Skip to content
This repository was archived by the owner on Mar 19, 2026. It is now read-only.
This repository was archived by the owner on Mar 19, 2026. It is now read-only.

Question: just how safe is safeHtml()? #177

@bobular

Description

@bobular

Just curious what's going on here:

/** Create a React Element using preformatted HTML */

There doesn't seem to be any checking for <script> tags (which naively I assume would be a bad thing). Is it really "safe" ?

Metadata

Metadata

Assignees

No one assigned

    Labels

    questionFurther information is requested

    Type

    No type
    No fields configured for issues without a type.

    Projects

    No projects

    Milestone

    No milestone

    Relationships

    None yet

    Development

    No branches or pull requests

    Issue actions