Javascript Checklists
Platforms
Secure Coding Practices
Avoid stringify()
The command JSON.stringify()
is not safe and can lead to XSS attacks.
Instead, use serialize-javascript
:
$npm install --save-dev serialize-javascript
The command JSON.stringify()
is not safe and can lead to XSS attacks.
Instead, use serialize-javascript
:
$npm install --save-dev serialize-javascript