Can I preview Markdown and convert HTML without running unsafe code?
Yes—provided the rendered HTML is sanitised before it is inserted into the page. Dhrub Free Tools parses Markdown with Marked, applies a strict DOMPurify allow-list, validates every retained link and only then creates the preview. HTML-to-Markdown follows the same boundary: the HTML is sanitised first and Turndown converts that safe subset. Scripts, forms, frames, embedded objects, inline styling, event handlers, unsafe URL schemes and remote images are excluded.
How to use the tool
Choose the direction
Select Markdown to HTML or HTML to Markdown, then paste text or choose a small local text file.
Convert through the safety filter
The browser loads the conversion libraries on demand and sanitises HTML before preview or reverse conversion.
Compare, copy or download
Read the safe preview and source output, then copy it or save a new HTML or Markdown file.
At a glance
- Processing
- In the current browser tab; Markdown parsing uses a disposable worker
- Markdown engine
- Marked with GFM-style parsing
- HTML safety layer
- DOMPurify plus link validation
- HTML-to-Markdown engine
- Turndown
- Input limit
- 120,000 characters
- HTML structure limits
- 4,000 tags and 80 nesting levels
- Remote images in preview
- Removed
Markdown parsing and HTML safety are separate jobs
Markdown is plain text with conventions for headings, emphasis, lists, links, code and other structure. Different flavours add features, so output can vary between editors. The studio enables GitHub-Flavoured Markdown behaviour in Marked, but it does not promise byte-for-byte agreement with every wiki, static-site generator or publishing platform.
A Markdown parser creates HTML; it does not make arbitrary embedded HTML trustworthy. Marked’s own guidance recommends sanitising the output. The studio sends every result through DOMPurify with a narrower project allow-list and then checks retained link schemes before rendering. The same sanitised string is the HTML available to copy or download.
- Treat pasted HTML and Markdown as untrusted input, even when it looks like text.
- Review headings, tables, code fences and links in the destination system.
- Keep a source copy when exact formatting matters.
- Do not reinsert removed scripts, event handlers or embedded content after export.
Why round trips can change formatting
HTML can express structures and behaviours that ordinary Markdown cannot. Turndown converts supported elements into readable Markdown rules, but attributes, layout containers, styling and unsupported elements can be discarded or simplified. Converting that Markdown back to HTML therefore may not reproduce the original source.
The safe preview deliberately omits images so a remote source cannot be contacted merely by rendering a draft. Links remain visible only when their scheme is HTTP, HTTPS, mailto, tel or a relative reference, and they open separately with opener protection.
Important limitations
- Sanitisation reduces script-injection risk but does not prove that the words, destinations or claims in a document are trustworthy.
- Documents above 120,000 characters, 4,000 HTML tags or 80 HTML nesting levels are refused; conversion speed within those limits still depends on the device.
- Markdown flavours differ; extensions, footnotes, diagrams, math and platform-specific syntax may not round-trip.
- HTML styling, forms, media, SVG, MathML, templates, frames and embedded objects are intentionally removed.
- Remote images are excluded from the preview and output to avoid an automatic third-party request.
- Always test exported content in its final publishing system, which may apply different parsing or sanitisation rules.
Questions people ask
Why was part of my HTML removed?
The studio keeps a conservative document-markup subset. Active content, forms, styling, embeds, images and unsafe attributes are removed before the result can be previewed.
Is Markdown itself always safe?
No. Markdown can contain raw HTML and links, and a parser normally emits HTML. Safety depends on sanitising the rendered output and on how the destination uses it.
Will HTML convert back to exactly the same Markdown?
No. Several Markdown forms can represent the same HTML, and HTML features without a Markdown equivalent are simplified or omitted.
Are my drafts uploaded?
No application API receives the pasted draft or selected text file. Conversion occurs in the active browser tab.
Primary and project sources
- Marked documentation — Marked projectPrimary documentation for the Markdown parser used by the studio.
- Marked advanced usage — Marked maintainersProject guidance that rendered HTML should be passed through a sanitisation library.
- DOMPurify project — Cure53 and DOMPurify maintainersPrimary sanitizer documentation, configuration and security guidance.
- Turndown project — Turndown maintainersPrimary documentation for converting HTML into Markdown.
- CommonMark specification — CommonMark projectSpecification and examples for a defined Markdown syntax.