Browser-local does not mean standards-complete
HTML parsing is error tolerant. Source diagnostics, sandboxed previews, and transformations do not replace full conformance, security, or production-browser testing.
Decoded entities can become markup-looking text
Decoded output remains text in this interface. If it contains tags or event attributes, review it as code before placing it into any live HTML context.
Parser and sanitizer boundary
HTML DOMParser creates a detached document and may repair or normalize markup. That is useful for inspection, but parsing alone does not sanitize untrusted HTML. Review scripts, inline event attributes, embedded content and application-specific URL/context rules before any live-DOM insertion.