My add-on shows inclusion of new JavaScript (using a script tag) by putting a red border on the parent tag, and it shows JavaScript called from the onMouseover, onLoad, onClick, etc. attributes in blue.
One of the most interesting things I've found is that these are actually relatively predictable things. If there's an expanding menu, there's probably some JavaScript. Certain types of forms. Content that you'd expect to be external. Links that involve pop-ups. Embedded content from other sources.
Take a look at the way the add-on colours this weather site:
data:image/s3,"s3://crabby-images/fe998/fe998fa11f533d6bb04d5d4a50f555e565bbc31e" alt=""
The question now is... Can this predictability be a helpful tool in developing more secure web pages?
No comments:
Post a Comment