// the find
douglascrockford/ADsafe
A safe JavaScript widget framework for advertising and other mashups.
ADsafe is Douglas Crockford's 2011 approach to running untrusted third-party widgets (ads, mashups) safely inside a host page by restricting JavaScript to a subset enforced via JSLint and mediating all DOM access through a runtime library. It's for anyone curious about pre-iframe-sandbox approaches to script isolation, not for anyone building something today.
The core idea is legitimately clever: instead of sandboxing at the browser/process level, it statically restricts the language subset a widget can use (no eval, no global access, no direct DOM) and then wraps all DOM interaction in a single object with a locked-down API. Small, readable codebase (one adsafe.js runtime) that's a good read for understanding capability-based security patterns in JS. Comes with concrete templates (template.html/template.js) showing exactly what a compliant widget looks like, so the constraints are demonstrated, not just described.
Dead project — last commit 2017, and the approach itself was effectively obsoleted years earlier by CSP, iframe sandboxing, and Shadow DOM, all of which solve the same problem with actual browser-enforced guarantees instead of static analysis you have to trust. Security model depends entirely on JSLint catching every unsafe construct before the widget ships; any gap in that subset checker is a full sandbox escape, and static analysis for a dynamic language is inherently leaky. No tests in the repo, no package published to npm, no build tooling — you'd be vendoring a single file and hoping. Public domain with an explicit no-warranty disclaimer, and no maintainer to ask when (not if) you find an edge case it misses.