Data and security guide

Convert CSV and JSON Locally, with Safer Spreadsheet Exports

Move tabular data between CSV and JSON in your browser while reducing spreadsheet formula-injection risk.

By Dhruba PoudelReviewed 2026-09-29Tool runs at tools.dhrub.com.np

Can CSV and JSON be converted without uploading the data?

Yes. A browser can parse CSV text, build JSON records, display a safe text-only table preview and create a new CSV download locally. Dhrub Free Tools uses Papa Parse inside the private workspace, limits input size and rows, and prefixes formula-like CSV cells on export so a spreadsheet is less likely to interpret untrusted values as commands.

How to use the tool

Choose a direction

Select CSV to JSON or JSON to CSV, then paste the content or choose a small local file.

Review the table

Check headings, row count, duplicate-heading warnings and the first 100 rows in the text-only preview.

Copy or download

Save the complete result as a new file and validate it in the destination application before relying on it.

At a glance

Processing
In the current browser tab
CSV parser
Papa Parse
Maximum data rows
10,000 per conversion
Formula-like CSV cells
Prefixed on JSON-to-CSV export

Why a CSV cell can be risky

CSV is a text exchange format, but spreadsheet programs can interpret cells beginning with characters such as an equals sign, plus sign, minus sign or at sign as a formula. If untrusted data is opened without care, a value that looked like ordinary text can be evaluated by the spreadsheet application.

The converter asks Papa Parse to escape formula-like values during JSON-to-CSV export. That is a risk reduction, not a universal security guarantee: spreadsheet products, import settings and downstream transformations differ.

  • Treat exported CSV as data, not executable instructions.
  • Keep formula protection enabled when the content came from another person or system.
  • Review leading apostrophes before importing the result into a database.
  • Use the destination system’s schema and validation rules as a separate check.

Headers, types and nested JSON

CSV does not carry a universal schema. The converter keeps values as text so identifiers such as leading-zero postcodes are not silently turned into numbers. Blank headings receive a generated name, and duplicate headings are renamed before JSON objects are created.

JSON-to-CSV accepts an array of objects. Nested arrays or objects are represented as JSON text inside a cell because a flat table cannot preserve every nested relationship. Complex data should be transformed against a documented schema instead of flattened blindly.

Important limitations

  • The formula prefix is a mitigation, not a guarantee across every spreadsheet and import workflow.
  • Automatic delimiter detection can be ambiguous for one-column or unusual files.
  • Values remain text; the converter does not infer a database schema or validate business rules.
  • The browser tool limits input size, rows and columns to keep the tab responsive.

Questions people ask

Why did a value gain an apostrophe in the CSV?

The value resembled a spreadsheet formula, so an apostrophe was added as a visible safety prefix. Confirm the destination’s import rules before removing it.

Will leading zeroes be preserved?

The converter treats CSV cells as text. A spreadsheet may still apply its own automatic type conversion when opening the downloaded file.

Can it flatten deeply nested JSON?

Nested values are serialised into one cell. Use a schema-aware data transformation when nested relationships must become several tables or columns.

Primary and project sources

  1. Papa Parse documentation — Papa Parse projectPrimary API documentation for CSV parsing, generation and escapeFormulae.
  2. CSV Injection — OWASP FoundationSecurity guidance on formula interpretation in spreadsheet exports.
  3. RFC 4180 — RFC Editor / IETFCommon CSV format and MIME type documentation.