Javascript Checklists

Platforms

Secure Coding Practices

Avoid stringify()

The command JSON.stringify() is not safe and can lead to XSS attacks.

Instead, use serialize-javascript:

$npm install --save-dev serialize-javascript

Resources & Advisories

https://medium.com/node-security