A script on the page uses a JavaScript API that is deprecated or discouraged: document.write, escape()/unescape(), or inline onload=/onclick= handlers. These still run today, but they slow rendering, conflict with Content Security Policy, or can be blocked by the browser.
bseoa scans the page's script content for these patterns and reports each one it finds, along with the suggested replacement:
document.write: use DOM methods instead.escape(: use encodeURIComponent().unescape(: use decodeURIComponent().onload= and onclick=: use addEventListener().The check matches text, so a method with a similar name, such as CSS.escape(, is also reported. CSS.escape() is a modern API and can be left alone.
document.write injects markup into the HTML parser while the page is loading. When it adds a parser-blocking external script, the browser has to stop, fetch and run that script before continuing. Chrome can block cross-site scripts inserted this way on slow connections, so the code may simply not run for some visitors. Called after the page loads, it replaces the whole document.
// Before
document.write('<script src="https://cdn.example.com/widget.js"><\/script>');
// After
const s = document.createElement('script');
s.src = 'https://cdn.example.com/widget.js';
s.async = true;
document.head.appendChild(s);
If the call comes from a third-party tag, check whether the vendor offers an async snippet.
These are legacy functions kept only for backward compatibility. They don't handle non-ASCII characters the way URLs expect, so values with accents or emoji get mangled.
// Before
const q = escape(searchTerm);
// After
const q = encodeURIComponent(searchTerm);
const original = decodeURIComponent(q);
Inline event attributes aren't removed from browsers, but they mix behavior into markup and require 'unsafe-inline' or 'unsafe-hashes' in a Content Security Policy. Attaching listeners in script keeps a strict CSP possible:
<!-- Before -->
<button onclick="openDemo()">Watch demo</button>
<!-- After -->
<button id="demo-button">Watch demo</button>
<script>
document.getElementById('demo-button')
.addEventListener('click', openDemo);
</script>
Googlebot renders pages with a recent version of Chrome. Script that blocks the parser delays rendering for users and for the renderer, and script that a browser refuses to run can leave content or links missing from the rendered page. See why JavaScript crawls break for how to check the rendered result.
This issue can affect your site's search engine rankings and user experience. Addressing it promptly helps ensure optimal performance and visibility in search results.
bseoa automatically checks for this warning during site analysis, along with hundreds of other technical SEO issues.
Choose the license that fits your needs and start getting the deep, actionable insights you deserve.