Avoiding the introduction of XSS into nontrivial applications is a difficult problem in practice: XSS remains among the top vulnerabilities in Web applications, according to OWASP (Open Web Application Security Project);4 within Google it is the most common class of Web application vulnerabilities among those reported under Google's Vulnerability Reward Program