Browser-local does not mean standards-complete
HTML parsing is error tolerant. Source diagnostics, sandboxed previews, and transformations do not replace full conformance, security, or production-browser testing.
Entity encoding is context-specific
Encoding common HTML characters is useful for literal text and many quoted-attribute cases, but it is not a universal JavaScript, URL, CSS, or sanitizer boundary.
Parser and sanitizer boundary
HTML DOMParser creates a detached document and may repair or normalize markup. That is useful for inspection, but parsing alone does not sanitize untrusted HTML. Review scripts, inline event attributes, embedded content and application-specific URL/context rules before any live-DOM insertion.