Writing and web guide

Convert Markdown and HTML Safely in Your Browser

Preview Markdown and move between Markdown and a safe HTML subset without uploading the draft.

By Dhruba PoudelReviewed 2026-09-29Tool runs at tools.dhrub.com.np

Can I preview Markdown and convert HTML without running unsafe code?

Yes—provided the rendered HTML is sanitised before it is inserted into the page. Dhrub Free Tools parses Markdown with Marked, applies a strict DOMPurify allow-list, validates every retained link and only then creates the preview. HTML-to-Markdown follows the same boundary: the HTML is sanitised first and Turndown converts that safe subset. Scripts, forms, frames, embedded objects, inline styling, event handlers, unsafe URL schemes and remote images are excluded.

How to use the tool

Choose the direction

Select Markdown to HTML or HTML to Markdown, then paste text or choose a small local text file.

Convert through the safety filter

The browser loads the conversion libraries on demand and sanitises HTML before preview or reverse conversion.

Compare, copy or download

Read the safe preview and source output, then copy it or save a new HTML or Markdown file.

At a glance

Processing
In the current browser tab; Markdown parsing uses a disposable worker
Markdown engine
Marked with GFM-style parsing
HTML safety layer
DOMPurify plus link validation
HTML-to-Markdown engine
Turndown
Input limit
120,000 characters
HTML structure limits
4,000 tags and 80 nesting levels
Remote images in preview
Removed

Markdown parsing and HTML safety are separate jobs

Markdown is plain text with conventions for headings, emphasis, lists, links, code and other structure. Different flavours add features, so output can vary between editors. The studio enables GitHub-Flavoured Markdown behaviour in Marked, but it does not promise byte-for-byte agreement with every wiki, static-site generator or publishing platform.

A Markdown parser creates HTML; it does not make arbitrary embedded HTML trustworthy. Marked’s own guidance recommends sanitising the output. The studio sends every result through DOMPurify with a narrower project allow-list and then checks retained link schemes before rendering. The same sanitised string is the HTML available to copy or download.

  • Treat pasted HTML and Markdown as untrusted input, even when it looks like text.
  • Review headings, tables, code fences and links in the destination system.
  • Keep a source copy when exact formatting matters.
  • Do not reinsert removed scripts, event handlers or embedded content after export.

Why round trips can change formatting

HTML can express structures and behaviours that ordinary Markdown cannot. Turndown converts supported elements into readable Markdown rules, but attributes, layout containers, styling and unsupported elements can be discarded or simplified. Converting that Markdown back to HTML therefore may not reproduce the original source.

The safe preview deliberately omits images so a remote source cannot be contacted merely by rendering a draft. Links remain visible only when their scheme is HTTP, HTTPS, mailto, tel or a relative reference, and they open separately with opener protection.

Important limitations

  • Sanitisation reduces script-injection risk but does not prove that the words, destinations or claims in a document are trustworthy.
  • Documents above 120,000 characters, 4,000 HTML tags or 80 HTML nesting levels are refused; conversion speed within those limits still depends on the device.
  • Markdown flavours differ; extensions, footnotes, diagrams, math and platform-specific syntax may not round-trip.
  • HTML styling, forms, media, SVG, MathML, templates, frames and embedded objects are intentionally removed.
  • Remote images are excluded from the preview and output to avoid an automatic third-party request.
  • Always test exported content in its final publishing system, which may apply different parsing or sanitisation rules.

Questions people ask

Why was part of my HTML removed?

The studio keeps a conservative document-markup subset. Active content, forms, styling, embeds, images and unsafe attributes are removed before the result can be previewed.

Is Markdown itself always safe?

No. Markdown can contain raw HTML and links, and a parser normally emits HTML. Safety depends on sanitising the rendered output and on how the destination uses it.

Will HTML convert back to exactly the same Markdown?

No. Several Markdown forms can represent the same HTML, and HTML features without a Markdown equivalent are simplified or omitted.

Are my drafts uploaded?

No application API receives the pasted draft or selected text file. Conversion occurs in the active browser tab.

Primary and project sources

  1. Marked documentation — Marked projectPrimary documentation for the Markdown parser used by the studio.
  2. Marked advanced usage — Marked maintainersProject guidance that rendered HTML should be passed through a sanitisation library.
  3. DOMPurify project — Cure53 and DOMPurify maintainersPrimary sanitizer documentation, configuration and security guidance.
  4. Turndown project — Turndown maintainersPrimary documentation for converting HTML into Markdown.
  5. CommonMark specification — CommonMark projectSpecification and examples for a defined Markdown syntax.