Prefer text over html
Prefer text over html: free step-by-step lesson with examples, common mistakes, and interview tips — part of jQuery Tutorial on Toolliyo Academy.
On this page
jQuery Tutorial · Lesson 67 of 100
Prefer text over html
Setup & DOM ✓ → Events Effects AJAX ✓ → Perf & Integrate → Ship & Projects
Perf & Integrate · 3 — Harden · ~10 min · Performance and Security
What is this?
Default to .text() for names, messages, and labels. Reach for .html() only when you intentionally insert trusted structure (e.g., a static wrapper you control).
Why should you care?
Teams that default to html() in QueryVerse accumulate XSS debt quickly.
See it live — copy this example
Examples include the jQuery 3.7 CDN. Paste into an HTML file or use Run Example to preview.
<!DOCTYPE html>
<html lang="en">
<head>
<meta charset="utf-8">
<meta name="viewport" content="width=device-width, initial-scale=1">
<title>QueryVerse</title>
<style>
body { font-family: system-ui, sans-serif; margin: 1.25rem; }
.box { padding: .75rem; border: 1px solid #ccc; border-radius: 8px; margin: .5rem 0; }
.muted { color: #666; }
button { margin-right: .35rem; margin-top: .35rem; }
input, select, textarea { margin: .25rem 0; }
table { border-collapse: collapse; width: 100%; }
th, td { border: 1px solid #ddd; padding: .4rem .55rem; text-align: left; }
.hidden { display: none; }
.row-odd { background: #f7f7f7; }
.active { font-weight: 700; }
.toast { background: #111; color: #fff; padding: .5rem .75rem; border-radius: 6px; }
</style>
</head>
<body>
<input id="who" value="Neha <script>">
<button type="button" id="go">Set greeting</button>
<h2 id="hi"></h2>
<script src="https://code.jquery.com/jquery-3.7.1.min.js"></script>
<script>
$(function () {
$('#go').on('click', function () {
var name = $('#who').val();
$('#hi').empty().append(document.createTextNode('Namaste, ')).append($('<strong/>').text(name));
});
});
</script>
</body>
</html>
Run Example »
Edit the code below and click Run to see the result in Toolliyo’s live editor.
What happened?
- Mixing createTextNode / .text on untrusted parts with fixed tags you create is a solid pattern.
- Avoid string-building full HTML with user bits concatenated.
Practice next
- Set greeting with the default tricky name.
- Inspect the DOM — no script node should run.
- Replace with .html("Namaste, "+name) mentally and reject it.
- Lint for .html( in your repo.
- Train the team with this demo.
Remember
Default to text. Trusted tags + text children. No string HTML with user data.
Greeting header
A Byju’s teacher QueryVerse header personalizes with the learner’s name.
Outcome: strong+text keeps styling without XSS.
Interview prep for this lesson
Practice these questions aloud after reading—each links to a full structured answer.
Sign in to ask a question or upvote helpful answers.
No questions yet — be the first to ask!