1. Parser prohibits literal "@click", there is no escape mechanism.
2. Only click, what about other DOM events?
3. Leaking: Event listeners not removed in destructor (your clean() function?)
4. No XSS protection, ow.
5. No tests, might want some.
6. Based on innerHTML assignment with nothing to guarantee valid HTML.
7. No error handling.