Disclaimer: It is still under research, this guide can be extended.
loadURL
loads only https://
linksnodeIntegration
is disabled (false
)contextIsolation
is enabled (true
)sandbox
is enabled (true
).setPermissionRequestHandler
)webSecurity
is enabled (true
)allowRunningInsecureContent
is not used or is set to (false
)experimentalFeatures
is disabled or not used (false
)enableBlinkFeatures
is not used<webview>
tag does not useĀ allowpopups
new-window
and will-navigate
, and other event listeners<webview>
tag)shell.openExternal
function invoke (http://
, https://
) or informs the user and provides a consent page that opening the next page can be a malicious action