We're looking for a way to secure third party code within our web pages. Someone suggested we use Caja. I looked into that, but the information about it is quite sparse. Before I deep dive into it, I would first like to know:
- Can Caja handle embedded HTML like Google Map's, which effectively acts as a bootstrap, and loads all the active HTML and JavaScript when run by the browser? 
- Is Caja mature enough to be used in a production environment, or is it still at the concept stage? 
Thanks, Eran