freecoding.school100% FREE · NO SIGNUP
Markup CityISSUE #25 of 39

iframes · pages inside pages

Tagg the BuilderVSThe Unclosed Tag
Tagg the Builder saysAn <iframe> embeds another HTML document inside your page — a window into a separate page.

<iframe src="page.html"> loads a whole other document in a box. It's how you embed maps, videos, payment widgets, and previews (this academy's sandbox uses one).

Iframes are isolated, which is good for safety — add the sandbox attribute to restrict what the embedded page can do. But they cost performance and can't be styled from the parent, so use them deliberately.

Power-ups you unlock

The Unclosed Tag attacks — common mistakes

Boss battleEmbed one site in an iframe with a fixed width/height, then add sandbox="allow-scripts" and observe what changes.

Example code

<!doctype html>
<html><head><meta charset="utf-8"></head>
<body style="background:#06040d">
  <iframe src="https://example.com" width="100%" height="240" style="border:1px solid #2a1d4a"></iframe>
</body></html>
▶ Open the interactive comic issue
‹ Ids · Unique HandlesScripts · Running Js From Html ›