Overview
Write forum-style BBCode - the [b]bold[/b], [i]italic[/i], [url] and [quote] markup used on phpBB, vBulletin, and countless forum and comment systems - and see it rendered instantly in a live preview pane, without needing an actual forum account to check your formatting. Every tag is converted through a strict allowlist: the raw input is fully HTML-escaped first, so any literal HTML you paste (including a stray <script> tag) is neutralized into inert text before a single BBCode tag is ever applied, and link/image URLs are restricted to plain http(s) addresses while color values are restricted to a fixed set of named colors. Nothing is sent anywhere - the toolbar buttons insert tags directly into the textarea and the preview re-renders in your browser as you type.
Best for: Drafting a forum post and checking the formatting before submitting it
How to use this tool
- Type or paste BBCode. Use the toolbar buttons to insert [b], [i], [url], and [color] tags, or type them directly.
- Input is escaped first. Every character is HTML-entity-encoded before any tag substitution, so raw HTML can never survive.
- Only allowlisted tags render. A fixed set of BBCode tags convert to a fixed set of safe HTML tags - nothing else passes through.
- See the live preview. The rendered preview pane updates immediately, or copy the generated safe HTML directly.
Why use this tool
Escape-then-substitute sanitization
Raw text is HTML-escaped before any BBCode tag is applied, so embedded HTML can never execute.
URLs restricted to http(s)
[url] and [img] reject javascript:, data:, and any other non-http(s) scheme outright.
Colors restricted to an allowlist
[color] only honors a fixed set of named CSS colors - no arbitrary CSS can be injected.
Runs entirely client-side
Nothing you type is ever uploaded - the toolbar, parser, and preview all run in your browser.
Frequently asked questions
Yes - the input is HTML-escaped before any BBCode conversion happens, so a literal <script> tag or an onerror= attribute typed into the box is rendered as plain, inert text in the preview rather than executed. Only a small fixed set of BBCode tags ([b], [i], [u], [s], [url], [img], [quote], [code], [list]/[*], [color], [size]) are ever converted into HTML, and each one is restricted (http(s)-only URLs, an allowlisted color set) rather than passed through as-is.
[b] bold, [i] italic, [u] underline, [s] strikethrough, [url]/[url=href] links, [img] images, [quote] blockquotes, [code] inline code, [list] with [*] items, [color=name] with an allowlisted color, and [size=NN] font sizing. Anything outside that set is left as plain escaped text rather than guessed at.
No - parsing and rendering both happen entirely in your browser. Nothing you write is sent to a server.