Trusted Types for DOM manipulation

- UNOFF

An API that forces developers to be very explicit about their use of powerful DOM-injection APIs. Can greatly improve security against XSS attacks.

IE

  1. 5.5 - 10: Not supported
  2. 11: Not supported

Edge

  1. 12 - 81: Not supported
  2. 83 - 86: Supported
  3. 87: Supported

Firefox

  1. 2 - 82: Not supported
  2. 83: Not supported
  3. 84 - 85: Not supported

Chrome

  1. 4 - 81: Not supported
  2. 83 - 86: Supported
  3. 87: Supported
  4. 88 - 90: Supported

Safari

  1. 3.1 - 13.1: Not supported
  2. 14: Not supported
  3. TP: Not supported

Opera

  1. 9 - 68: Not supported
  2. 69 - 71: Supported
  3. 72: Supported

iOS Safari

  1. 3.2 - 13.7: Not supported
  2. 14: Not supported

Opera Mini

  1. all: Not supported

Android Browser

  1. 2.1 - 4.4.4: Not supported
  2. 81: Supported

Opera Mobile

  1. 10 - 12.1: Not supported
  2. 59: Not supported

Chrome for Android

  1. 87: Supported

Firefox for Android

  1. 83: Not supported

UC Browser for Android

  1. 12.12: Not supported

Samsung Internet

  1. 4 - 12.0: Not supported
  2. 13.0: Supported

QQ Browser

  1. 10.4: Not supported

Baidu Browser

  1. 7.12: Not supported

KaiOS Browser

  1. 2.5: Not supported
Resources:
Firefox position: non-harmful
Web.dev article on using trusted types