain text if markup is unnecessary. Do not silently fall back to assigning untrusted input to innerHTML.

Rank #3
Yubico - YubiKey 5C NFC - Multi-Factor authentication (MFA) Security Key and passkey, Connect via USB-C or NFC, FIDO Certified - Protect Your Online Accounts
  • POWERFUL SECURITY KEY: The YubiKey 5C NFC is the most versatile physical passkey, protecting your digital life from phishing attacks. It ensures only you can access your accounts
  • WORKS WITH 1000+ ACCOUNTS: Compatible with popular accounts like Google, Microsoft, and Apple. A single YubiKey 5C NFC secures 100+ of your favorite accounts, including email, password managers, and more
  • FAST & CONVENIENT LOGIN: Plug in your YubiKey 5C NFC via USB and tap it, or tap it against your phone (NFC), to authenticate. No batteries, no internet connection, and no extra fees required
  • MOST SECURE PASSKEY: Supports FIDO2/WebAuthn, FIDO U2F, Yubico OTP, OATH-TOTP/HOTP, Smart card (PIV), and OpenPGP. That means it’s versatile, working almost anywhere you need it
  • PRIMARY & SPARE KEYS: Just like having a spare house key, we recommend buying two YubiKeys - one for daily use and one as a spare. That way you’ll never get locked out of your accounts

What can make sanitized markup unsafe again?

Do not serialize sanitized markup and then reparse it through innerHTML. Sanitization is context-sensitive: content safe in one insertion context may not remain safe after serialization and insertion elsewhere, a class of issue associated with mutation XSS. MDN specifically warns that taking a result from setHTML(), reading its innerHTML, and assigning that string to another element’s innerHTML is unsafe.

  • Insert the original untrusted HTML at its destination with setHTML() when supported.
  • If content must be transformed or moved, sanitize it again for the destination context.
  • Prefer keeping content as text or structured data instead of serializing and reparsing HTML.
Independent reader supportYour contribution helps us test, update, and keep practical guides available for everyone.Support on Ko-Fi

Why not use setHTMLUnsafe()?

The Sanitizer API also exposes unsafe insertion methods for cases where an application needs markup that safe methods strip. They are not interchangeable with setHTML(). MDN says setHTMLUnsafe() should almost never be used when setHTML() is available; accepting untrusted input with an unsafe method requires careful sanitizer configuration and policy review. If the content does not require elements or attributes that the safe method removes, use the safe method instead.

Rank #4
Yubico - Security Key NFC - Basic Compatibility - Multi-Factor Authentication (MFA) Key, Connect via USB-A or NFC, FIDO Certified
  • POWERFUL SECURITY KEY: The Security Key NFC is the essential physical passkey for protecting your digital life from phishing attacks. It ensures only you can access your accounts.
  • WORKS WITH 1000+ ACCOUNTS: Compatible with Google, Microsoft, and Apple. A single Security Key NFC secures 100 of your favorite accounts, including email, password managers, and more.
  • FAST & CONVENIENT LOGIN: Plug in your Security Key NFC via USB-A and tap it, or tap it against your phone (NFC) to authenticate. No batteries, no internet connection, and no extra fees required.
  • TRUSTED PASSKEY TECHNOLOGY: Uses the latest passkey standards (FIDO2/WebAuthn & FIDO U2F) but does not support One-Time Passwords. For complex needs, check out the YubiKey 5 Series.
  • BUILT TO LAST: Made from tough, waterproof, and crush-resistant materials. Manufactured in Sweden and programmed in the USA with the highest security standards.

Product prices and availability are accurate as of the date/time indicated and are subject to change. Any price and availability information displayed on Amazon at the time of purchase will apply.

What’s actually slowing this PC down?

Pick the symptom - the matching free tool is one click away.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

Leave a Reply

Your email address will not be published. Required fields are marked *

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

More from the Wire

  1. World desk4 min
    How to Spot an AI Voice Scam Before Sending MoneyDon’t rely on how a caller sounds. Pause, call back through a known number, and verify the emergency with another trusted person before sending money.
  2. Mountain View desk4 min
    Google’s SynthID Detector: How to Check AI-Generated Images, Video and AudioGoogle’s SynthID Detector looks for an embedded watermark in supported images, video and audio. Here is what its results do—and do not—show.
  3. Redmond desk20 min
    How to create a link to File or Folder in Windows 11Windows 11 gives you several ways to point to a file or folder without moving or duplicating it. You can create a desktop shortcut,…
Recommended PC Tool
Recommended PC Tool
Outdated Drivers Are Slowing You DownFree scan - exact matches
Windows Errors? Fix Them Before They SpreadFree repair scan

Two free Windows tools

One Free Minute Could Fix That PC

Before you go - each of these free tools takes about a minute and tackles what quietly slows a Windows PC down.

Special offer. View Outbyte info, uninstall instructions, EULA, and Privacy Policy.