---
title: "Remove Dangerous Patterns from Inline Scripts to Prevent XSS | bseoa"
description: "An inline script on your page contains patterns that could be exploited by attackers to inject malicious code. These patterns, such as using eval(), innerHTML …"
image: "https://www.blackseoanalyzer.com/static/images/black-seo-analyzer-og-image.png"
canonical: "https://www.blackseoanalyzer.com/en/technical-seo/security-analyzer/dangerous-pattern-in-inline-script"
language: "en"
---

# Remove Dangerous Patterns from Inline Scripts to Prevent XSS

Security Analyzer

## What is this warning?

An inline script on your page contains patterns that could be exploited by attackers to inject malicious code. These patterns, such as using `eval()`, `innerHTML` with user data, or `document.write()`, can create security vulnerabilities if not handled carefully.

## How to Fix This Issue

### How to Fix It

#### The Problem

```
<script>
  var userInput = getUrlParameter('data');
  document.getElementById('content').innerHTML = userInput;
</script>
```

#### The Solution

Use safer alternatives like `textContent` instead of `innerHTML`, avoid `eval()`, and always sanitize user input.

```
<script>
  var userInput = getUrlParameter('data');
  document.getElementById('content').textContent = userInput; // Safe
</script>
```

#### Why This Works

Using safer DOM manipulation methods and avoiding dangerous functions prevents attackers from injecting malicious scripts through user input or URL parameters.

### SEO Impact

This issue can affect your site's search engine rankings and user experience. Addressing it promptly helps ensure optimal performance and visibility in search results.

### Automatic Detection

bseoa automatically checks for this warning during site analysis, along with hundreds of other technical SEO issues.

## Other Security Analyzer issues

- [Add Crossorigin Attributes to External Resources for Better Security](https://www.blackseoanalyzer.com/en/technical-seo/security-analyzer/missing-crossorigin-attribute)
- [Add Input Validation to Credit Card Fields for Better Security](https://www.blackseoanalyzer.com/en/technical-seo/security-analyzer/credit-card-field-missing-pattern)
- [Disable Autocomplete on Sensitive Form Fields to Protect User Data](https://www.blackseoanalyzer.com/en/technical-seo/security-analyzer/sensitive-field-autocomplete)
- [Eliminate Mixed Content to Keep Your Site Secure](https://www.blackseoanalyzer.com/en/technical-seo/security-analyzer/mixed-content)
- [Fix Content Security Policy Issues to Strengthen Site Security](https://www.blackseoanalyzer.com/en/technical-seo/security-analyzer/content-security-issue)
- [Protect Your Forms from CSRF Attacks with Anti-CSRF Tokens](https://www.blackseoanalyzer.com/en/technical-seo/security-analyzer/form-missing-csrf-protection)
- [Remove Unsafe Content to Improve Site Security](https://www.blackseoanalyzer.com/en/technical-seo/security-analyzer/recommendation-to-remove-unsafe-content)
- [Replace Inline Event Handlers with Safer Alternatives](https://www.blackseoanalyzer.com/en/technical-seo/security-analyzer/inline-event-handler)
- [Secure External Resources by Using HTTPS](https://www.blackseoanalyzer.com/en/technical-seo/security-analyzer/insecure-external-resource)
- [Secure Your Forms by Using HTTPS for Form Submissions](https://www.blackseoanalyzer.com/en/technical-seo/security-analyzer/insecure-form-action)
- [Strengthen Your Site's Defense Against XSS with a Content Security Policy](https://www.blackseoanalyzer.com/en/technical-seo/security-analyzer/inline-script-without-nonce)
- [Use addEventListener for Better Security and Code Organization](https://www.blackseoanalyzer.com/en/technical-seo/security-analyzer/recommendation-to-use-addeventlistener)
- [Use Proper Input Type for Password Fields to Enhance Security](https://www.blackseoanalyzer.com/en/technical-seo/security-analyzer/password-field-not-type-password)
- [Use Subresource Integrity (SRI) to Secure Your CDN Assets](https://www.blackseoanalyzer.com/en/technical-seo/security-analyzer/cdn-resource-missing-integrity)

## Ready to Unlock Your Site's Full SEO Potential?

Choose the license that fits your needs and start getting the deep, actionable insights you deserve.

[Download Free Trial](https://www.blackseoanalyzer.com/en/free-trial) [Purchase Single License](https://www.blackseoanalyzer.com/buy/single)

```json
{"@context":"https://schema.org","@graph":[{"@type":"Organization","@id":"https://www.blackseoanalyzer.com/#organization","name":"Fiscus Technology, LLC","url":"https://www.blackseoanalyzer.com/","logo":"https://www.blackseoanalyzer.com/static/images/black-seo-analyzer.png","founder":{"@type":"Person","name":"Seth Black"}},{"@type":"WebSite","@id":"https://www.blackseoanalyzer.com/#website","name":"bseoa","url":"https://www.blackseoanalyzer.com/","publisher":{"@id":"https://www.blackseoanalyzer.com/#organization"}},{"@type":"TechArticle","@id":"https://www.blackseoanalyzer.com/en/technical-seo/security-analyzer/dangerous-pattern-in-inline-script#article","headline":"Remove Dangerous Patterns from Inline Scripts to Prevent XSS","name":"Remove Dangerous Patterns from Inline Scripts to Prevent XSS","description":"An inline script on your page contains patterns that could be exploited by attackers to inject malicious code. These patterns, such as using eval(), innerHTML with user data, or document.write(), can create security vulnerabilities if not handled carefully.","url":"https://www.blackseoanalyzer.com/en/technical-seo/security-analyzer/dangerous-pattern-in-inline-script","image":{"@type":"ImageObject","url":"https://www.blackseoanalyzer.com/static/images/black-seo-analyzer-og-image.png","width":1200,"height":630},"author":{"@type":"Person","name":"Seth Black","url":"https://www.blackseoanalyzer.com/about"},"publisher":{"@id":"https://www.blackseoanalyzer.com/#organization"},"mainEntityOfPage":{"@type":"WebPage","@id":"https://www.blackseoanalyzer.com/en/technical-seo/security-analyzer/dangerous-pattern-in-inline-script"},"inLanguage":"en-US","keywords":"technical SEO, SEO warning, Seth Black&#39;s SEO Analyzer"},{"@type":"BreadcrumbList","itemListElement":[{"@type":"ListItem","position":1,"name":"Home","item":"https://www.blackseoanalyzer.com/"},{"@type":"ListItem","position":2,"name":"Technical SEO Warnings","item":"https://www.blackseoanalyzer.com/en/technical-seo"},{"@type":"ListItem","position":3,"name":"Remove Dangerous Patterns from Inline Scripts to Prevent XSS","item":"https://www.blackseoanalyzer.com/en/technical-seo/security-analyzer/dangerous-pattern-in-inline-script"}]}]}
```
