Skip to main content

Be Aware When You Install Third Party Code

We've been seeing a few problem reports, in Blogger Help Forum: Something Is Broken, from blog owners who are not aware of the risks from installing third party code, on their blog.

Some blog owners are not even aware that the code being installed is not supplied by Blogger - and is not subject to the same coding standards as code supplied by Blogger.

Third party accessories and code - from simple JavaScript that installs in the blog template, to attractive XML gadgets installed using the "Add a Gadget" wizard - has always been a challenge, to Blogger blogs.

Knowing when you are installing code provided by someone other than Blogger / Google, and taking appropriate precautions, is your responsibility. What you install can affect your reader activity - and even your reader's computers.

Blogger provides a large library of XML coded accessories, installed using the Layout "Add a Gadget" wizard.

Sadly, the Blogger "Add a Gadget" library is subject to abuse by hackers.
As we have learned in the past, however, the "Add a Gadget" accessory library is also used for distribution of non Blogger supplied gadgets. Gadgets supplied by Blogger are available using "Add a Gadget", and are labeled "By Blogger".

Google does have other accessory libraries - the late "iGoogle" library is one well known one. That aside, most Blogger blogs - and all non Google websites, which are used for distribution of Blogger accessories and gadgets - are non Blogger products.

Consider, carefully, any third party code.
Be aware of what you are about to install, on your blog.
  • A gadget provided using "Add a Gadget", and labeled "By Blogger" is a Blogger provided gadget.
  • A gadget provided using "Add a Gadget", but not labeled "By Blogger", is not a Blogger provided gadget.
  • A gadget provided using a Blogger blog, which is not published by Blogger, is not a Blogger provided gadget.
  • A gadget provided using a non Google website is not a Blogger provided gadget.

These are examples of Blogger supplied gadgets. Anything different is not a Blogger supplied gadget.

If you install non Blogger code in the template, and later see
Your blog has been deleted because of MALICIOUS JAVASCRIPT
this is a risk which you take.

Consider the risks involved, before installing third party code.
Do not install non Blogger code on your blog, without knowing the risks.

Comments

Popular posts from this blog

Stats Components Are Significant, In Their Own Context

One popular Stats related accessory, which displays pageview information to the public, is the "Popular Posts" gadget.

Popular Posts identifies from 1 to 10 of the most popular posts in the blog, by comparing Stats pageview counts. Optional parts of the display of each post are a snippet of text, and an ever popular thumbnail photo.

Like many Stats features, blog owners have found imaginative uses for "Popular Posts" - and overlook the limitations of the gadget. Both the dynamic nature of Stats, and the timing of the various pageview count recalculations, create confusion, when Popular Posts is examined.

Help! I Can't See My Blog!

I just posted to my blog, so I know that it's there. I can tell others are looking at it. But I can't see it.

Well, the good news is you don't have a blog hijack or other calamity. Your blog is not gone.

Apparently, some ISPs are blocking *.blogspot.com, or maybe have network configuration or infrastructure problems. You can access Blogger.com or you can access Blogspot.com, but you can't access nitecruzr.blogspot.com, or bloggerstatusforreal.blogspot.com.

You can't access them directly, that is. If you can access any free, anonymous proxy servers, though, you may be able to access your blog.

Note: You can use PKBlogs with the URL pre packaged. Here is the address of this post (with gratuitous line breaks to prevent the old post sidebar alignment problem):
http://www.pkblogs.com/bloggerstatusforreal.blogspot.com/
2006/07/help-i-cant-see-my-blog.html


And an additional URL, to provide to those suffering from this problem, would be the WordPress version of this post:
ht…