Security · Library

DOMPurify

A small, widely used JavaScript library that cleans untrusted HTML before it goes on a page, keeping safe formatting and stripping anything that could run script.

Defences · Open source · updated

How it works

Call DOMPurify.sanitize(html) and it parses the string with the browser's own HTML parser, walks the result and removes script tags, event-handler attributes such as onclick, javascript: links and other dangerous parts, while keeping ordinary markup such as paragraphs, links, lists and images. It handles HTML, SVG and MathML, and it can be configured to allow or forbid particular tags and attributes.

It is the usual choice whenever an app must display HTML it did not write: rendered Markdown, rich text from an editor such as Tiptap, emails or content from a CMS. The security firm Cure53 maintains it and updates it as new ways of smuggling script past sanitisers are found. It needs a DOM, so on a server it runs with jsdom or through the isomorphic-dompurify wrapper.

Browsers have started to ship a built-in Sanitizer API (element.setHTML); until every browser a site supports has it, DOMPurify remains the portable choice. Clean the HTML right before it is inserted, and keep the library updated.

DOMPurify pricing

Open source

Free (Apache 2.0 or MPL 2.0).

Approximate, checked September 2026.What the other tools cost

More in Security

Defences

All 20 Security terms

Crafted in the dark. Shipped to the world.

Tell us what you are building. You get a private project space with a proposal and a line-by-line quote within a day.