Dangerous JavaScript Functions
Dangerous JavaScript functions like eval(), document.write(), and innerHTML can introduce DOM-based XSS vulnerabilities when used with untrusted input.
Results in 1–3 minutes · Free · No signup required
Want the result for your own site? Free Website Vulnerability Scanner — paste your domain, get the report.
Why It Matters
DOM-based XSS through dangerous functions is harder to detect than reflected XSS and bypasses server-side sanitization. Attackers can execute arbitrary code in the user's browser context.
How We Check
We scan inline scripts and event handler attributes for calls to eval(), document.write(), innerHTML assignments, new Function(), and string-based setTimeout/setInterval.
How to Fix
Replace eval() with JSON.parse(). Use textContent instead of innerHTML. Use DOM APIs (createElement, appendChild) instead of document.write(). Implement Trusted Types via CSP.
Frequently Asked Questions
What is Dangerous JavaScript Functions?
Dangerous JavaScript functions like eval(), document.write(), and innerHTML can introduce DOM-based XSS vulnerabilities when used with untrusted input.
Why does Dangerous JavaScript Functions matter for website security?
DOM-based XSS through dangerous functions is harder to detect than reflected XSS and bypasses server-side sanitization. Attackers can execute arbitrary code in the user's browser context.
How do I fix Dangerous JavaScript Functions issues?
Replace eval() with JSON.parse(). Use textContent instead of innerHTML. Use DOM APIs (createElement, appendChild) instead of document.write(). Implement Trusted Types via CSP.
Related Security Checks
Related Tool
Website Vulnerability Scanner
Run all 7 related checks with our free website vulnerability scanner
Check Your Website Now
Run a free security scan to check for Dangerous JavaScript Functions issues and 62+ other security vulnerabilities.
Scan Your Website Free