Sanitizer API Playground - Interactive Lab | IconVault

Sanitize HTML with the browser Sanitizer API and test real XSS payloads safely. Free, runs fully in your browser.

All tools

Sanitizer API Playground

HTML sanitizer with XSS attack-payload testing

5 of 5 free uses left
Engine:Strict allowlist fallbackThis browser has no setHTML(), so a strict built-in allowlist sanitizer runs instead. Same rules, no dependency.

Attack-payload test bench

These are real XSS attack patterns, clearly labeled. They are never executed: the input preview below is escaped text, and the cleaned result renders inside a sandboxed iframe.

Test payloads

5 of 5 free sanitizations left.

Raw input (escaped, never rendered)

<img src="x" onerror="alert('xss')">Hello

Sanitized output

Press Sanitize to see what survives.

The pattern

// Prefer the built-in Sanitizer API where available
const el = document.createElement("div");
if (typeof el.setHTML === "function") {
  el.setHTML(untrustedHtml); // browser strips scripts, event handlers, javascript: URLs
  container.append(el);
} else {
  // Fallback: parse and keep only an allowlist of tags/attributes,
  // drop on* handlers, style, and non-http(s) URLs.
  container.append(allowlistSanitize(untrustedHtml));
}

About this tool

IconVault's Sanitizer API Playground lets you sanitize untrusted HTML safely: paste markup or fire labeled XSS attack payloads, clean them with the browser's built-in Sanitizer API (setHTML) or a strict built-in allowlist fallback, and view the result in a sandboxed iframe with removal stats. It is free to use and runs fully in your browser with nothing uploaded.

How to use: pick an attack payload like img onerror or javascript: links, press Sanitize, and compare the escaped input with the cleaned output. Perfect for developers learning XSS prevention, secure DOM insertion and content-security practices.

Frequently asked questions

Popular searches

sanitizer apisethtml examplejavascript sanitize htmlxss prevention javascriptsanitize user input jshtml sanitizer onlinetest xss payloadxss attack examplessanitizer api browser supportelement.sethtmlsanitizer api sanitizedompurify vs sanitizer apisanitize innerhtmlsafe innerhtml javascriptxss cheat sheetimg onerror xsssvg onload xssjavascript url xssscript tag xssxss payload listlearn xss preventionweb security xsssanitize html javascriptallowlist html sanitizerstrip script tags jsremove event handlers htmltrusted types vs sanitizercontent security policy xssxss tester onlinehtml injection testsanitizer api mdnsanitizer api tutorialxss prevention cheat sheetowasp xss preventionescape html javascriptencode html entities jssafe dom insertiontextcontent vs innerhtmlxss in javascriptstored xss examplereflected xss exampledom based xsssanitize markdown htmlxss filter bypasshtml sanitizer librarysanitize svgxss playgroundweb security labfrontend security toolsxss demo safesanitizer api playground

More tools

Coming soon

CLI

Coming soon

Figma plugin

Coming soon

VS Code extension

Coming soon

Chrome extension

Coming soon

AI icon generator

Coming soon

Team workspaces

Coming soon

View all 10+ tools →