The Dangers of += in JavaScript
kellysutton.tumblr.com
kellysutton.tumblr.com
The real reason you should not be generating HTML with string concatenation is that using jQuery (or an equivalent) gives you built-in escaping for field attributes and content.
Consider this:
wrappedInput += '<input type="text" value="' + defaultValue + '"/>';
If somehow defaultValue got passed in as " /><script>foo()</script><br x="
, then you've just been XSS'd. If you use jQuery to set input.val(defaultValue), you're safe.Or you could do the sane thing and use JS templates (handlebars, mustache, jquery tmpl, etc).