- Raw HTML is escaped unless you allow it
- Because Markdown allows embedded HTML, converting untrusted input with passthrough enabled is a cross-site scripting vector. By default a <script> tag in the source becomes visible text. Enable "Allow raw HTML" only for documents you control, such as your own README.
- Dangerous link schemes are blocked
- Even with raw HTML disabled, a Markdown link can carry a javascript: URL. Those are rejected along with vbscript: and data: URLs, except data: images, which are a legitimate way to embed a small picture. The link renders as plain text instead.
- Fenced code blocks and language hints
- Triple-backtick blocks become <pre><code>, and a language hint becomes a class="language-x" attribute, which is the convention highlight.js and Prism expect. Code content is always escaped, so a snippet containing markup displays rather than executing.
- Tables and task lists
- GitHub-style pipe tables become real <table> markup, with the colons in the separator row translated into text-align styles. Task list items become disabled checkboxes, matching how GitHub renders them.
- Hard line breaks need two trailing spaces
- A single newline inside a paragraph is just a space in the output, which is standard Markdown behaviour and often surprises people. Two trailing spaces produce a <br />, and a blank line starts a new paragraph.