Remove XSS vectors from HTML using an allowlist. Keeps 49 safe tags, blocks script/iframe/svg/form and strips all on* handlers. Shows exactly what was removed.
Paste any HTML fragment and the XSS Input Sanitizer walks every node through an allowlist, returning only the elements and attributes that cannot carry a cross-site scripting payload. The lead sample, titled "A blog post preview", arrives with an inline onclick handler, a bare <script> tag, a javascript: href, and an onerror on an <img>. The sanitiser drops all four and returns the heading, paragraph, and link with a clean https:// href intact.
The approach is allowlist-first: 49 structural tags are permitted (headings, paragraphs, lists, tables, inline formatting elements) and everything outside that set is refused. Dangerous tags — script, style, iframe, svg, object, embed, form, link, meta, base and a further dozen — are blocked entirely: the tag and all of its children disappear. Unknown tags outside the 49 are treated more charitably: the wrapper is stripped but the text content is kept, which preserves the readable parts of a lightly malformed fragment without discarding the whole paragraph.
Every on* event handler is removed unconditionally, regardless of which tag it appears on. style attributes are dropped because CSS can carry expression() calls and url('javascript:…') values that survive a naive attribute scan. URL attributes (href, src, cite) must begin with https?:, mailto:, tel:, / or #; anything else, including bare javascript: and data URIs, is stripped. All processing runs in your browser tab with no upload.
DOMParserto build the tree. A server-side renderer without a real DOM will not run this tool, and the output reflects how this browser's parser interprets the markup. Another engine may parse malformed HTML differently. For server-side sanitisation, use a dedicated library such as DOMPurify, which runs the same logic in Node via jsdom.innerHTML, which is the same path mXSS exploits. DOMPurify addresses this by walking the serialised output a second time; this tool does not. Keep that in mind for HTML that will be re-parsed after sanitisation.style attributes are dropped entirely. If your use case requires styled HTML, apply a CSS allowlist step after sanitisation, the clean structural markup this tool produces is a safe base to build on.template elements are blocked at the tag level. Their inert content is never parsed into the live DOM by DOMParser, so removing the tag removes the threat without needing a recursive pass into the inert tree.Paste HTML above or click Load Sample to sanitise it.