Earlier quoted context omitted.
Sorry, but you're out of touch. Almost everyone wants the features that JS enables. Literally: Almost everyone. I understand you don't, and I absolutely respect that decision, but it means that you're not worth developing for. Full stop. It's not a matter of mal-intent, it's a matter of financial logistics. You bought that machine to run code. If you don't want to run code that sites serve you on the internet, don't…
> That said, I'd be willing to wager a fair bit that literally every line of code you've run on your machine (probably ever if it's been bought in the last few years) outside of the vendor installed OS and drivers came from the internet. We explicitly decide to install software and we know where we're getting it from. We may not be careful enough, but I certainly trust `brew install` a lot more than I trust a random…
The single safest thing you can do while using the web is to simply be aware of what you're clicking on, and what sites you visit.
> I bought my car to drive it, but that doesn't mean that every person I pass on the street gets to drive my car.
Damn right you don't let random people drive your car! just like I expect you not to click every link you see!
I'd also love it if you'd install an ad blocker, remove just about every other extension you have in your browser (ABSOLUTELY do this for old firefox extensions and IE BHOs) and trust your browser when it tells you that maybe visiting that particular site isn't the best idea.
That said, modern browsers do a really, really good job at isolating the code running in that page from anything you care about.