I by default block JS on the web and only allow it for domains I accept.
It's a tiny bit of work for a whole lot of safety.
Not intending to sound snarky but do you just not use the web much? Or if you're adding allows all the time, what's the net gain?
I also set temporary permissions for any site I dont think I will be spending a lot of time on because they might change what's running and I dont have any trust or insight into their process - so I might authorize that site 3-4x a year sometimes before I say it can stay.