# Security

This page gathers the behaviors that matter when handling untrusted Markdown: HTML passthrough, outbound requests, and third-party script sources.

## HTML Is Not Sanitized

`transToHTML()` does not sanitize. HTML tags and attributes in the text are kept as-is, and `MDViewer` writes the result into the page through `innerHTML`:

```markdown
<img src=x onerror="alert(document.cookie)">
```

This runs directly in the viewer. Only text inside inline code and code blocks is escaped.

| Situation | Risk | Recommendation |
|---|---|---|
| Users editing their own content | Low: affects only themselves | Use as-is |
| Previewing Markdown submitted by others | High: stored XSS | Do not display it with `MDViewer`; convert with `MDParser`, sanitize with a tool such as DOMPurify, then insert |
| Converting on a server before publishing | High | Same as above; sanitize before storing |

`MDViewer` offers no hook to intercept HTML before it is written, so the viewer is only suitable for trusted content.

## Links

Every link is `target="_blank"` with no `rel`. Current mainstream browsers apply `noopener` to `_blank` by default, but in older browsers the opened page can still rewrite the original through `window.opener`.

## Outbound Requests

| Trigger | Destination | Note |
|---|---|---|
| Bundle load | jsDelivr, Google Fonts | See [Runtime Dependencies](/runtime-dependencies) |
| Content with a YouTube link | `i.ytimg.com` | Thumbnail loads; the iframe loads only after a click |
| Content with a Vimeo link | `vimeo.com/api/v2` | Synchronous XHR for the thumbnail on every conversion |
| Content with external images/video | The image host | Loaded on preview; can be used to track a reader's IP |
| Deploy button | `nanomd-deploy.pardn.workers.dev` | Appears only on nanomd.pardn.io; uploads the content |

## Third-party Script Versions

code-prettify is loaded from `gh/google/code-prettify@master`, a moving branch rather than a pinned version, and without Subresource Integrity. Where supply-chain guarantees matter, self-host code-prettify and Mermaid and put `window.PR` and `window.mermaid` in place before NanoMD loads.

## Exported HTML

Files produced by `download("html")` contain the same unsanitized raw HTML and load `run_prettify.js` from jsDelivr. Check where the content came from before sharing an export.
