1 comment

[ 3.0 ms ] story [ 14.3 ms ] thread
You should consider putting the JS in an iframe using srcdoc so that you can sandbox it from XSS attacks.