diff --git a/lib/rules/call_setTimeout.js b/lib/rules/call_setTimeout.js index 27b424b..b85ca2e 100644 --- a/lib/rules/call_setTimeout.js +++ b/lib/rules/call_setTimeout.js @@ -10,7 +10,7 @@ module.exports = function (context) { return { "CallExpression": function (node) { if ((node.callee.name == 'setTimeout') || ((node.callee.property) && (node.callee.property.name == 'setTimeout'))) { - context.report(node, "The function setTimeout can be unsafe"); + context.report(node, "Calling setTimeout with a first argument as string (or string concatenation) with user input may lead to XSS"); } } };