Skip to main content
WizTools123
WizTools123
Free Online Tools

Tool Categories


Developer Tools New Tool

Free Online Markdown Previewer With Sanitised HTML

Type Markdown and read the rendered result as it appears, with GitHub flavoured tables, strikethrough and task lists. Take away the preview, the HTML source or a tidied copy of the Markdown, and the raw HTML in your document is sanitised before anything is displayed.

Free Forever Nothing Uploaded HTML is sanitised Runs in your browser
Free Online Markdown Previewer With Sanitised HTML
Share this tool
Advertisement Slot (Top Banner) Google AdSense Unit • Responsive Banner
Markdown Previewer Everything happens in this tab. Nothing you paste is sent anywhere.
Your Markdown
Output
Output
Dialect

0 words 0 min read 0 headings 0 links 0 things removed

Preview

Contents

Markdown allows raw HTML, so the rendered result is sanitised before it is put on the page. script, style, iframe, object, embed and form elements are removed, every on* attribute is stripped, and javascript: and data: URLs are blocked in href and src. That last one also blocks inline base64 images, which is the trade being made.

Buy Us A Coffee

Enjoying WizTools123? Help keep our server infrastructure 100% free and open for everyone.

Buy Us A Coffee
Sponsored Content (Below Tool) Google AdSense Placement

Why a Markdown Previewer Has to Sanitise

Because Markdown is allowed to contain HTML.

Markdown was designed to let you drop into HTML whenever the format runs out of syntax, which means a Markdown document can contain <script>, an onerror attribute on a broken image, an <iframe> or a link whose target is javascript:. A previewer takes that text and puts it into a live page. Do that without checking and you have built a reliable way to run someone else's code in your browser, with your session and your cookies.

So the rendered HTML here is parsed into an inert document first, which is a parser that does not execute anything, and then walked: dangerous elements are dropped, every attribute beginning with on is removed, and href and src values are checked before they are kept. Only then is the result put on the page. The count of what was removed is shown with the other counts, so if your document did contain something like that, you find out rather than just not seeing it.

How to Preview Markdown

A few steps, and nothing is uploaded.

1
Write or paste Markdown A README, a changelog, release notes or a comment you are about to post. It renders as you type and nothing is uploaded.
2
Choose the dialect GitHub extensions give you tables, strikethrough and task lists. Turn on the line-break option if your source treats every newline as a break.
3
Read the preview The preview sits under your source and follows it as you scroll, with a contents list built from your headings and a word and reading-time count.
4
Take what you need The output box holds the HTML source, or a tidied copy of the Markdown itself if you pick that instead. Copy it or download it.

What to Know About Markdown

Raw HTML, hard line breaks, and which dialect this is.

Markdown allows raw HTML, so a previewer that does not sanitise is a security hole. Your document may contain <script>, an onerror attribute or a javascript: link, and a preview puts all of that into a live page. This one renders the Markdown, parses the result into an inert document, removes script, style, iframe, object, embed and form elements, strips every on* attribute, and blocks javascript: and data: URLs in href and src. What was removed is counted on the page.
There is no single Markdown, so a preview is a preview of one dialect. This renders CommonMark with the GitHub extensions, which is what GitHub, GitLab and most modern tools use. Reddit, older forums, Python-Markdown and Discourse each differ in places, particularly around nested lists, line breaks and raw HTML. For a README this is the right dialect; for a comment box somewhere else, check the result there too.
A single newline is not a line break unless you ask for it. In standard Markdown two lines of text separated by one newline become one paragraph. GitHub comment boxes break on every newline, which is why text looks different when pasted into one, so there is a switch for that here. The other way to force a break is to end a line with two spaces, which is invisible in most editors and easy to lose.
The tidied Markdown is conservative, and it does not reformat your prose. It normalises heading markers, makes list bullets consistent, trims trailing spaces except a deliberate hard break, and collapses runs of blank lines. It does not rewrap paragraphs, reindent nested lists, touch anything inside a fenced code block or convert reference links into inline ones. A full Markdown formatter would do more and would also change more than you expect.

Key Features & Capabilities

What this tool does, and what it deliberately does not.

Renders as you type No run button. The preview and the counts follow every keystroke.
Sanitised before display Scripts, on* attributes and javascript: URLs never reach the page.
GitHub extensions Tables, strikethrough and task lists, switchable on and off.
Contents from headings A nested list of your headings, with the ids they were given.
Three things to take The preview, the HTML source, or a tidied copy of your Markdown.
Nothing uploaded Unreleased notes and internal docs stay in your browser tab.

About the Markdown Previewer

Markdown is the format people write documentation in, and almost every editor shows it slightly differently. A preview is useful precisely at the moment before you commit: does that table line up, did the nested list survive, is the link actually a link. This page renders it with marked, which follows CommonMark plus the GitHub extensions, so what you see matches what a modern host will show.

The interesting problem in a previewer is not the rendering, it is the safety. Markdown deliberately permits raw HTML, so a document can carry a script tag, an event handler or a javascript: link, and a preview inserts that into a live page. The rendered HTML here is therefore parsed into an inert document, walked, and cleaned before it is displayed, and the number of things removed is reported alongside the word count.

The rest is practical detail. Heading ids are generated here rather than by the renderer, because marked stopped doing that by default, and the same pass builds the contents list. The tidied Markdown option normalises the things that are safe to normalise and leaves prose, code blocks and reference links alone, on the grounds that a formatter which quietly rewraps your paragraphs is worse than no formatter at all.

Frequently Asked Questions

Flavours, sanitising, headings and what the output is for.

CommonMark, with the GitHub extensions turned on by default: tables, strikethrough, task lists and automatic links. That combination is what GitHub, GitLab, Bitbucket and most static site generators use. You can switch the extensions off to see how a stricter renderer would treat the same text, which is useful when something renders on GitHub and not somewhere else.

The document is never sent anywhere, and the HTML it produces is sanitised before it is displayed. Script, style, iframe, object, embed and form elements are removed, every attribute starting with on is stripped, and javascript: and data: URLs are blocked in href and src. That last rule also stops inline base64 images from showing, which is a deliberate trade for a previewer that may be handed an untrusted file.

Because in standard Markdown a single newline inside a paragraph is just whitespace; two consecutive newlines start a new paragraph. GitHub comment boxes are the exception and break on every newline. Turn on the line-break switch to match that behaviour, or end a line with two spaces to force a break in any renderer.

It normalises heading markers to a single hash run with one space, makes unordered list bullets consistent, removes trailing whitespace unless it is a deliberate two-space hard break, and collapses three or more blank lines into one. It does not rewrap text, reindent lists, alter fenced code blocks or convert reference links. It is a tidy-up, not a reformat.

Yes, and it is the sanitised HTML rather than the raw render, so it is safe to embed. It carries no styles, which is intentional: the classes and layout are yours. If your Markdown relied on raw HTML that the sanitiser removed, the output will not contain it, and the removal count on the page tells you that happened.

Other Developer Tools

Advertisement Slot (Bottom Banner) Google AdSense Unit • Responsive Banner