Browser-local does not mean standards-complete
HTML parsing is error tolerant. Source diagnostics, sandboxed previews, and transformations do not replace full conformance, security, or production-browser testing.
Link extraction is not URL safety validation
Parsed link count and extracted href/text/target/rel are shown together. Treat unknown schemes and external destinations as data that still needs application-specific validation.
Parser and sanitizer boundary
HTML DOMParser creates a detached document and may repair or normalize markup. That is useful for inspection, but parsing alone does not sanitize untrusted HTML. Review scripts, inline event attributes, embedded content and application-specific URL/context rules before any live-DOM insertion.