javascript - Is XSS possible with handsontable and no PHP? -


my webpage has php extension, there no php code in it. there handsontable , user insert numbers , cool js effects on same page. when writing code comments, used strip_tags protection, working php. , curious if there danger leaving handsontable is?

well question is, can visitor alter content in way visitor load browser not intended developers. if it's purely client side , if not accept user inputs, think pretty safe. if have unused php scripts, remove them.


Comments

Popular posts from this blog

c# - DetailsView in ASP.Net - How to add another column on the side/add a control in each row? -

javascript - firefox memory leak -

Trying to import CSV file to a SQL Server database using asp.net and c# - can't find what I'm missing -