When reporting XSS, don't use alert(1)