So `.setHTML("<script>...</script>")` does not set HTML?
And instead of this security feature some might want to take a more fundamental look at security which might lead them to a completely different design. Again, make it optional.
In fact, it’s better for the industry even if a few such individuals are so pained by having to learn about and handle security that they just quit web development entirely. Just like aspiring pilots who can’t stand checklists and safety rules should pursue a different career.
.innerHTML = "<script>...</script>"