Paste untrusted HTML and get clean, safe markup. Scripts, event handlers and dangerous URLs are stripped instantly — all locally in your browser.
Cross-site scripting attacks ride on user-controlled HTML: comment fields, forum posts, rich-text editors and chat messages. A robust sanitizer runs the markup through the browser's own HTML parser, walks every node, and rebuilds the document — dropping script, style, iframe, object, embed and form tags, every on* event attribute, javascript: / data: URLs and CSS expression(). Balanced mode additionally whitelists only plain formatting tags for maximum safety.