---
title: "Deprecated JavaScript APIs: document.write, escape() and Inline Handlers | bseoa"
description: "A script on the page uses a JavaScript API that is deprecated or discouraged: document.write, escape()/unescape(), or inline onload=/onclick= handlers. These s…"
image: "https://www.blackseoanalyzer.com/static/images/black-seo-analyzer-og-image.png"
canonical: "https://www.blackseoanalyzer.com/en/technical-seo/javascript-analyzer/deprecated-api-usage"
language: "en"
---

# Deprecated JavaScript APIs: document.write, escape() and Inline Handlers

JavaScript Analyzer

## What is this warning?

A script on the page uses a JavaScript API that is deprecated or discouraged: document.write, escape()/unescape(), or inline onload=/onclick= handlers. These still run today, but they slow rendering, conflict with Content Security Policy, or can be blocked by the browser.

## How to Fix This Issue

### How to Fix It

#### What bseoa flags

bseoa scans the page's script content for these patterns and reports each one it finds, along with the suggested replacement:

- `document.write`: use DOM methods instead.
- `escape(`: use `encodeURIComponent()`.
- `unescape(`: use `decodeURIComponent()`.
- `onload=` and `onclick=`: use `addEventListener()`.

The check matches text, so a method with a similar name, such as `CSS.escape(`, is also reported. `CSS.escape()` is a modern API and can be left alone.

#### document.write

`document.write` injects markup into the HTML parser while the page is loading. When it adds a parser-blocking external script, the browser has to stop, fetch and run that script before continuing. Chrome can block cross-site scripts inserted this way on slow connections, so the code may simply not run for some visitors. Called after the page loads, it replaces the whole document.

```
// Before
document.write('<script src="https://cdn.example.com/widget.js"><\/script>');

// After
const s = document.createElement('script');
s.src = 'https://cdn.example.com/widget.js';
s.async = true;
document.head.appendChild(s);
```

If the call comes from a third-party tag, check whether the vendor offers an async snippet.

#### escape() and unescape()

These are legacy functions kept only for backward compatibility. They don't handle non-ASCII characters the way URLs expect, so values with accents or emoji get mangled.

```
// Before
const q = escape(searchTerm);

// After
const q = encodeURIComponent(searchTerm);
const original = decodeURIComponent(q);
```

#### Inline onload= and onclick= handlers

Inline event attributes aren't removed from browsers, but they mix behavior into markup and require `'unsafe-inline'` or `'unsafe-hashes'` in a Content Security Policy. Attaching listeners in script keeps a strict CSP possible:

```
<!-- Before -->
<button onclick="openDemo()">Watch demo</button>

<!-- After -->
<button id="demo-button">Watch demo</button>
<script>
  document.getElementById('demo-button')
    .addEventListener('click', openDemo);
</script>
```

#### Why this matters for SEO

Googlebot renders pages with a recent version of Chrome. Script that blocks the parser delays rendering for users and for the renderer, and script that a browser refuses to run can leave content or links missing from the rendered page. See [why JavaScript crawls break](https://www.blackseoanalyzer.com/en/blog/why-your-javascript-crawl-is-broken-and-how-to-fix-it) for how to check the rendered result.

### SEO Impact

This issue can affect your site's search engine rankings and user experience. Addressing it promptly helps ensure optimal performance and visibility in search results.

### Automatic Detection

bseoa automatically checks for this warning during site analysis, along with hundreds of other technical SEO issues.

## Other JavaScript Analyzer issues

- [Add crossorigin Attribute for Better Error Logging](https://www.blackseoanalyzer.com/en/technical-seo/javascript-analyzer/missing-crossorigin-attribute)
- [Audit Third-Party Scripts for Performance and Security](https://www.blackseoanalyzer.com/en/technical-seo/javascript-analyzer/third-party-script-loaded)
- [Avoid document.write for Better Performance and Security](https://www.blackseoanalyzer.com/en/technical-seo/javascript-analyzer/document-write-usage)
- [Avoid eval() Due to Significant Security Risks](https://www.blackseoanalyzer.com/en/technical-seo/javascript-analyzer/eval-usage)
- [Avoid Synchronous Scripts in <head> to Speed Up Rendering](https://www.blackseoanalyzer.com/en/technical-seo/javascript-analyzer/synchronous-script-in-head)
- [Clarify Script Loading by Removing Redundant async and defer](https://www.blackseoanalyzer.com/en/technical-seo/javascript-analyzer/redundant-async-and-defer)
- [Correct Unknown Script type for Proper Execution](https://www.blackseoanalyzer.com/en/technical-seo/javascript-analyzer/unknown-script-type)
- [Enhance Security by Loading All Scripts Over HTTPS](https://www.blackseoanalyzer.com/en/technical-seo/javascript-analyzer/insecure-script-load)
- [Improve Code Maintainability by Avoiding Inline Event Handlers](https://www.blackseoanalyzer.com/en/technical-seo/javascript-analyzer/inline-event-handler)
- [Improve Performance by Externalizing Large Inline Scripts](https://www.blackseoanalyzer.com/en/technical-seo/javascript-analyzer/large-inline-script)
- [Improve Security with Subresource Integrity (SRI) for CDN Scripts](https://www.blackseoanalyzer.com/en/technical-seo/javascript-analyzer/missing-integrity-attribute)
- [Modernize Your HTML by Removing Unnecessary Script type Attributes](https://www.blackseoanalyzer.com/en/technical-seo/javascript-analyzer/unnecessary-type-attribute)
- [Optimize JavaScript Module Loading](https://www.blackseoanalyzer.com/en/technical-seo/javascript-analyzer/module-without-async)
- [Optimize Loading of Blocking Third-Party Scripts](https://www.blackseoanalyzer.com/en/technical-seo/javascript-analyzer/blocking-third-party-script)
- [Optimize Script Loading to Prevent Page Rendering Delays](https://www.blackseoanalyzer.com/en/technical-seo/javascript-analyzer/render-blocking-script)
- [Preload Critical Scripts to Improve Page Load Performance](https://www.blackseoanalyzer.com/en/technical-seo/javascript-analyzer/missing-preload-hint-for-script)
- [Remove console.log Statements from Production Code](https://www.blackseoanalyzer.com/en/technical-seo/javascript-analyzer/console-log-usage)

## Ready to Unlock Your Site's Full SEO Potential?

Choose the license that fits your needs and start getting the deep, actionable insights you deserve.

[Download Free Trial](https://www.blackseoanalyzer.com/en/free-trial) [Purchase Single License](https://www.blackseoanalyzer.com/buy/single)

```json
{"@context":"https://schema.org","@graph":[{"@type":"Organization","@id":"https://www.blackseoanalyzer.com/#organization","name":"Fiscus Technology, LLC","url":"https://www.blackseoanalyzer.com/","logo":"https://www.blackseoanalyzer.com/static/images/black-seo-analyzer.png","founder":{"@type":"Person","name":"Seth Black"}},{"@type":"WebSite","@id":"https://www.blackseoanalyzer.com/#website","name":"bseoa","url":"https://www.blackseoanalyzer.com/","publisher":{"@id":"https://www.blackseoanalyzer.com/#organization"}},{"@type":"TechArticle","@id":"https://www.blackseoanalyzer.com/en/technical-seo/javascript-analyzer/deprecated-api-usage#article","headline":"Deprecated JavaScript APIs: document.write, escape() and Inline Handlers","name":"Deprecated JavaScript APIs: document.write, escape() and Inline Handlers","description":"A script on the page uses a JavaScript API that is deprecated or discouraged: document.write, escape()/unescape(), or inline onload=/onclick= handlers. These still run today, but they slow rendering, conflict with Content Security Policy, or can be blocked by the browser.","url":"https://www.blackseoanalyzer.com/en/technical-seo/javascript-analyzer/deprecated-api-usage","image":{"@type":"ImageObject","url":"https://www.blackseoanalyzer.com/static/images/black-seo-analyzer-og-image.png","width":1200,"height":630},"author":{"@type":"Person","name":"Seth Black","url":"https://www.blackseoanalyzer.com/about"},"publisher":{"@id":"https://www.blackseoanalyzer.com/#organization"},"mainEntityOfPage":{"@type":"WebPage","@id":"https://www.blackseoanalyzer.com/en/technical-seo/javascript-analyzer/deprecated-api-usage"},"inLanguage":"en-US","keywords":"technical SEO, SEO warning, Seth Black&#39;s SEO Analyzer"},{"@type":"BreadcrumbList","itemListElement":[{"@type":"ListItem","position":1,"name":"Home","item":"https://www.blackseoanalyzer.com/"},{"@type":"ListItem","position":2,"name":"Technical SEO Warnings","item":"https://www.blackseoanalyzer.com/en/technical-seo"},{"@type":"ListItem","position":3,"name":"Deprecated JavaScript APIs: document.write, escape() and Inline Handlers","item":"https://www.blackseoanalyzer.com/en/technical-seo/javascript-analyzer/deprecated-api-usage"}]}]}
```
