---
title: "Avoid eval() Due to Significant Security Risks | bseoa"
description: "Your code is using the eval() function. This is extremely dangerous. The eval() function executes any string as JavaScript code, which can open your website up…"
image: "https://www.blackseoanalyzer.com/static/images/black-seo-analyzer-og-image.png"
canonical: "https://www.blackseoanalyzer.com/en/technical-seo/javascript-analyzer/eval-usage"
language: "en"
---

# Avoid eval() Due to Significant Security Risks

JavaScript Analyzer

## What is this warning?

Your code is using the `eval()` function. This is extremely dangerous. The `eval()` function executes any string as JavaScript code, which can open your website up to major security vulnerabilities, particularly Cross-Site Scripting (XSS) attacks. There is almost always a safer, better alternative.

## How to Fix This Issue

### How to Fix It

#### The Problem

```
eval('alert("Hello World")');
```

#### The Solution

Refactor your code to avoid executing strings. If you need to parse JSON, use `JSON.parse()`. If you need to call a function by name, access it as a property of the `window` object.

#### Why This Works

Removing `eval()` closes a significant security hole. The mantra in the JavaScript community is "eval is evil" for a good reason. Always look for a safer way to achieve your goal.

### SEO Impact

This issue can affect your site's search engine rankings and user experience. Addressing it promptly helps ensure optimal performance and visibility in search results.

### Automatic Detection

bseoa automatically checks for this warning during site analysis, along with hundreds of other technical SEO issues.

## Other JavaScript Analyzer issues

- [Add crossorigin Attribute for Better Error Logging](https://www.blackseoanalyzer.com/en/technical-seo/javascript-analyzer/missing-crossorigin-attribute)
- [Audit Third-Party Scripts for Performance and Security](https://www.blackseoanalyzer.com/en/technical-seo/javascript-analyzer/third-party-script-loaded)
- [Avoid document.write for Better Performance and Security](https://www.blackseoanalyzer.com/en/technical-seo/javascript-analyzer/document-write-usage)
- [Avoid Synchronous Scripts in <head> to Speed Up Rendering](https://www.blackseoanalyzer.com/en/technical-seo/javascript-analyzer/synchronous-script-in-head)
- [Clarify Script Loading by Removing Redundant async and defer](https://www.blackseoanalyzer.com/en/technical-seo/javascript-analyzer/redundant-async-and-defer)
- [Correct Unknown Script type for Proper Execution](https://www.blackseoanalyzer.com/en/technical-seo/javascript-analyzer/unknown-script-type)
- [Deprecated JavaScript APIs: document.write, escape() and Inline Handlers](https://www.blackseoanalyzer.com/en/technical-seo/javascript-analyzer/deprecated-api-usage)
- [Enhance Security by Loading All Scripts Over HTTPS](https://www.blackseoanalyzer.com/en/technical-seo/javascript-analyzer/insecure-script-load)
- [Improve Code Maintainability by Avoiding Inline Event Handlers](https://www.blackseoanalyzer.com/en/technical-seo/javascript-analyzer/inline-event-handler)
- [Improve Performance by Externalizing Large Inline Scripts](https://www.blackseoanalyzer.com/en/technical-seo/javascript-analyzer/large-inline-script)
- [Improve Security with Subresource Integrity (SRI) for CDN Scripts](https://www.blackseoanalyzer.com/en/technical-seo/javascript-analyzer/missing-integrity-attribute)
- [Modernize Your HTML by Removing Unnecessary Script type Attributes](https://www.blackseoanalyzer.com/en/technical-seo/javascript-analyzer/unnecessary-type-attribute)
- [Optimize JavaScript Module Loading](https://www.blackseoanalyzer.com/en/technical-seo/javascript-analyzer/module-without-async)
- [Optimize Loading of Blocking Third-Party Scripts](https://www.blackseoanalyzer.com/en/technical-seo/javascript-analyzer/blocking-third-party-script)
- [Optimize Script Loading to Prevent Page Rendering Delays](https://www.blackseoanalyzer.com/en/technical-seo/javascript-analyzer/render-blocking-script)
- [Preload Critical Scripts to Improve Page Load Performance](https://www.blackseoanalyzer.com/en/technical-seo/javascript-analyzer/missing-preload-hint-for-script)
- [Remove console.log Statements from Production Code](https://www.blackseoanalyzer.com/en/technical-seo/javascript-analyzer/console-log-usage)

## Ready to Unlock Your Site's Full SEO Potential?

Choose the license that fits your needs and start getting the deep, actionable insights you deserve.

[Download Free Trial](https://www.blackseoanalyzer.com/en/free-trial) [Purchase Single License](https://www.blackseoanalyzer.com/buy/single)

```json
{"@context":"https://schema.org","@graph":[{"@type":"Organization","@id":"https://www.blackseoanalyzer.com/#organization","name":"Fiscus Technology, LLC","url":"https://www.blackseoanalyzer.com/","logo":"https://www.blackseoanalyzer.com/static/images/black-seo-analyzer.png","founder":{"@type":"Person","name":"Seth Black"}},{"@type":"WebSite","@id":"https://www.blackseoanalyzer.com/#website","name":"bseoa","url":"https://www.blackseoanalyzer.com/","publisher":{"@id":"https://www.blackseoanalyzer.com/#organization"}},{"@type":"TechArticle","@id":"https://www.blackseoanalyzer.com/en/technical-seo/javascript-analyzer/eval-usage#article","headline":"Avoid eval() Due to Significant Security Risks","name":"Avoid eval() Due to Significant Security Risks","description":"Your code is using the eval() function. This is extremely dangerous. The eval() function executes any string as JavaScript code, which can open your website up to major security vulnerabilities, particularly Cross-Site Scripting (XSS) attacks. There is almost always a safer, better alternative.","url":"https://www.blackseoanalyzer.com/en/technical-seo/javascript-analyzer/eval-usage","image":{"@type":"ImageObject","url":"https://www.blackseoanalyzer.com/static/images/black-seo-analyzer-og-image.png","width":1200,"height":630},"author":{"@type":"Person","name":"Seth Black","url":"https://www.blackseoanalyzer.com/about"},"publisher":{"@id":"https://www.blackseoanalyzer.com/#organization"},"mainEntityOfPage":{"@type":"WebPage","@id":"https://www.blackseoanalyzer.com/en/technical-seo/javascript-analyzer/eval-usage"},"inLanguage":"en-US","keywords":"technical SEO, SEO warning, Seth Black&#39;s SEO Analyzer"},{"@type":"BreadcrumbList","itemListElement":[{"@type":"ListItem","position":1,"name":"Home","item":"https://www.blackseoanalyzer.com/"},{"@type":"ListItem","position":2,"name":"Technical SEO Warnings","item":"https://www.blackseoanalyzer.com/en/technical-seo"},{"@type":"ListItem","position":3,"name":"Avoid eval() Due to Significant Security Risks","item":"https://www.blackseoanalyzer.com/en/technical-seo/javascript-analyzer/eval-usage"}]}]}
```
