Injecting markup into someone else's website isn't what I'd call too strict a default configuration
If you mean to convey that it's possible to configure it to filter properly, let me introduce you to `textContent` which is older than Firefox (I'm struggling to find a date it's so old)
That's the whole point of the setHTML.
How would I set a header level using textContent?