Of the myriads of existing transfer or serialization formats,
* JSON is still the only secure by default one (if you ignore the two later updates, which made it insecure),
* JSON is by far the easiest to parse (small and secure, no references),
* is natively supported by Javascript.
It has some minor design mistakes, and is not binary (such as msgpack, which is therefore faster), but still is a sane and proper default. Esp. it does not support objects and other extensions, with its initializer problems on MITM attacks, and is properly ended. Unlike XML, YAML, BJSON, BSON, ... which do have major problems, or msgpack, protobuf, ... which do have minor problems.
In every application, any dependency to XML should be minimized, contained and preferably eliminated.