looks ok, but how about add a test for the client-side css sanitizer in tests/src/com/google/caja/plugin/sanitizecss_test.js
(verbal review). other than removing es5mode restriction in the test, LGTM