Rich Text Sanitizer
Parse pasted HTML and rebuild only a defined set of rich-text tags. Disable every link or retain vetted absolute HTTPS links. Review removal categories and the result. This policy is not a guarantee against XSS in every context.
Key features
- Keep a fixed allowlist of paragraphs, headings, lists, quotes and emphasis
- Remove scripts, forms, images, SVG, MathML, CSS and event attributes
- Disable links or keep only vetted absolute HTTPS links
- Show removal counts and input/output size
- Use a link-free isolated preview; copy or download the HTML
How to use
- Paste HTML or load the formatting or attack sample.
- Choose a link policy and run the sanitizer.
- Review the output HTML and removal findings.
- Inspect text structure in the isolated preview.
- Copy or download output and validate it in the publishing context.
Use cases
- Keep basic formatting from HTML copied from an editor
- Remove tracking images and handlers while restricting links
- Find SVG, forms and style traces in third-party content
Frequently asked questions
Which tags remain?
Only a, b, blockquote, br, code, del, div, em, h1–h6, hr, i, ins, li, ol, p, pre, s, span, strong, u and ul. Original attributes are discarded; optional HTTPS href and fixed rel/target are generated anew.
How are links handled?
The default policy makes links plain text. The HTTPS policy accepts only absolute URLs without whitespace, backslashes, controls or credentials. Preview links are always disabled.
Can I insert the result anywhere safely?
No. This is a particular policy for an HTML body fragment. Do not reuse it in HTML attributes, JavaScript, CSS or URLs. Apply context-specific encoding and review in the publishing environment.
Will it fetch remote resources?
The tool makes no network requests and removes images, frames and styles. A person clicking an allowed external link after publication is a separate action.
What are the limits?
UTF-8 input is limited to 64 KiB, with node, depth and output limits.
Privacy
HTML stays in the browser. The tool uploads nothing and fetches no URL. The preview removes links and uses an empty sandbox and CSP.
Comments & questions