Parsedown



Better Markdown Parser in PHP - Demo.

  1. Super Fast
  2. Parsedown Recaptcha
  3. Using Markdown With PHP
  4. Parsedown Syntax Highlighting

March 1st, 2018 Since Laravel 5.4 the framework has included a markdown parser called Parsedown. It’s used internally for the markdown emails, but you can also easily use it in your apps. The Parsedown team recently released v1.7.0 to address an XSS issue that caused the SensioLabs Composer vulnerability check to fail. Parsedown This is an exact mirror of the Parsedown project. SourceForge is not affiliated with Parsedown. For more information, see the SourceForge Open Source Mirror Directory. Downloads: 0 This Week Last Update: 11 minutes ago. Get project updates, sponsored content from our select partners, and more. Parsedown This page gives the essential Git commands for working with this project’s source files. Version to work from. Update Notice: See Git instructions updates for.

  • This is where Parsedown comes into play. For convenience, we will register the Parsedown as a singleton service in our application, so we can automatically inject it wherever we want, using the.
  • Parsedown This page gives the essential Git commands for working with this project’s source files. Version to work from. Update Notice: See Git instructions updates for a record of updates to these instructions.

¶Features

Parsedown
  • One File
  • No Dependencies
  • Extensible
  • Tested in 5.3 to 7.3

¶Installation

Parsedown

Install the composer package:

Or download the latest release and include Parsedown.php

¶Example

You can also parse inline markdown only:

More examples in the wiki and in this video tutorial.

¶Security

Parsedown is capable of escaping user-input within the HTML that it generates. Additionally Parsedown will apply sanitisation to additional scripting vectors (such as scripting link destinations) that are introduced by the markdown syntax itself.

To tell Parsedown that it is processing untrusted user-input, use the following:

If instead, you wish to allow HTML within untrusted user-input, but still want output to be free from XSS it is recommended that you make use of a HTML sanitiser that allows HTML tags to be whitelisted, like HTML Purifier.

In both cases you should strongly consider employing defence-in-depth measures, like deploying a Content-Security-Policy (a browser security feature) so that your page is likely to be safe even if an attacker finds a vulnerability in one of the first lines of defence above.

¶Security of Parsedown Extensions

Safe mode does not necessarily yield safe results when using extensions to Parsedown. Extensions should be evaluated on their own to determine their specific safety against XSS.

¶Escaping HTML

WARNING: This method isn't safe from XSS!

If you wish to escape HTML in trusted input, you can use the following:

Beware that this still allows users to insert unsafe scripting vectors, such as links like [xss](javascript:alert%281%29).

ParsedownextraParsedown table of contents

¶Questions

How does Parsedown work?

It tries to read Markdown like a human. First, it looks at the lines. It’s interested in how the lines start. This helps it recognise blocks. It knows, for example, that if a line starts with a - then perhaps it belongs to a list. Once it recognises the blocks, it continues to the content. As it reads, it watches out for special characters. This helps it recognise inline elements (or inlines).

We call this approach 'line based'. We believe that Parsedown is the first Markdown parser to use it. Since the release of Parsedown, other developers have used the same approach to develop other Markdown parsers in PHP and in other languages.

Is it compliant with CommonMark?

It passes most of the CommonMark tests. Most of the tests that don't pass deal with cases that are quite uncommon. Still, as CommonMark matures, compliance should improve.

Who uses it?

Cached

Super Fast

Laravel Framework, Bolt CMS, Grav CMS, Herbie CMS, Kirby CMS, October CMS, Pico CMS, Statamic CMS, phpDocumentor, RaspberryPi.org, Symfony Demo and more.

Parsedown Recaptcha

How can I help?

Use it, star it, share it and if you feel generous, donate.

Using Markdown With PHP

What else should I know?

I also make Nota — a writing app designed for Markdown files :)

Parsedown Syntax Highlighting

¶Stargazers over time