HTML Sanitizer
DOMPurify-based. Strips scripts, event handlers, and javascript: URLs. 100% client-side.
Allowed tags
Options
Sanitized output
Rendered preview
HTML Sanitizer — Free Online Tool
Sanitizes untrusted HTML using DOMPurify with configurable allowed tags, attributes, and protocol schemes, stripping XSS payloads, event handlers, and javascript: URLs while preserving safe formatting, useful for previewing user-submitted HTML, testing CMS rich-text filters, and hardening email and chat message rendering against script injection.
How to use the HTML Sanitizer
- Open the tool above — it runs entirely in your browser, so your input never leaves this page.
- Paste or type your input into the field, then press the relevant button (e.g. Encode / Decode, Generate, or Convert).
- Copy the result from the output area with the copy button orCtrl/Cmd + C.
- No signup, no upload, and no tracking — repeat as often as you need.
Frequently asked questions
Is the HTML Sanitizer free to use?
Yes. The HTML Sanitizer is completely free, with no signup, no ads inside the tool, and no hidden limits.
Does the HTML Sanitizer upload my data?
No. The HTML Sanitizer processes everything locally in your browser. Your input is never sent to a server, so it stays private even on shared devices.
Does the HTML Sanitizer work offline?
After the page loads, the HTML Sanitizer runs entirely in your browser, so it keeps working without a network connection.
Free & private — why use this HTML Sanitizer
The HTML Sanitizer runs 100% client-side in your browser. Your data is never uploaded to a server, no account is required, and the tool is completely free. It works offline once the page has loaded and is part of a growing collection of privacy-first developer utilities.