Why sanitize the output at all#
Markdown allows raw HTML to pass through unchanged — that is part of the spec, not a bug. It means a <script> tag pasted into the source panel would otherwise render, and execute, inside this page. Before the generated HTML touches the preview panel, it is run through DOMPurify, a well-audited sanitizer that strips scripts, event handlers and other executable content while leaving normal formatting HTML untouched.
The HTML you copy out is the sanitized version, not the raw conversion — so pasting it elsewhere carries the same protection, without needing to trust whatever markdown you started from.
What "GitHub-flavored" adds over plain Markdown#
Original Markdown does not define tables, strikethrough text, or task-list checkboxes — those were popularized later by GitHub's dialect (GFM) and have since become the de facto standard most tools and CMSs expect. This converter follows GFM, so ~~strikethrough~~, pipe-delimited tables, and - [ ] todo checklists all render as expected, alongside standard headings, lists, links, and fenced code blocks with language-tagged syntax classes.
Where this fits — READMEs, CMS bodies, email templates#
Markdown is the natural format for writing, but most places that display content on the web want HTML: a CMS rich-text field, a static site generator without built-in Markdown support, an HTML email template, or a component that only accepts markup. This tool is the bridge — write in Markdown, ship HTML, without installing a build toolchain for a one-off conversion.