The decisive boundaryapplyIndexTaps only invokes transforms. Inspect the plugin callback that first changes the bytes.

String replacement has its own language.

Unsafe dynamic string
html.replace('</html>', `${script}</html>`)
Literal callback result
html.replace('</html>', () => `${script}</html>`)

Fix the insertion boundary.

Callback

Return dynamic content literally.

Explicit slice

Compose around the closing tag index.

Loud fallback

Define behavior when the anchor is absent.

Do not patch only the currency string.

Changing quotes hides one trigger.

The transform remains unsafe for replacement tokens arriving in any future plugin payload.

Regression matrix.

Primary evidence.

Keep the full plugin runbook.

The canonical guide includes safe insertion shapes, diagnostic order, and a replacement-token matrix.

Read and star on GitHub