Free Online Markdown Previewer With Sanitised HTML
Type Markdown and read the rendered result as it appears, with GitHub flavoured tables, strikethrough and task lists. Take away the preview, the HTML source or a tidied copy of the Markdown, and the raw HTML in your document is sanitised before anything is displayed.
Enjoying WizTools123? Help keep our server infrastructure 100% free and open for everyone.
Why a Markdown Previewer Has to Sanitise
Because Markdown is allowed to contain HTML.
Markdown was designed to let you drop into HTML whenever the format runs out of syntax,
which means a Markdown document can contain <script>, an
onerror attribute on a broken image, an <iframe> or a link
whose target is javascript:. A previewer takes that text and puts it into a
live page. Do that without checking and you have built a reliable way to run someone
else's code in your browser, with your session and your cookies.
So the rendered HTML here is parsed into an inert document first, which is a parser that
does not execute anything, and then walked: dangerous elements are dropped, every
attribute beginning with on is removed, and href and
src values are checked before they are kept. Only then is the result put on
the page. The count of what was removed is shown with the other counts, so if your
document did contain something like that, you find out rather than just not seeing it.
How to Preview Markdown
A few steps, and nothing is uploaded.
What to Know About Markdown
Raw HTML, hard line breaks, and which dialect this is.
<script>, an onerror attribute or a javascript: link, and a preview puts all of that into a live page. This one renders the Markdown, parses the result into an inert document, removes script, style, iframe, object, embed and form elements, strips every on* attribute, and blocks javascript: and data: URLs in href and src. What was removed is counted on the page.
Key Features & Capabilities
What this tool does, and what it deliberately does not.
About the Markdown Previewer
Markdown is the format people write documentation in, and almost every editor shows it slightly differently. A preview is useful precisely at the moment before you commit: does that table line up, did the nested list survive, is the link actually a link. This page renders it with marked, which follows CommonMark plus the GitHub extensions, so what you see matches what a modern host will show.
The interesting problem in a previewer is not the rendering, it is the safety. Markdown deliberately permits raw HTML, so a document can carry a script tag, an event handler or a javascript: link, and a preview inserts that into a live page. The rendered HTML here is therefore parsed into an inert document, walked, and cleaned before it is displayed, and the number of things removed is reported alongside the word count.
The rest is practical detail. Heading ids are generated here rather than by the renderer, because marked stopped doing that by default, and the same pass builds the contents list. The tidied Markdown option normalises the things that are safe to normalise and leaves prose, code blocks and reference links alone, on the grounds that a formatter which quietly rewraps your paragraphs is worse than no formatter at all.
Frequently Asked Questions
Flavours, sanitising, headings and what the output is for.