Developer · THE NO-PANIC PLAN
Convert Markdown documentation into reviewed HTML safely
For technical writers and developers preparing a Markdown document for a website, help center, or static documentation page. The Nirmion Markdown to HTML tool converts GitHub-flavoured Markdown in the browser and provides downloadable HTML; it does not certify that output is safe to publish. GitHub's own renderer performs additional processing and sanitization, which a downloaded conversion does not inherit automatically. Treat source Markdown as untrusted when it can be edited by others, sanitize rendered HTML with a maintained allowlist sanitizer before browser insertion, validate URL schemes, and review the final output in the actual destination. Do not use this workflow to publish private material or bypass the site's normal review process.
MISSION Convert a Markdown document to HTML for a named destination, preserve its structure and links, and prevent untrusted raw HTML or URLs from becoming unsafe browser content.
Convert a reviewed Markdown copy to HTMLTHE REAL-WORLD BIT
What happens outside this browser tab?
Identify the intended Markdown dialect and HTML destination; protect private content and source files; convert a copy using the matching dialect; sanitize and validate HTML and URLs for the actual renderer; check heading structure, links, media and behavior; then release through the destination's normal review path.
YOUR CHECKLIST, WITH FEWER DRAMATIC SIGHES
One step at a time.
Follow the order below. If a step names a Nirmion tool, its link is right there with it.
- 01
Name the source dialect and the HTML destination
Record where the Markdown came from, its intended dialect (for this tool, GitHub-flavoured Markdown), extensions in use, raw-HTML policy, and the exact destination that will consume the output. GitHub Flavored Markdown is based on CommonMark but adds extensions, and GitHub.com applies additional processing after conversion; do not assume an exported file has the same safety behavior as content rendered on GitHub. Identify whether the HTML will be a downloadable document, trusted static site content, or user-authored content inserted into an application. If the destination expects a different dialect or applies its own templating, use that renderer's documented conversion path. (Sources 1, 2, 3)
- 02
Prepare a safe working copy and check document assets
Keep the original Markdown unchanged and make a separate working copy. Remove credentials, private customer information, unpublished incident details, and internal links that are not approved for the destination. Inventory images, relative links, file downloads, tables, task lists, code fences, and embedded raw HTML; confirm the publication owner has permission to use every referenced asset. Check whether relative paths will remain valid after download or deployment and decide how missing files should be handled. The converter runs locally in the browser, but your organization's classification and release rules still govern what may be opened or exported in a browser tool. (Sources 1, 2)
- 03
Convert the copy with the intended Markdown dialect
Use Markdown to HTML (Nirmion tool 168) on a non-sensitive working copy when GitHub-flavoured Markdown matches the source requirements. Convert the document and download the result without replacing the source. Compare representative headings, nested lists, tables, links, code blocks, task-list markers, images, and raw HTML against the expected destination behavior. CommonMark and GitHub-flavoured Markdown define parsing behavior; conversion alone does not sanitize all allowed markup for every downstream HTML context. If the output is missing an extension or changes meaning, stop and use the renderer specified by the destination instead of manually patching the generated page without review. (Sources 1, 2, 3)
- 04
Sanitize HTML and validate links before browser use
If any source content is untrusted or the HTML will be inserted into a website or application, pass the rendered HTML through a maintained allowlist sanitizer configured for the destination's permitted elements, attributes, and URL schemes. Validate links and image sources, reject dangerous schemes, and use context-appropriate output handling in the application. Do not rely on Markdown parsing, a preview, regular-expression removal, or GitHub's sanitization as a security boundary for a separately exported file. Do not modify sanitized output afterward in a way that reintroduces unsafe markup; keep the sanitizer updated and follow the site's security review process. (Sources 2, 4)
- 05
Review accessibility and release the final artifact
Open the sanitized HTML in the actual destination or a representative staging environment. Check that headings describe the structure and are nested meaningfully, links make sense out of context, images have appropriate text alternatives, tables have clear headers, and code remains readable on narrow screens and with keyboard navigation. Test ordinary and adversarial examples, including raw tags, event-handler attributes, `javascript:`-style links, malformed nesting, and broken relative assets; verify unsafe content is removed or displayed only as text. Confirm the page owner approves the content, title, links, and download behavior, retain the source version and conversion date, and publish only through the normal content review and rollback process. (Sources 4, 5)
THE HELPER CREW
Tools for the fiddly bits.
These are the currently published Nirmion tools matched to this guide. Open a tool page for its accepted inputs and limits.
RECEIPTS, PLEASE
Sources & review notes
Each source is linked to the steps it supports. Open it to check its scope and current guidance.
Source checked 2026-10-09