HeadertestHT
HomeFeaturesGuidesBlogResultsAPISign Up
HomeFeaturesGuidesBlogResultsAPISign Up
  1. Home
  2. /
  3. Blog
  4. /
  5. DOMPurify

Articles tagged DOMPurify

July 18, 2026HeaderTest Team

Stopping DOM-Based XSS with Trusted Types and CSP

A strict CSP stops injected script tags, but DOM-based XSS sneaks attacker input into sinks like innerHTML and eval that your own trusted code already runs. Trusted Types, shipped through CSP, makes those sinks refuse raw strings and closes the gap.

Read more

CSP Scanner

Advanced security scanning and analysis tools for modern web applications.

Products

  • CSP Scanner
  • OSN — Internet Exposure SearchSister project: open ports, CVEs, DNS

Resources

  • Features
  • Guides
  • Blog
  • API Docs
  • Analytics

Company

  • About
  • Results
  • Early Access
  • Security Policy
© 2024-2026 Headertest. All rights reserved.
Security PolicyKybersuomi