XSS Sanitizer

Paste untrusted HTML and get clean, safe markup. Scripts, event handlers and dangerous URLs are stripped instantly — all locally in your browser.

Sanitizing Mode

Input HTML

Try:

Sanitized Output

0
Removed
0
Kept
0
Output length
 

Removed Items

Nothing removed yet.

About XSS Sanitizing

Cross-site scripting attacks ride on user-controlled HTML: comment fields, forum posts, rich-text editors and chat messages. A robust sanitizer runs the markup through the browser's own HTML parser, walks every node, and rebuilds the document — dropping script, style, iframe, object, embed and form tags, every on* event attribute, javascript: / data: URLs and CSS expression(). Balanced mode additionally whitelists only plain formatting tags for maximum safety.