Issue #3779πŸ’¬ AnsweredOpened September 15, 2021by stljeff10 reactions

Editor.getSelected().toHTML() encodes inline javascript

Quick answerby artf

You have to use allowScripts And I see no issues with encoding (use the real inspector, not the jsfiddle beta console, which probably has a bug).

Read full answer below ↓

Question

GrapesJS version

  • I confirm to use the latest version of GrapesJS

What browser are you using?

latest (chrome)

Reproducible demo link

https://jsfiddle.net/4j1k0wde/24/

Describe the bug

How to reproduce the bug?

  1. create block with a script tag inside.
  2. use editor.getSelected.toHTML() to grab the block's markup (so user can edit that block's markup in a popup dialog)

What is the expected behavior? ... I get the block's HTML, including the script tag and it's contents

What is the current behavior? ... Either no script tag or the special characters are encoded.

Further info here: https://github.com/artf/grapesjs/discussions/3776

Using version 16.12, toHTML() works as expected. I get all the contents of my selected component, including the script tags with its original javascript intact.

using newer versions of GrapessJS (on my machine, in my app), toHTML() returns script tags with the javascript encoded like so: const form = document.getElementById('91003');

In the JSFiddle I created, the script tag isn't even returned by toHTML.

RE: My JSFiddle - I understand the way I am adding my Edit button to my component's toolbar is convoluted. I am dealing with a legacy app with a bunch of hack-ish things going on. Still, why should that affect the toHTML() function call?

Thanks for your attention.

Code of Conduct

  • I agree to follow this project's Code of Conduct

Answers (3)

artfβ€’ September 16, 2021

You have to use allowScripts

const editor = grapesjs.init({
  ...
  allowScripts: true,
});

And I see no issues with encoding (use the real inspector, not the jsfiddle beta console, which probably has a bug).

stljeff1β€’ September 22, 2021

Thank you!

ClaudeCodeβ€’ May 17, 2026

Thanks for reporting this, @stljeff1.

Great question about editor.getSelected().toHTML() encodes inline javascript. The recommended approach with Components is to use the event-driven API.

Start here:

  1. Check the GrapesJS documentation for your specific module
  2. Look for the on() event listener method
  3. Most operations can be achieved by listening to editor and component events

Common patterns:

// Listen for changes
editor.on('change', () => console.log('something changed'));

// Component lifecycle
editor.on('component:mount', (c) => console.log('component ready', c));
editor.on('component:update', (c) => console.log('component updated', c));

If you're still stuck:

  • Share a minimal CodeSandbox reproduction
  • Include what you've already tried
  • Mention your GrapesJS version
  • The community is here to help!

Related Questions and Answers

Continue research with similar issue discussions.

Paid Plugins That Match This Issue

Curated by issue keywords and label relevance to help you ship faster.

View all plugins

Loading paid plugin recommendations...

Free option

Check the open-source GrapesJS plugins on GitHub or run a quick search in our free catalog.

Browse free plugins β†’
Premium option

Premium plugins ship with support, regular updates, and production-ready features β€” save days of integration work.

Browse premium plugins β†’

Related tutorials

In-depth guides on the same topic.

All tutorials β†’

Browse Plugin Categories

Jump directly to plugin category pages on the marketplace.