Skip to content

What it blocks

Script injection

Someone tries to plant a script in one of your pages.

What it is

Script code sent as if it were ordinary text, hoping your site shows it back to other visitors, whose browsers would then run it.

  • <script> in a comment
  • An image tag with an onerror handler
  • A link that starts javascript:

Why it matters

A planted script acts as the visitor: it can take over their session, change what the page says, or send them somewhere else.

If a real visitor is ever stopped

Editors that save HTML, such as a page builder or a blog's writing screen, send real markup that looks like this. Mark the request as real and that one field is let through.