Googlebot got 0 characters inside a client-rendered blog's root div, its developer found after Google crawled 270 of the posts and indexed none. A bot-only branch in an existing Netlify edge function now hands crawlers the rendered article and JSON-LD.
Reality
- Evidence55
- Adoption
- Insufficient
- Hype gap+10
- Incentives
- Insufficient
- Confidence50
OopsSec Store, a deliberately vulnerable Next.js app, lets an admin-uploaded SVG run JavaScript in every visitor's browser. It works because the server trusts the client-set Content-Type and the product page renders SVGs through an <object> tag.
Reality
- Evidence62
- Adoption
- Insufficient
- Hype gap+8
- Incentives40
- Confidence72
MDN now lists the Trusted Types API as Baseline 2026, newly available. The JavaScript half only lets you sanitize; require-trusted-types-for is the part that makes an unsanitized assignment throw, and the sanitizer stays yours to write.
Publishers:developer.mozilla.org
Reality
- Evidence70
- Adoption
- Insufficient
- Hype gap+8
- Incentives22
- Confidence63
A green CodeQL run and a two-line sanitiser call would have left the boxes and arrows intact on four of five Mermaid diagram types while quietly deleting the text inside them. Counting elements is what caught it.
Reality
- Evidence58
- Adoption30
- Hype gap−8
- Incentives35
- Confidence60
ProjectDiscovery says an audit of Markdown Preview Enhanced turned an ordinary repository file into arbitrary file write. Editor extensions run with developer privileges and go uninventoried.
Publishers:projectdiscovery.io
Reality
- Evidence64
- Adoption68
- Hype gap+14
- Incentives80
- Confidence55