for(var i=0; i<products.length; i++) {
content += products[i].name + '<br />';
}
$('.content').html(content);
Use a template library, do not concatenate strings and then just set HTML. Most template libraries will have safeguards in place to prevent XSS vulnerabilities. Even if the product name is always trusted to be non-malicious, it's still a dangerous anti-pattern.XSS will eat your lunch. It breaks every safeguard there is, it even defeats 2 factor auth and lets the attacker adopt the identity and privileges of whoever has been exposed to the attack. It's prudent to be extra careful and never have code that looks like this.