Pixel Pete saysinnerHTML reads or replaces an element’s markup as a string — powerful but risky.
el.innerHTML = "<b>hi</b>" parses the string and rebuilds the element's children — fast for big chunks. But injecting untrusted input via innerHTML is the classic XSS hole: a malicious string can run scripts. Use it only with trusted/escaped content; for plain text use textContent, and for dynamic UIs prefer creating nodes.
Power-ups you unlock
innerHTML gets/sets markup as a string
Fast for building big chunks of DOM
XSS risk with untrusted input
Use textContent for plain text
Quirks Mode attacks — common mistakes
Injecting user input via innerHTML (XSS)
innerHTML += in a loop (re-parses each time)
Using innerHTML where textContent is safer
Boss battleBuild a small list with innerHTML from a trusted array, then note why user input would be unsafe.