Trap #1: JSON.parse(JSON.stringify(obj)) Data Loss
The old JSON hack for deep cloning drops functions, Symbols, and undefined properties, and converts Dates to strings and Maps/Sets to empty objects. Use the native structuredClone() API.
Trap #2: Object.freeze() Is Strictly Shallow
Object.freeze(obj) only freezes top-level properties; nested objects and arrays remain completely mutable. Implement a deep freeze utility for recursive immutability.
Trap #3: Prototype Property Bleed in for...in Loops
for...in iterates over inherited prototype properties. Always filter with Object.hasOwn(obj, key) to verify the property belongs to the instance itself.
Trap #4: Prototype Pollution Vulnerability
Merging unvalidated user input into nested objects without filtering __proto__ or constructor can overwrite Object.prototype, exposing severe security vulnerabilities.
Trap #5: Object Keys Are Always Coerced to Strings or Symbols
Using an object as a key (obj[{}] = 1) converts the key to "[object Object]". If you need arbitrary object references as keys, use a Map.
💬 Frequently Asked Questions
What is the difference between an Object and a Map in JavaScript?
Objects only support string and symbol keys and inherit prototype properties. Maps support keys of any data type (including objects and functions), guarantee insertion order, and offer optimal performance for frequent additions/removals.
Why should you use Object.hasOwn() instead of obj.hasOwnProperty()?
Object.hasOwn(obj, key) is safer because it works even on objects created with Object.create(null) and cannot be shadowed or overwritten by a malicious hasOwnProperty property.
What does structuredClone() support that JSON cloning does not?