
Callum Reid
Markdown is a family of closely related dialects, and most bugs in it come from writing for one and rendering in another. On top of that sit tables, footnotes, task lists, strikethrough, attributes, maths and raw HTML. A renderer either enables a subset of these or ignores them silently, and ignored syntax usually surfaces as literal punctuation. Fenced code blocks are the most reliable part and still have edge cases. Info strings carry a language identifier for highlighting, and some renderers read options from the same string. An unclosed fence swallows the remainder of the document, which is why a stray backtick is worth checking first when a page renders short. Links get their own treatment. Reference-style links resolve anywhere in the document, which is convenient right up until two definitions collide. Bare URLs are autolinked by some renderers and left as plain text by others, and a link with mismatched brackets produces output that looks fine and points at the wrong place. Raw HTML is where sanitisation earns its place. Markdown passes HTML through by design, so a document containing a script tag or an event handler attribute reaches the browser unless the pipeline strips it. Sanitisers differ in which tags they allow, and allowing a tag for a benign reason can permit an attribute with a script handler, reintroducing the problem it was meant to remove. I cover heading level discipline too, because renderers frequently promote or demote headings to fit a template, and that silently breaks both the outline and accessibility.
About ToolSura
ToolSura offers 80+ free, privacy-first online tools that run 100% in your browser — no uploads, no logins. Learn more about our mission →